Select Page

Australian Cyber Aware

Providing Australian and New Zealand news and services on cybersecurity, information security, privacy, and AI security.
Vendor-neutral, press release-free, and advertisement-free.

Please follow the Source link to the original article to support the content owner. We only provide a summary with metadata to assist in categorisation.

Monthly Australian Cyber News Summaries

Loading

Email Subscription

Australian Info & Cyber Security News

Scam alert: Scammers are impersonating ASIC via SMS. Scammers are sending SMS messages impersonating ASIC and urging recipients to call a fake phone number. The messages falsely state there… | ASIC

Scam alert: Scammers are impersonating ASIC via SMS. Scammers are sending SMS messages impersonating ASIC and urging recipients to call a fake phone … [...]

Optus outage attributed to hardware failure at exchange

Key points A hardware failure at an Optus exchange in Victoria caused a voice outage lasting about one hour and 16 minutes on Friday. • The outage … [...]

Digital platforms to be targeted as part of NSW crackdown on organised crime operations

NSW’s Premier has announced a raft of measures to combat the facilitation of serious crimes, such as gang-related murder. • Mon, 07 Sep 2026 • … [...]

Exclusive: Penfold Motors latest car dealer to fall victim to the Storm ransomware group

Victorian car dealership says it is contacting its customers after their contact and vehicle details were compromised by hackers. • Mon, 14 Sep 2026 • … [...]

ATO employee charged over alleged disclosure of information to organised crime groups

A Gold Coast man who worked with the Australian Taxation Office (ATO) has been charged over the alleged disclosure of information to organised crime … [...]

Cyber Wardens program to shut down as government funding ends

COSBOA CEO says lessons learned from the program “will help shape what comes next” as she celebrates assisting 23,150 small businesses. • Fri, 11 Sep … [...]

Nick Scali security breach: What it means for customer information

Furniture giant Nick Scali has confirmed New Zealand customers’ personal details were held on systems affected by a security breach last month. In an … [...]

Data breach exposes millions of students, teachers and parents | 9 News Australia

Millions of people, including school students, have had their data exposed in a data breach on an education website. | Subscribe and 🔔: http://9Soci.al/KM6e50GjSK9 | Get more breaking news at [...]

AI transforms cyber crime threat in Australia | 7NEWS

There's a new warning tonight: artificial intelligence is about to make cyber criminals far more dangerous. One of Australia's most respected cyber security figures has told 7NEWS, AI has transformed [...]

Exclusive: The Gentlemen strikes Sharp Office as company confirms incident investigation

A ransomware group claims to have hacked a Broadmeadow-based office technology supplier that works with Newcastle Airport and Royal Life Saving … [...]

Australian Cyber Aware - As It Was 2608 - August 2026

This monthly review provides a curated summary of cybersecurity, privacy, AI, fraud, governance, risk, and compliance developments in Australia and … [...]

Australians to gain greater control over compromised identity documents with new IDLock scheme

The Albanese government will introduce a new myGov service allowing Australians to block, unblock, and monitor the use of eligible identity documents … [...]

Late patching of Metabase SQLi bug claims Sydney's Mathspace

Key points Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted instance … [...]

ACMA fines Telstra for SIM swapping prevention misses

Key points ACMA has fined Telstra $277,000 for failing to use required identity authentication processes to prevent SIM swapping fraud. • The fraud … [...]

Vocus hit by Australia Singapore Cable break

Key points Vocus is grappling with a cable break on its Australia Singapore Cable (ASC) system between Perth and Singapore, following a shunt fault on … [...]

Tabcorp appoints new CISO

Key points Tabcorp has named Maxine Harrison as its new chief information security officer, following the former leader's departure in July. • Harrison … [...]

Hundreds of old, vulnerable Exchange servers remain in Australia

Key points 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft's … [...]

'Now measured in the millions': The common process being used to scam Australians

in brief Scammers are exploiting the growing use of CAPTCHAs to trick people into running malicious code outside their browser. • An expert has practical … [...]

Australian Cyber Incidents and Audits Reports

September 2026 so far

Auto-ITConfirmed 15-Sep-26 AU VIC
Exclusive: Aussie software firm Auto-IT confirms customers compromised by Storm ransomware attack
Maker of dealer management software responds to dark web hacking claims, saying a “small number of Auto-IT customer environments” were impacted by an unauthorised external party. On 18 August, the threat actor Storm, started listing Australian car dealerships and auto and machinery suppliers. Among the first were Westco Motors Cairns, alongside Ramsey Bros and Penfold Motors. The Sharp Motor Group, Agrimac, and Macquarrie followed. 

St James Anglican SchoolConfirmed 15-Sep-26 AU WA
Student photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attack
St James Anglican School, in Perth’s north, identified a cyber breach involving unauthorised access into its computer systems. Hackers copied names, addresses, emails, phone numbers, bank account details, student medical records and photographs of current and former students enrolled at the school since 2015, according to The West Australian. 

Penfold MotorsConfirmed 14-Sep-26 AU VIC
Exclusive: Penfold Motors latest car dealer to fall victim to the Storm ransomware group
Victorian car dealership Penfold Motors says it is contacting customers after hackers compromised their contact and vehicle details. Data published so far includes staff efficiency reports, customer details, vehicle identification numbers, and tax invoices. 

Way ForwardConfirmed 10-Sep-26 AU NSW
Exclusive: Not-for-profit Way Forward suspends payments following external cyber incident
The New South Wales registered charity Way Forward has disclosed that its payment systems have been suspended following a third-party cyber incident.

Sharp OfficeConfirmed 09-Sep-26 AU VIC
Exclusive: The Gentlemen strikes Sharp Office as company confirms incident investigation
The ransomware group known as The Gentlemen has targeted Sharp Office, a Hunter Region office technology specialist, as its latest Australian victim.

MathspaceConfirmed 08-Sep-26 AU NSW
Late patching of Metabase SQLi bug claims Sydney's Mathspace
Unknown attackers exploited a critical vulnerability in the Metabase business intelligence (BI) tool to breach the online mathematics learning platform Mathspace. Stolen data includes user IDs, usernames, first and last names, email addresses and other login-related information for students, staff, parents and guardians.

Verve PortraitsPublished 08-Sep-26 AU VIC
Exclusive: Verve Portraits data allegedly compromised by Settra ransomware attack
Threat actor Settra has listed the Victorian-based photography business Verve Portraits, claiming that 105 GB of data was exfiltrated. Settra provided summaries of the information and files claimed. 

MacquarriePublished 08-Sep-26 AU VIC
Exclusive: Machinery management specialist Macquarrie investigating data breach after ransomware claims
The Storm ransomware group continues to target Australian companies, this time adding the Victoria-based Macquarrie Corporation to its leak site last week. Sample images, including a passport, tax file declaration, invoice and other documents, were provided as evidence.

Telstra03-Sep-26 AU ACMA Telcommunication 
ACMA fines Telstra for SIM swapping prevention misses
Telstra has been fined $277,000 by the Australian Communications and Media Authority (ACMA) for not using required identity authentication processes to prevent SIM swapping fraud. In addition to the penalty, the ACMA has accepted court-enforceable undertakings from Telstra to strengthen its fraud prevention processes and improve training for customer-facing staff. 

 

If you believe any information in this post is inaccurate or incomplete, please contact us so we can review the matter. Parties with additional relevant information relating to the incident are also invited to get in touch.

Australian InfoSec Incidents and Audits Issues

NZ Incident: KillSec claims breach of NZ medical supplier | Cyberdaily.au

NZ Incident – Medical Ransomware Attack, 13 February 2025: KillSec claims ransomware attack on New Zealand based Obex Medical. While the exact details of the breach remain unclear, this latest incident highlights the persistent threat of ransomware groups, particularly those focused on industries like healthcare.

Loading

Information Security Memes