Select Page

Australian Cyber Aware – As It Was 2608 – August 2026

Australian Cyber Aware – As It Was 2608 – August 2026

 

Australian Cyber Aware August 2026 News

This monthly review provides a curated summary of cybersecurity, privacy, AI, fraud, governance, risk, and compliance developments in Australia and New Zealand. It includes notable security and privacy incidents, regulatory and legislative updates, audit findings, and other industry news relevant to business and government audiences.

This report may be used and shared within an organisation for internal awareness and educational purposes. Australian Cyber Aware retains the intellectual property rights to the compilation, selection, analysis, commentary, and presentation of the content. No part of this report may be reproduced, redistributed, republished, incorporated into a commercial product or service, or otherwise used for commercial gain without prior written permission.

This post may be updated as more news or reports are discovered. You can access the latest version on the Australian Cyber Aware website.

Australian Cyber Aware - Flipboard

Commentary August 2026

August saw continued cyber incidents across Australia and New Zealand, but the biggest developments were in privacy reform, identity protection, and AI governance. Proposed Privacy Act reforms, the introduction of the IDLock concept, and growing debate around facial recognition technology reinforced privacy’s growing importance as a business and governance issue.

At the same time, cyber incidents affecting healthcare providers, retailers, publishers, accommodation providers, and financial institutions demonstrated that operational disruption, regulatory scrutiny, and reputational impact remain key consequences of cyber events. Origin Energy, in an update, disclosed that several customer bank accounts were compromised.

Audit reports released during the month also highlighted ongoing weaknesses in governance, risk management, and legacy technology environments.

Pick of the Month

YouTube player

The Australian Government’s proposed Privacy Act reforms, “Privacy Reform – Consultation on Exposure Draft legislation“, are likely to have a greater long-term impact than any individual cyber incident reported this month. The reforms seek to strengthen privacy rights, improve identity protection measures, and increase transparency around how personal information is handled.

Major reforms included in Tranche 2:

  1. Fair and reasonable test – A single overarching test replaces existing APP rules on collection, use and disclosure, preventing organisations from gathering more data than necessary or using it in unexpected ways.
  2. Right to erasure (limited to large digital platforms) – Individuals may request deletion of their personal information from platforms meeting thresholds such as $500 million in group revenue or 2.5 million Australian end‑users.
  3. Stronger consent standards – Consent must be voluntary, informed, current, specific and unambiguous, ruling out bundled consents and pre‑ticked boxes.
  4. Restrictions on trading personal information – Businesses cannot trade personal data without clear permission, covering shopping habits, online interests and location data.
  5. 72‑hour data breach notification – Entities must notify the OAIC within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has occurred.
  6. Expanded fraud and breach‑response obligations. – Organisations must maintain breach‑response practices and take reasonable steps to contain harm.
  7. Updated definitions of personal information – The definition is broadened to include behavioural, inferred and device‑generated data.
  8. Introduction of IDLock – A new digital identity protection service allowing Australians to block, unblock and monitor identity document use via myGov

Incidents

August 2026 saw a steady flow of publicly reported cyber and privacy incidents across Australia and New Zealand, affecting organisations in sectors including healthcare, finance, retail, telecommunications, accommodation, publishing, real estate, and professional services.

Several incidents involved the exposure of personal or sensitive information, making confidentiality breaches of PII the highest cyber business risk for organisations.

Judgements and Findings

Bendigo and Adelaide Bank has admitted breaching its Banking Executive Accountability Regime (BEAR) obligations in relation to a 2023 cyber incident affecting its Alliance Bank business and has agreed to an $8 million penalty sought by APRA. The case reminds organisations that cyber security failures can result in regulatory consequences when they cannot demonstrate effective management of their obligations.

Government Audits

After the rush of end-of-financial-year reports, some agencies are starting to release audit results: NSW and Tasmania

A key theme this year, including the root cause of the Telstra outage, is that organisations must take legacy systems seriously at all levels. Failing to audit devices, review vendor support contracts, invest and manage risks is a serious breach of “reasonable steps” security practices.

Standards and Regulation

Privacy Reform – Consultation on Exposure Draft legislation, been covered in the Pick of the Month, has had a lot of press, and will continue to. Responses are due 18th September 2026.

OAIC Publishes Updated Guidance on Facial Recognition Technology for Australia – Cyber Law Watch. The updates apply to Australian Privacy Principle (APP) entities considering using facial recognition technology in high-volume, publicly accessible physical spaces such as retail shopfronts..

📅 10 December 2026 Privacy Compliance Deadline – APP entities that use personal information in ADM with the potential to affect rights or interests will be required to provide information in their privacy policies about the kinds of personal information used and the kinds of decisions made using ADM.

Looking Ahead

September is likely to be dominated by Privacy Act reform discussions, identity protection initiatives, AI governance, and the practical implications of emerging regulatory expectations. Organisations should expect increased attention on privacy management, third-party risk, and responsible use of AI technologies.

From an Australian Cyber Aware perspective, I will release the Regulation and Enforcement Page, similar to the Security Incident and Audit Lists but focused on current regulations and actions authorities have taken to enforce the laws and regulations..

Please feel free to comment and provide suggestions.

Be Safe, not too safe” – Steve…K.


Publicly Reported Incidents for August 2026

YouTube player

Claim Status: Confirmed = Acknowledged by organisation/public statement/regulator | Published = Published in mainstream or reputable media | Claim = Leak-site claim only, unverified | Withdrawn = The claim has been withdrawn | Denied = The victim has formally denied the claim | Unknown = No corroborating evidence has been found

NOTE: Claimed, withdrawn, denied, and unknown listings may be extortion events with no factual basis to believe that an actual incident occurred.

Zenith TechnologyClaim 30-Aug-26 NZ
[Unconfirmed] New Zealand Zenith Technology has been listed by Zawoo as a ransomware victim
Threat actor Zawoo listed New Zealand-based Zenith Technology as a victim and provided sample files containing medical information.

TixelConfirmed 29-Aug-26 AU VIC
Second-hand ticket marketplace Tixel confirms customer information stolen in data breach
Melbourne-based ticket resale platform, Tixel, has notified users that their email addresses and mobile numbers may have been accessed after an attacker exploited a zero-day vulnerability in its third-party analytics provider, Metabase.

Sharp Motor GroupConfirmed 28-Aug-26 AU NSW
Exclusive: Sharp Motor Group confirms third-party cyber incident in wake of ransomware claims
The Sharp Motor Group is aware of the hacker’s claims and is actively investigating the incident. Threat actor Storm listed the company on 24-Aug-26 on their breach site. As evidence, Storm provided screenshots of driver licences, a customer list with names/contact details/VIN numbers, along with a range of internal documents.

DigiGround Claim 28-Aug-26 AU NSW
[Unconfirmed] Qilin’s latest victim post puts DigiGround in the extortion spotlight
A ransomware-linked post has named Sydney-based web development company, DigiGround, as a new victim associated with Qilin. No details of evidence of the breach were posted.

The Frame GroupClaim 29-Aug-26 AU NSW
[Unconfirmed] New South Wales ICT Consulting firm, The Frame Group, has been listed by Qilin as a victim
Qilin ransomware group posted an allegation tied to the ICT consulting firm, The Frame Group. No evidence has been presented to support the claim.

Confirmed 28-Aug-26 AU NSW
Sydney-based telco employee accused of selling customer data
Financial Crimes Squad detectives have charged a telecommunications employee with allegedly accessing customer information without authorisation and selling it to criminal groups.

Claim 27-Aug-26 AU NSW
[Unconfirmed] A victim entry tied to health.nsw.gov.au describes 103 extracted emails
A new ransomware listing has put a health-related domain into the public record, but the facts remain narrow. Medusalocker is named in connection with a victim entry labelled Health, and 103 emails are said to have been extracted from health.nsw.gov.au. Public information does not establish the intrusion method, the initial access vector, or whether any wider data types were affected.

Agrimac Claim 27-Aug-26 AU VIC
[Unconfirmed] Storm has just published a new victim: Agrimac
Victorian agribusiness Agrimac has been listed on threat actor Storm’s breach site. No details of the breach are available at this time.

Hachette AustraliaConfirmed 27-Aug-26 AU, NZ
Aussie publisher Hachette restoring systems following ‘detection of unauthorised activity’ on network
Hachette bookstores are facing stocking delays in the wake of a cyber attack, as the publisher says a timeline for return to full operations is impossible to judge.

New Zealand Sotheby's International RealtyPublished 24-Aug-26 NZ
Exclusive: New Zealand Sotheby’s International Realty investigating cyber security incident
Known only as 2019, the hacker posted details of a hack impacting New Zealand Sotheby’s International Realty on 18 August. The compromised data includes customer details such as names, email addresses, and physical addresses, which is currently being offered for sale.

Tower InsuranceClaim 22-Aug-26 NZ
[Unconfirmed] Coinbasecartel puts Tower Insurance Into Its victim feed
New Zealand-based Tower Insurance has been listed on the threat actor Coinbasecartel’s ransomware site. No details or evidence have been presented.

Quest Apartment Hotels

Confirmed 19-Aug-26 AU
Quest Apartment Hotels customers’ personal data exposed in security breach
In an email to customers, seen by ABC News, Quest Apartments Hotels said the compromised data related to records from before June 2025 and included full names, email addresses and other contact details.

Brighton East Dental ClinicPublished 18-Aug-26 AU VIC
Exclusive: Patient data potentially compromised in alleged dental clinic data breach
INC Ransom cyber extortion group shares patient X-rays, specialist reports, and correspondence on the dark web after claiming a breach of a Victorian dental clinic, Brighton East Dental Clinic.

SIA Medical Centre Published 18-Aug-26 AU VIC
Exclusive: SIA Medical Centre confirms it is investigating cyber incident involving patient data
Victorian-based SIA Medical Centre is responding to a ransomware incident after the Rhysida cyber extortion group claimed to have thousands of patient records.

Oz Hair and BeautyPublished 18-Aug-26 AU NSW
Exclusive: Oz Hair and Beauty confirms cyber incident
Oz Hair & Beauty was listed on the dark web leak site of a threat actor “xpl0itrs”, which claimed to have stolen 2,100,000 customer records containing names, email addresses, home addresses, phone numbers and the last four digits of active gift cards. The threat actor did not post any corroborating evidence.

Ramsey BrosClaim 18-Aug-26 AU SA
[Unconfirmed] Storm listing puts a farm-equipment dealer in the ransomware crosshairs
Threat actor Storm names South Australian farming equipment dealer Ramsey Bros as a victim. The report provided sample screenshots of files as evidence.

Westco Motors CairnsClaim 18-Aug-26 AU QLD
[Unconfirmed] Storm names motor dealer Westco Motors Cairns as ransomware victim
Westco Motors Cairns has appeared in a new victim listing associated with Storm, putting the Cairns dealership into the public frame of a ransomware and extortion event. Some screenshots of files were presented as evidence.

Might KingdomClaim 17-Aug-26 AU SA
[Unconfirmed] An extortion claim by Direwolf has been made against South Australian games developer Mighty-Kingdom
Threat actor Direwolf has made a claim against South Australian games developer Mighty-Kingdom. No clear evidence was posted in the claim.

Ollies PlaceClaim 14-Aug-26 AU NSW
[Unconfirmed] Ollies Place Kidswear has been listed by thegentlemen ransomware group
New South Wales retailer Ollies Place Kidswear has been listed on TheGentleman’s breach site. No details of the breach or sample files could be located.

MidlandPublished 14-Aug-26 AU NSW
Exclusive: Australian truck trailer company Midland among dozens of victims listed by Cl0p cyber extortion group
Midland was listed on 12 August, with Cl0p claiming to have accessed half a gigabyte of data, which the hackers claim includes project information and at least one database.

Nick ScaliConfirmed 14-Aug-26 AU NSW
Aussie furniture company Nick Scali discloses cyber incident
Furniture retailer Nick Scali has said it is investigating a security incident in a disclosure to the Australian Stock Exchange. The company was forced to take “certain systems” offline in the wake of a cyber attack, and customer orders were impacted.

3-point AustraliaClaim 13-Aug-26 AU VIC
[Unconfirmed] Ransomware group Storm publicly claimed responsibility for a cyberattack against 3-point Australia
Victorian project management consultancy 3-point Australia has been reported breached by threat actor Storm. Storm listed various documents, including passports, as evidence of the exfiltration.

Bendigo BankConfirmed 11-Aug-26 AU VIC
Bendigo and Adelaide Bank admits to breaching its BEAR obligations in relation to cyber incident
Bendigo and Adelaide Bank Limited (Bendigo Bank) has conceded it has breached its obligations under the Banking Executive Accountability Regime (BEAR) in relation to a 2023 cyber attack involving its Alliance Bank business. Accepts an $8 million penalty.

Asset Flooring GroupPublished 03-Aug-26 AU VIC
Exclusive: Qilin claims breach of Victoria-based flooring firm
Asset Flooring Group was listed on the dark web by the infamous Qilin ransomware group overnight, with the threat actor claiming to have stolen 45 gigabytes of data.

 

 


Government Audit Reports Australia August 2026

12-Aug-26 AU NSW
AONSW Multiple Agencies
Internal controls and governance 2026: grants, consultants, purchasing cards and technology
Less than half of agencies reported compliance with requirements to protect and govern their risk exposure. Some agencies did not assess risks from legacy systems that cannot be patched, increasing their exposure to cyber-attack.

Audit Tasmania12-Aug-26 AU TAS
AuditTas Finance Multiple Agencies
Auditor-General’s Report on the Financial Statements of State Entities 2025-26, Volume 1
Our audits continue to identify recurring weaknesses in core control disciplines. These issues have been reported repeatedly over several years and should no longer be regarded as emerging challenges. They are known risks requiring sustained management attention. This includes matters on cyber security and information technology. However, due to the sensitive nature of these matters, only limited detail has been included in the report to avoid identifying potential security vulnerabilities.

 

 


Cyber News of Australia August 2026

 

Mon, 31 Aug 2026
Facial recognition technology ‘scope creep’ is upon us, experts warn
A shopper walks into a supermarket and grabs a basket. By that time, a camera has scanned their face. That is what experts warn could be the new …

Mon, 31 Aug 2026
AFCA opens consultation on proposed Scam Rules | Australian Financial Complaints Authority (AFCA)
The Australian Financial Complaints Authority (AFCA) is inviting feedback from stakeholders on proposed changes to its Rules, that will enable it to …

Mon, 31 Aug 2026
What changes will be made under the federal government’s privacy law reform? | ABC NEWS

YouTube player

The federal government has unveiled plans to strengthen privacy laws. The proposed reforms take aim at identity fraud and give people the right to erase their data from online platforms. Associate Professor Katharine Kemp from the UNSW welcomes the changes and says it would bring Australian consumer privacy protections in line with European standards.

Mon, 31 Aug 2026
Australians to gain greater control over compromised identity documents with new IDLock scheme
The Albanese Government will introduce a new myGov service allowing Australians to block, unblock, and monitor the use of eligible identity documents …

Mon, 31 Aug 2026
Two WA Men Face Court Over Global Cybercrime Syndicate Allegations | 10 News

YouTube player

Two WA men have faced court, accused of masterminding of a sophisticated cyber-crime syndicate. The pair arrested following raids across three suburbs in a joint investigation between Australian police and the FBI.

Mon, 31 Aug 2026
New privacy laws target smart glasses and AI tech | 7NEWS

YouTube player

The Federal Government is developing new privacy laws targeting AI technology, including smart glasses and social media platforms. The proposed measures include expanding the Credential Protection Register through a new service called ID Lock, available via the MyGov app in 2024, which has already blocked over 830,000 fraud attempts. The laws will also give Australians the right to demand social media companies erase their online information, while the eSafety Commissioner advocates for restrictions on smart glasses technology, including potentially blurring faces, visible recording indicators, or outright bans.

Mon, 31 Aug 2026
ASX creates deputy CISO role
Key points The ASX has created a new deputy chief information security officer role, with Hanlie Botha appointed as its first holder. • Botha joins ASX …

Sat, 29 Aug 2026
Bendigo and Adelaide Bank admits to breaching its BEAR obligations in relation to cyber incident | APRA
Bendigo and Adelaide Bank Limited (Bendigo Bank) has conceded it has breached its obligations under the Banking Executive Accountability Regime …

Sat, 29 Aug 2026
Mopping up AI Slop: Fair Work Commission taking ac… | Clayton Utz
What you need to know On 24 August 2026, Justice Hatcher, President of the Fair Work Commission (FWC), released a Guidance Note on the use of …

Fri, 28 Aug 2026
Busted! Alleged Aussie hackers linked to TeamPCP arrested in joint AFP-FBI-WAPF operation
Two men in their early 20s are to face a total of 14 charges for their alleged part in a global cybercrime organisation. • Fri, 28 Aug 2026 • …

Fri, 28 Aug 2026
Latest News – NSW Police Public Site
Financial Crimes Squad detectives have charged a telecommunications employee with allegedly accessing customer information without authorisation and …

Fri, 28 Aug 2026
Sydney-based telco employee accused of selling customer data
Key points A 30-year-old telco employee has been charged over allegedly accessing customer data and selling it to “criminal groups”. • NSW Police made …

Thu, 27 Aug 2026
APRA and ASIC warn frontier AI awareness must turn to action | APRA
The Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC) are urging financial market …

Thu, 27 Aug 2026
Aussie publisher Hachette restoring systems following ‘detection of unauthorised activity’ on network
Bookstores are facing stocking delays in the wake of a cyber attack, as the publisher says a timeline for return to full operations is impossible to …

Tue, 25 Aug 2026
Report: Australia’s transport sector underprepared for risk of cyber attack
Less than half of respondents in a recent survey polling the logistics industry said they felt prepared to face a cyber security incident. • Tue, 25 …

Tue, 25 Aug 2026
Minister to launch smart device security labelling pilot at Connecting Technology Summit
The conversation around securing connected devices in Australia is entering its next phase and smart product vendors and manufacturers are preparing …

Tue, 25 Aug 2026
NSW mandates facial recognition in gaming reform package
Key points NSW will make facial recognition technology mandatory for hotels and clubs with gaming machines, tied to a statewide exclusion register …

Tue, 25 Aug 2026
Automated decision-making transparency under the Privacy Act: are you prepared for 10 December 2026?
From 10 December 2026, privacy policies will be required to include additional information about how APP entities use personal information in any …

Tue, 25 Aug 2026
Australian Privacy Commissioner Finds Health Firms Track Patients’ Searches Without Obtaining Consent – Cyber Law Watch
The Australian Privacy Commissioner has determined that Monash IVF and a telehealth company have interfered with the privacy of website visitors via …

Mon, 24 Aug 2026
Exclusive: New Zealand Sotheby’s International Realty investigating cyber security incident
Prolific hacker 2019 claims hack of a luxury Kiwi real estate firm, but the company says the hacker is overstating the extent of the breach. • Mon, 24 …

Sat, 22 Aug 2026

YouTube player

Public backlash over police AI surveillance trial | A Current Affair
An Australian-first trial of live facial recognition technology in WA has led to 18 arrests in just seven days, but privacy experts are sounding the alarm.

Sat, 22 Aug 2026
Origin energy data breach update | Slump in Inghams’ annual profit

YouTube player

An update on last month’s Origin Energy data breach, which impacted around 900 thousand customers. The company says 60 full bank account numbers and 100 identity document numbers were accessed, along with 15 thousand numbers linked to government concession schemes. The original breach exposed names, addresses, dates of birth and partial credit card and bank details. SBS News is Australia’s trusted news source for the latest news from Australia and across the world.

Sat, 22 Aug 2026
The industry speaks: Scam Awareness Week 2026
The theme for this year’s Scam Awareness Week – which runs from 24 to 28 August – is “No one’s just a number”, and that’s certainly true of the …

Fri, 21 Aug 2026
Have I Been Pwned: Oz Hair and Beauty Data Breach
Have I Been Pwned In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently …

Fri, 21 Aug 2026
Dozens of Origin Energy customers’ full bank details, ID numbers accessed in July breach
Origin Energy says as many as 60 customers had their full bank account numbers accessed by a hacker in July. Last month, Origin confirmed a major …

Fri, 21 Aug 2026
Exclusive: Ransomware newcomers list South Australia’s Ramsey Bros as hacking victim
The Storm ransomware group claims to have hacked an Australian farm machinery supplier and has allegedly published customer data and vehicle …

Fri, 21 Aug 2026
Oz Hair and Beauty confirms cyber incident to customers
Aussie hair and beauty business Oz Hair and Beauty has disclosed to customers that it has suffered a cyber incident. • Thu, 20 Aug 2026 • …

Thu, 20 Aug 2026
NSW drivers licence photos could be part of national database under new laws
The New South Wales government is planning to join a national facial recognition service, aimed at preventing identity fraud, as part of a wider bill …

Thu, 20 Aug 2026
Quest Apartment Hotels customers’ personal data exposed in security breach
Quest Apartment Hotels says it is investigating a security breach that has affected customers’ personal data. In an email to customers, seen by ABC …

Wed, 19 Aug 2026
Fake ABC News articles are promoting scams. The money leads to an international fraud network
Hooked up to a drip and awaiting surgery, Rodger was running out of options. “You guys have all of my money tied up,” he texted his broker. “I need … …

Tue, 18 Aug 2026
Origin Energy hack traced to Accenture’s Manila call centre
Authorities have traced the Origin Energy cyber hack that exposed the personal data of close to a million Australians to a Manila call centre.

Tue, 18 Aug 2026
Exclusive: Patient data potentially compromised in alleged dental clinic data breach
INC Ransom cyber extortion group shares patient X-rays, specialist reports, and correspondence on the dark web after claiming a breach of a Victorian …

Tue, 18 Aug 2026
Exclusive: SIA Medical Centre confirms it is investigating cyber incident involving patient data
A Victorian medical centre is responding to a ransomware incident after the Rhysida cyber extortion group claimed to have thousands of patient …

Tue, 18 Aug 2026
Exclusive: Oz Hair and Beauty confirms cyber incident
Threat actors have claimed a cyber attack on an Australian beauty retailer, having posted data they allegedly stole from the company. • Tue, 18 Aug …

Tue, 18 Aug 2026
CBA upgrades its third-party risk management
In summary, CBA is five to six weeks from migrating 5000 suppliers onto ServiceNow’s third-party risk management platform, completing a shift that …

Tue, 18 Aug 2026
Widespread Wearables: what the $89 Kmart smart glasses mean for your organisation
The $89 Anko Smart Glasses sold out nationally in under one week, bringing discreet recording capability to the mass market. With the…

Tue, 18 Aug 2026
Multiple Governments Issue Joint Alert on North Korean IT Workers
On July 31, 2026, authorities from the United States, Japan, the Republic of Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New…

Tue, 18 Aug 2026
Coles and Woolworths test facial recognition technology
Coles and Woolworths have conducted tests of facial recognition technology, but it is unclear if either supermarket will be implementing it in stores. …

Mon, 17 Aug 2026
Facebook Marketplace warning as woman loses $10k after buying stolen car
Leanne Roney’s “heart dropped” when a woman appeared at her door and announced the car in her driveway was stolen. But her quest to recoup the $9,000 …

Mon, 17 Aug 2026
Exclusive: Aussie kidswear brand launches investigation following hacker claims
An Australian kidswear retailer has confirmed that it is aware of claims of a cyber incident and has subsequently launched an investigation. • Mon, 17 …

Mon, 17 Aug 2026
AI deepfake scams ‘an emergency in the making’ as ASIC reports rise in false investment endorsements
Scammers are using impersonations of celebrities, politicians and trusted public figures to promote fake investment schemes, with the corporate …

Mon, 17 Aug 2026
South Australia To Launch Royal Commission Into Artificial Intelligence | 10’s Late News

YouTube player

As concerns grow about the threat of Artificial Intelligence, South Australia is launching a wide-ranging royal commission into its possible threats.

Mon, 17 Aug 2026
WA Police AI mass surveillance face-scanning trial attracts criticism | ABC NEWS

YouTube player

Experts and legal advocates have raised privacy concerns about an Australian-first trial of live AI facial recognition technology by WA Police. National AI reporter Cameron Wilson says there are concerns about accuracy and whether the technology can successfully identify the faces of First Nations people.

Mon, 17 Aug 2026
Top 10 most impersonated Australians in AI deepfake scams | 9 News Australia

YouTube player

There are fresh warnings to think twice before clicking on celebrity investment pitches, as AI deepfake scams rise. On the eve of Scam Awareness Week, Money Editor Effie Zahos reveals the 10 most impersonated Aussies and how you can stay safe.

Mon, 17 Aug 2026
26-195MR ASIC warns scammers are using AI to spin vast webs of deception | ASIC
ASIC is warning Australians that a quick online search is not enough to verify investment opportunities as scammers use generative AI to create vast …

Sat, 15 Aug 2026
Boardroom Brief Week Commencing 10 August 2026
In this edition, we cover joint guidance from the Australian Signals Directorate (ASD) and the Australian Institute of Company Directors (AICD) on …

Sat, 15 Aug 2026
Perspectives on Cyber Risk 2026: The AI edition
Each year, for over a decade, we have asked Australian senior decision-makers how they see cyber risk, what they are doing about it, and from where…

Fri, 14 Aug 2026
Responsible AI use for not-for-profits
Microsoft Copilot is gaining traction across the not-for-profit (NFP) sector, offering appealing benefits: reduced administrative effort, more …

Fri, 14 Aug 2026
OAIC Publishes Updated Guidance on Facial Recognition Technology for Australia – Cyber Law Watch
The Office of the Australian Information Commissioner (OAIC) has published updated guidance for entities considering using facial recognition …

Fri, 14 Aug 2026
AUSCERT Week in Review for 14th August 2026
Friday 14 August 2026 A routine attempt to secure a place in a popular gym class has highlighted a growing challenge in the age of artificial …

Fri, 14 Aug 2026
AI scribe makes up drug use accusation during patient consultation | ABC NEWS

YouTube player

There are warnings that AI scribes are hallucinating details about patients during consultations with doctors. A scribe incorrectly recorded a woman as using illicit drugs, while another listed the wrong breast for a breast cancer patients.

Fri, 14 Aug 2026
Nick Scali manually processes orders after cyber breach forced systems offline
The ASX-listed company says it is still investigating the cyber breach as it brings its systems back online. The post Nick Scali manually processes …

Thu, 13 Aug 2026
AICD submission on SOCI Act proposed reforms
Measure 1 Exemptions Framework: We supported the development of a clearer and more flexible exemptions framework for entities, or classes of …

Thu, 13 Aug 2026
Foreign control of AI vendors a board-level risk, ASD says
Australian boards should treat the foreign ownership, control and influence of their artificial intelligence (AI) providers as a cyber risk in its …

Thu, 13 Aug 2026
Super funds to test coordinated cyber attack response
GNGB chief executive Michelle Bower said the exercise had become a bellwether for cooperation across the sector on cyber preparedness. The Gateway …

Tue, 11 Aug 2026
Exclusive: Kairos ransomware lists Warwick Fabrics NZ as hack victim
Alleged 386-gigabyte data breach includes employee passports, medical reports, and salary data. • Tue, 11 Aug 2026 • Security *]:clear-none …

Tue, 11 Aug 2026
APRA seeks $8m Bendigo cyber control penalty
The Australian Prudential Regulation Authority (APRA) has commenced Federal Court proceedings against Bendigo and Adelaide Bank, seeking approval for …

Tue, 11 Aug 2026
AFP assessing report in connection with Perth cable faults
The Australian Federal Police is assessing a report of a potential crime after the owner of two undersea cables laid in protection zones near Perth …

Mon, 10 Aug 2026
Two subsea communication cables damaged off Perth coast in ‘concerning development’
Two subsea cables off the coast of Perth, vital for international communications, suffered a fault over the weekend, and the company that owns them …

Mon, 10 Aug 2026
Cybersecurity concerns abate ahead of national census
Australians providing sensitive information about their sexual orientation, religion and income in the upcoming census survey are being reassured …

Mon, 10 Aug 2026
Privacy concerns raised over Australian-first live AI police face scanning trial
An Australian-first trial of live AI facial recognition technology by a police force has been criticised by privacy experts and legal advocates. The …

Mon, 10 Aug 2026
Origin Energy data leak cybersecurity lessons have experts worried
Three weeks ago, Origin Energy told 900,000 former and current customers that their information had been exposed in a data breach. The major …

Mon, 10 Aug 2026
What we know about the AI agent hack on a gym booking system | ABC NEWS

YouTube player

An AI agent has hacked a gym website in Australia, becoming the first known case of an autonomous AI cyber attack. The AI assistant found a way to book gym classes further in advance than the gym allowed and even kicked someone out of the waiting list. ABC NEWS AI reporter Cam Wilson explains why this case should raise alarm bells about the vulnerabilities of companies, services and websites when AI goes rogue.

Sun, 09 Aug 2026
AI assistant hacks gym website in first known Australian autonomous cyber attack
Andrew asked his personal assistant to book him a spot in one of his gym’s coveted morning classes. It was a task he thought was well suited to this …

Sat, 08 Aug 2026
Home Affairs warns of scams as 2026 census approaches
Multiple government departments have issued warnings ahead of the 2026 census, cautioning people to stay vigilant as scammers look to take advantage …

Thu, 06 Aug 2026
Health regulator AHPRA apologises for breaching doctor privacy in bulk email
The national healthcare watchdog has inadvertently identified more than 100 doctors, nurses and other practitioners who were offered addiction and …

Wed, 05 Aug 2026
Always watching: Victorian state government targets spying bosses and online bullies
Victoria’s Labor government to introduce laws to unmask cyber bullies and stop bosses from spying on workers. • Mon, 20 Jul 2026 • …

Wed, 05 Aug 2026
Exclusive: Alleged Top Education Group data breach could impact thousands
A prominent hacker is claiming to have breached the company behind the Australian National Institute of Management and Commerce, with student …

Wed, 05 Aug 2026
Exclusive: Downies Collectables continues to respond to ransomware incident
Investigations by Aussie rare coin supplier remain ongoing, as cyber extortionists continue to apply pressure on the dark web. • Tue, 04 Aug 2026 • …

Wed, 05 Aug 2026
Exclusive: 2019 allegedly hacks BestPriceTravel Australia
A notorious threat actor has claimed a cyber attack on an Australian online travel agency, listing the company on a dark web hacking forum, having …

Mon, 03 Aug 2026
Exclusive: Partnered Health responds to INC Ransom data breach claims
Cyber extortion group INC Ransom has listed Australian GP network Partnered Health on its darknet leak site, with at least 21 clinics potentially …

Mon, 03 Aug 2026
Patients deserve right to refuse AI scribes, watchdog warns
Australians should have a legal right to refuse the use of AI scribes during medical appointments without being denied care, as a digital rights …

Mon, 03 Aug 2026
Exclusive: Qilin claims breach of Victoria-based flooring firm
Threat actors have claimed a cyber attack on a Victoria-based flooring specialist, allegedly having stolen data. • Mon, 03 Aug 2026 • …

Sun, 02 Aug 2026
Australian Cyber Aware – As It Was 2607 – July 2026
Sat, 01 Aug 2026 The life of an information security chief just got a lot faster Subscribe to gift this article Gift 5 articles to anyone you choose …

Sat, 01 Aug 2026
The life of an information security chief just got a lot faster
Subscribe to gift this article Gift 5 articles to anyone you choose each month when you subscribe. Already a subscriber?

Sat, 01 Aug 2026
Privacy Commissioner publishes updated guidance on facial recognition in retail spaces
The Office of the Australian Information Commissioner (OAIC) has published updates to its guidance for Australian Privacy Principle (APP) entities …

Sat, 01 Aug 2026
In brief: cyberthreat detection and reporting in Australia
Threat detection and reporting Internal policies and procedures What policies or procedures must organisations have in place to protect data or …

 


Australian Information and Cyber Security Videos 2026

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

Australians to gain greater control over compromised identity documents with new IDLock scheme

The Albanese government will introduce a new myGov service allowing Australians to block, unblock, and monitor the use of eligible identity documents … [...]

Digital platforms to be targeted as part of NSW crackdown on organised crime operations

NSW’s Premier has announced a raft of measures to combat the facilitation of serious crimes, such as gang-related murder. • Mon, 07 Sep 2026 • … [...]

Late patching of Metabase SQLi bug claims Sydney's Mathspace

Key points Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted instance … [...]

ACMA fines Telstra for SIM swapping prevention misses

Key points ACMA has fined Telstra $277,000 for failing to use required identity authentication processes to prevent SIM swapping fraud. • The fraud … [...]

Vocus hit by Australia Singapore Cable break

Key points Vocus is grappling with a cable break on its Australia Singapore Cable (ASC) system between Perth and Singapore, following a shunt fault on … [...]

Tabcorp appoints new CISO

Key points Tabcorp has named Maxine Harrison as its new chief information security officer, following the former leader's departure in July. • Harrison … [...]

Hundreds of old, vulnerable Exchange servers remain in Australia

Key points 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft's … [...]

'Now measured in the millions': The common process being used to scam Australians

in brief Scammers are exploiting the growing use of CAPTCHAs to trick people into running malicious code outside their browser. • An expert has practical … [...]

Experts sound alarm on rise of fake digital IDs | 9 News Australia

There's a warning tonight about a rise in fake digital IDs being sold to teenagers. Cyber safety experts say it's putting vulnerable Victorians at risk of having their identities stolen. [...]

Aussie government announces cyber security labelling scheme for smart devices

The federal government has launched a pilot scheme that will allow Australians to compare the cyber security of smart devices before buying them. • … [...]

The Next Wave of Australian Privacy Reform: Key Pr... | Clayton Utz

Modernised Definitions: Casting a Wider Net The Exposure Draft Bill would amend and clarify some of the foundational definitions in the Privacy Act … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading