Select Page

Australian Cyber Security News September 2026 | Breaches, AI, Privacy & Risk

Australian Cyber Security News September 2026 | Breaches, AI, Privacy & Risk

 

Australian Cyber Aware Monthly News

This monthly review provides a curated summary of developments in information and cybersecurity, privacy, AI, fraud, governance, risk, and compliance in Australia. It includes notable security and privacy incidents, regulatory and legislative updates, audit findings, and other industry news relevant to business and government audiences.

This report may be used and shared within an organisation for internal awareness and educational purposes. Australian Cyber Aware retains the intellectual property rights to the compilation, selection, analysis, commentary, and presentation of the content. No part of this report may be reproduced, redistributed, republished, incorporated into a commercial product or service, or otherwise used for commercial gain without prior written permission.

This post may be updated as more news or reports are discovered. You can access the latest version on the Australian Cyber Aware website.

Australian Cyber Aware Flipboard

YouTube player

Commentary September 2026

If there was a dominant theme throughout September, it was artificial intelligence. Hardly a day passed without headlines predicting that AI would transform industries, eliminate jobs, create unprecedented risks, or fundamentally reshape society. I have a bit to say and a challenge for you all in my “Pick of the Month”.

At the same time, cyber incidents affecting healthcare providers, retailers, publishers, accommodation providers, and financial institutions demonstrated that operational disruption, regulatory scrutiny, and reputational impact remain key consequences of cyber events.

Beyond the AI headlines, several incidents reinforced a more traditional cybersecurity lesson. Organisations continue to be impacted by poor security hygiene, third-party failures, and inadequate protection of personal information. The Origin Energy account compromise and the ongoing Quest Hotels breach response demonstrate that customer trust can be damaged long after the initial incident has occurred.

As for regulation, Telstra and Amaysim ran into the ACMA for not doing enough to stop faults in thier SIM transfering processes, with just under half a million dollars in fines being issued.

Audit reports released during the month also highlighted ongoing weaknesses in governance, risk management, and legacy technology environments.

Pick of the Month

Artificial Intelligence continued to dominate headlines throughout September, but not always for the right reasons. Almost every month now brings claims that AI will revolutionise entire industries, eliminate jobs, transform economies, or create unprecedented security risks. While some of these predictions may eventually prove correct, much of the current coverage sits somewhere between optimism, fear and outright hype.

A good example is the recent reporting around Medicare data appearing online. Much of the media immediately called the incident a “hack”, despite limited publicly available evidence that a sophisticated technical intrusion had actually occurred. In cybersecurity, words matter. A breach can occur through many different pathways, including misuse of legitimate access, phishing, poor security practices, insider activity or technical compromise. Calling every incident a hack may make headlines, but it can also distract from understanding what really happened and what controls might have prevented it.

That said, heightened media attention isn’t necessarily a bad thing. Public discussion raises awareness and encourages organisations to take their own exposure seriously. AI systems are becoming more capable, easier to access and easier to misuse. Organisations are already handling risks including unauthorised disclosure of sensitive information, AI-generated fraud and scams, deepfakes, automated social engineering, inaccurate AI outputs, intellectual property risks, and regulatory uncertainty. The threat is real, even when individual news stories may exaggerate certain aspects.

Business leaders must avoid both extremes. AI is neither a magical cure to every business problem nor an existential threat to avoid entirely. Like most technologies, it brings significant opportunities and significant risks. The organisations that benefit most will approach AI with curiosity, caution, and clear governance rather than hype or panic.

“Regulators, mount up” – Young Guns 1988

As we continue to integrate AI into business and everyday life, perhaps it is time to start thinking about modern equivalents of Isaac Asimov’s famous Three Laws of Robotics. The Australian political landscape is abuzz with proposals to “regulate”, set “guardrails”, “self-regulate”, and take “measures” to address the risks and maximise the opportunities.

Laying my cards on the table, I’m not optimistic that vested interests and lobbying will allow any meaningful regulation or legislation. Still, it is good to see the conversations taking place. There is some great information available on the Australian government and business sites; give them a read:

My own starting point is deliberately simple:

If it is illegal for a human to do it, it should be illegal for an AI to do it.

This statement doesn’t solve every ethical challenge posed by artificial intelligence, but in my opinion it provides a practical foundation. AI should not become a loophole that lets organisations or individuals avoid accountability for actions society has already decided are unacceptable. Whether AI writes content, makes recommendations, interacts with customers, or analyses personal information, responsibility must ultimately remain with the humans who build, deploy, and use it.

What would be your basis, or three laws?

Regardless of what “rules” governments put in place, as a business owner, I still have to assess my own risks and opportunities, and take practical actions to protect my business.

Practical actions for business today

  1. Conduct an AI Information Risk Assessment with realistic treatments, across your business, from top to bottom; it is worth engaging experts.
    Do you have any information that needs extra protection? What could an AI do with that information? Combine it with other sources? What information do you use to make decisions? Do we use AI to make/suggest decisions? What information do we have exposed externally, and how? What information do we share, and with whom? Which suppliers use AI and how? What opportunities and benefits can AI bring to the business (spend time on this, important)
  2. Create an AI Acceptable Use Policy and regularly educate your staff.
    “A policy not communicated is worthless”

Even if you ban AI use now, you are just kicking the can down the road and potentially missing significant opportunities, especially around productivity. You are just a couple of clicks away from a user uploading your customer data spreadsheet to a public AI cloud. Just do the assessment.

GRC Calendar

  • 📅 10 December 2026 Privacy Compliance Deadline – APP entities that use personal information in ADM with the potential to affect rights or interests will be required to provide information in their privacy policies about the kinds of personal information used and the kinds of decisions made using ADM.

Looking Ahead

Looking ahead, artificial intelligence will almost certainly remain at the centre of media, public policy, regulatory, security and business discussions. The challenge for organisations is to move beyond the headlines and focus on practical governance. Understanding where AI is being used, what information it can access, and what risks it creates will become as important as managing privacy, cybersecurity and fraud risks today.

From an Australian Cyber Aware perspective, you will notice a shift in branding, new dedicated domain (https://AustralianCyberAware.com) and a clear focus towards business leader awareness.

Please feel free to comment and provide suggestions.

“Be Safe, not too safe” – Steve…K.


Publicly Reported Incidents for September 2026

Claim Status: Confirmed = Acknowledged by organisation/public statement/regulator | Published = Published in mainstream or reputable media | Claim = Leak-site claim only, unverified | Withdrawn = The claim has been withdrawn | Denied = The victim has formally denied the claim | Unknown = No corroborating evidence has been found

NOTE: Claimed, withdrawn, denied, and unknown listings may be extortion events with no factual basis to believe that an actual incident occurred.

YouTube player

 
 

Virtual Ideas Claim 30-Sep-26 AU NSW
[Unconfirmed] Lamashtu Group Claims Australian Victim Virtual Ideas With 40,000 Files Threatened for Release
New South Wales, 3D visualisation studio Virtual Ideas was added to the Lamashtu Group ransomware victim listed with the group claiming to hold around 40,000 files threatened for release. Sample images of files were provided as evidence.

James Fallon High SchoolConfirmed 25-Sep-26 AU NSW
NSW Department of Education and James Fallon High School: Department investigation concludes after cyber breach at Border high school
James Fallon High School in North Albury, NSW, experienced a cyber breach, prompting an investigation by the NSW Department of Education and Cyber NSW. The incident, traced to an external source outside the state, involved unauthorised access to a combination of school and personal data, including school policies, curriculum materials, and limited information on students, parents, carers, and staff

Stake trading platformConfirmed 25-Sep-26 AU NSW
Australian trading platform Stake caught in data breach
Australian-based trading and investment platform Stake has been caught in a data breach after a third-party partner company was hacked. In an email to customers about midday on Friday, Stake said personal information such as names, email addresses, phone numbers, postal addresses, tax status and tax country were compromised.

Zig Inge GroupClaim 24-Sep-26 AU VIC
[Unconfirmed] Qilin ransomware group claims Zig Inge Group as victim
Qilin has listed Victorian-based real estate and retirement living company Zig Inge Group on a it’s ransomware site. No supporting information published to support the claim.

NSW TransportClaim 23-Sep-26 AU NSW
[Unconfirmed] Ransomware group clop hits TRANSPORT-NSW.GOV.AU
The CLOP group claims to have attacked Transport for NSW. The leak post provides no specific details on what data was exfiltrated or the scope of the breach.

Thorndale FoundationClaim 16-Sep-26 AU NSW
[Unconfirmed] Thorndale Foundation has been listed by the ransomware group Qilin as a victim of their attack.
Thorndale Foundation is a disability support services organisation operating in Western Sydney and has been listed by threat actor Qilin as a victim. The attackers posted sample images of passports, staff and contractor clearances, and other documents as proof of the claim.

Reddrop GroupClaim 16-Sep-26 AU VIC
[Unconfirmed] Threat actor Qilin has posted a breach claim against an Australian independent supermarket chain.
The Reddrop Group, a prominent Victorian independent supermarket, has been listed as a victim of a cyberattack by the Qilin ransomware group. Qilin provided no published evidence to support the claim.

Leisure Coast KitchensClaim 16-Sep-26 AU NSW
[Unconfirmed] Leisure Coast Kitchens listed as a victim of Kairos ransomware group.
New South Wales’ Leisure Coast Kitchens has been named by the Kairos ransomware group on a leak site. As of 17 September 2026, no public confirmation from the company, regulators, or mainstream media has been identified, so the claim remains unverified.

Alchin Long GroupClaim 15-Sep-26 AU NSW
[Unconfirmed] TheGentlemen Ransomware Attack on Alchin Long Group
On September 15, 2026, the ransomware group The Gentlemen publicly claimed responsibility for a cyberattack against Alchin Long Group, a prominent Australian hardware conglomerate. The group posted an extortion notice threatening to leak sensitive data unless negotiations were initiated.

Auto-IT

Confirmed 15-Sep-26 AU VIC
Exclusive: Aussie software firm Auto-IT confirms customers compromised by Storm ransomware attack
Maker of dealer management software responds to dark web hacking claims, saying a “small number of Auto-IT customer environments” were impacted by an unauthorised external party. On 18 August, the threat actor Storm, started listing Australian car dealerships and auto and machinery suppliers. Among the first were Westco Motors Cairns, alongside Ramsey Bros and Penfold Motors. The Sharp Motor Group, Agrimac, and Macquarrie followed.

St James Anglican SchoolConfirmed 15-Sep-26 AU WA
Student photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attack
St James Anglican School, in Perth’s north, identified a cyber breach involving unauthorised access into its computer systems. Hackers copied names, addresses, emails, phone numbers, bank account details, student medical records and photographs of current and former students enrolled at the school since 2015, according to The West Australian.

Dome Gold MinesClaim 14-Sep-26 AU NSW
[Unconfirmed] Dome Gold Mines listed by The Gentlemen Ransomware Group
Dome Gold Mines was listed on The Gentlemen’s leak site. The Gentlemen claims it stole internal data. This is the group’s claim, not a confirmed finding.

Penfold MotorsConfirmed 14-Sep-26 AU VIC
Exclusive: Penfold Motors latest car dealer to fall victim to the Storm ransomware group
Victorian car dealership Penfold Motors says it is contacting customers after hackers compromised their contact and vehicle details. Data published so far includes staff efficiency reports, customer details, vehicle identification numbers, and tax invoices.

Way ForwardConfirmed 10-Sep-26 AU NSW
Exclusive: Not-for-profit Way Forward suspends payments following external cyber incident
The New South Wales registered charity Way Forward has disclosed that its payment systems have been suspended following a third-party cyber incident.

Sharp OfficeConfirmed 09-Sep-26 AU VIC
Exclusive: The Gentlemen strikes Sharp Office as company confirms incident investigation
The ransomware group known as The Gentlemen has targeted Sharp Office, a Hunter Region office technology specialist, as its latest Australian victim.

MathspaceConfirmed 08-Sep-26 AU NSW
Late patching of Metabase SQLi bug claims Sydney’s Mathspace
Unknown attackers exploited a critical vulnerability in the Metabase business intelligence (BI) tool to breach the online mathematics learning platform Mathspace. Stolen data includes user IDs, usernames, first and last names, email addresses and other login-related information for students, staff, parents and guardians.

Verve PortraitsPublished 08-Sep-26 AU VIC
Exclusive: Verve Portraits data allegedly compromised by Settra ransomware attack
Threat actor Settra has listed the Victorian-based photography business Verve Portraits, claiming that 105 GB of data was exfiltrated. Settra provided summaries of the information and files claimed.

MacquarriePublished 08-Sep-26 AU VIC
Exclusive: Machinery management specialist Macquarrie investigating data breach after ransomware claims
The Storm ransomware group continues to target Australian companies, this time adding the Victoria-based Macquarrie Corporation to its leak site last week. Sample images, including a passport, tax file declaration, invoice and other documents, were provided as evidence.

 


Australian Regulatory Actions September 2026

Amaysim30-Sep-26 AU ACMA Telecommunications
Amaysim and Ezee Mobile breach anti-fraud rules
Amaysim Mobile Pty Ltd (Amaysim) has paid a $138,600 penalty after failing to carry out mandatory ID verification checks before transferring mobile phone numbers from other telco providers.
The Telecommunications (Mobile Number Pre-Porting Additional Identity Verification) Industry Standard 2020 requires telcos to use an additional ID verification process before transferring a mobile number to their service. They must also publish information for consumers about where to report suspected fraudulent number transfers.

Telstra03-Sep-26 AU
ACMA Telecommunications
ACMA fines Telstra for SIM swapping prevention misses
Telstra has been fined $277,000 by the Australian Communications and Media Authority (ACMA) for not using required identity authentication processes to prevent SIM swapping fraud. In addition to the penalty, the ACMA has accepted court-enforceable undertakings from Telstra to strengthen its fraud prevention processes and improve training for customer-facing staff.

The Art Scene01-Sep-26 AU NSW
NSW District Court, Privacy Act
A Canva account at centre of legal fight over employee privacy
Australia’s new privacy laws have been used to prevent a business, The Art Scene, from destroying a former employee’s personal information, including family medical records, that were stored on a Canva account, in an unusual early application of the new rules.

 


Australian Audit Reports September 2026

30-Sep-26 AU WA
WAOAG Department of Water and Environmental Regulation
Services Contaminated Sites – Application Systems
The audit found that the Department of Water and Environmental Regulation‘s contaminated sites systems have significant weaknesses in information security, data integrity and system resilience. Confidential information, including the identities of people reporting potential contamination, was not adequately protected due to excessive user access, weak authentication controls and poor monitoring, while critical assessment data could be changed without validation and relied heavily on manual processes. The ageing Contaminated Sites System also suffers from limited functionality, poor integration with related systems, reliance on a single vendor resource and numerous long-standing cyber security vulnerabilities.
The Auditor General recommended strengthening access controls and data protection measures, improving data validation and monitoring, implementing modern authentication and vulnerability management practices, and progressing the replacement or modernisation of the legacy system to better protect information, improve regulatory compliance and ensure the continued availability of critical services

24-Sep-26 AU FED
ANAO Department of Health, Disability and Ageing Health
Artificial Intelligence and Medicare Benefits Integrity
The ANAO found that while the Department of Health, Disability and Ageing has largely effective enterprise-level governance arrangements for artificial intelligence, its use of AI to support Medicare Benefits Schedule (MBS) compliance is only partly effective. The department has not systematically assessed or managed the risks associated with AI being used by health providers, has limited assurance over whether AI is being used safely and in line with policy requirements, and did not fully apply better-practice governance, security, privacy and assurance controls to its own AI-enabled Medicare fraud detection system. The audit also found that the department makes relatively limited use of AI to combat an estimated $1.5 to $3 billion in annual Medicare provider non-compliance and has not assessed whether AI could be used more effectively to strengthen compliance activities.
The ANAO recommended that the department assess and manage AI risks in healthcare and Medicare claiming, strengthen governance and approval processes for AI systems, and improve assurance arrangements, including cyber security oversight, to ensure AI is used safely, responsibly and effectively.

 


Cyber News of Australia September 2026

Wed, 30 Sep 2026
ASIC to review banking sector AI use and customer impacts
Australia’s corporate ⁠regulator will formally review the country’s banking sector’s usage of AI in dealing with customers. The Australian Securities …

Wed, 30 Sep 2026
OpenAI agent accessed “credentials” via Medicare data portal
Key points OpenAI now admits the model that accessed the Medicare statistics portal ran commands and retrieved internal files and credentials, beyond …

Wed, 30 Sep 2026
Home Affairs orders gov-wide ‘legacy’ system stocktake within six months
Key points Home Affairs has ordered all federal departments and agencies to conduct a legacy technology stocktake within six months, until the end of …

Tue, 29 Sep 2026
OpenAI apologizes to Australia after its AI agents breached government sites
OpenAI on Monday apologized to the Australian government for not immediately notifying the country’s administration that its agents had breached some public services websites. The company also detailed how some of those breaches happened and outlined additional measures it is taking to assess the …

Tue, 29 Sep 2026
Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes
In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare …

Mon, 28 Sep 2026
The US could send Australian personal data to third countries under secret ‘partnership’
While the Albanese government stays silent on plans to hand citizens’ biometric data to the Trump administration, the Europeans have publicly …

Sat, 26 Sep 2026
Cyber Threat Landscape – Australia and New Zealand – CYFIRMA
Published On : 2026-09-25 EXECUTIVE SUMMARY A regional pattern with sector-specific expression Identity and access, not novel exploitation, is the …

Fri, 25 Sep 2026
OAIC’s action in relation to the 2023 Latitude Data Breach and information to update and assist individuals
On 10 May 2023, the OAIC commenced an investigation into the personal information handling practices of the Latitude group of companies[1] (Latitude). …

Fri, 25 Sep 2026
China seizes sensitive F-35 parts diverted from Australia
Washington | The Chinese government has taken possession of potentially sensitive F-35 stealth aircraft parts that were inexplicably diverted to Hong …

Thu, 24 Sep 2026
NAB restores systems following online outage impacting customers
Major Australian bank NAB has restored systems following online outages that prevented customers from using their services. • Thu, 24 Sep 2026 • …

Thu, 24 Sep 2026
OpenAI breach strengthens Australia’s case for tougher AI safety rules
An unprecedented breach of a government website by a rogue OpenAI agent will sharpen Australia’s push to impose stricter safety, transparency and …

Thu, 24 Sep 2026
VIDEO: Quest tells customers to replace passports after security breach | ABC NEWS

YouTube player

The hotel company, Quest, is warning customers they may need to replace their driver’s licences and passports. It comes after a cyber hack last month exposed swathes of personal information, impacting an estimated 2 million people.

Thu, 24 Sep 2026
VIDEO: Why did it take OpenAI three months to report the Medicare hack? | ABC NEWS

YouTube player

The federal government has raised concerns about uncontrolled and unauthorised AI activity after an AI model infiltrated a Medicare platform owned by Services Australia. The OpenAI agent accessed data not meant for public disclosure during a search for information on medical spending in Australia. AI reporter Cameron Wilson says the AI developer detected the breach during a sweep of activity logs in August after scrutinising massive volumes of data.

Thu, 24 Sep 2026
VIDEO: OpenAI agent hacked into Medicare to access data, prime minister says | ABC NEWS

YouTube player

Prime Minister Anthony Albanese has revealed an AI agent hacked into an Australian Medicare portal earlier this year. The OpenAI agent reportedly gained unauthorised access to private and public data on a site operated by Services Australia while conducting research into public spending. The Australian leader expressed ‘extreme concern’ to OpenAI CEO Sam Altman that his company took three months to notify the federal government.

Thu, 24 Sep 2026
Health data attack the ‘first’ government hack by autonomous AI, researchers say
A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say …

Thu, 24 Sep 2026
Australian Medicare data portal “infiltrated” by OpenAI agent
Key points An OpenAI agent gained unauthorised access to both public and non-public files on a Medicare statistics reporting portal, Anthony Albanese …

Wed, 23 Sep 2026
OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says
Prime Minister Anthony Albanese has revealed an AI agent hacked into an Australian Medicare data portal earlier this year. Speaking in New York, Mr …

Wed, 23 Sep 2026
Quest Apartment Hotels tells customers to replace passports and licences after security breach
Quest Apartments has advised customers affected by a data breach in August to replace their passports and driver’s licences after its investigation …

Mon, 21 Sep 2026
Hacked? Qantas investigating WhatsApp phishing reports
The Flying Kangaroo and a Sydney hotel warn customers not to share payment details following suspicious messages targeting Qantas Hotels customers. • …

Mon, 21 Sep 2026
Exclusive: Aussie not-for-profit Thorndale Foundation investigating Qilin breach claims
Hackers have targeted a local disability support organisation, with passports and confidentiality agreements already published on the dark web. • Mon, …

Mon, 21 Sep 2026
Report: 44% of Australian cyber crime victims fail to report the incident
Nearly half of Australians who have experienced cyber crime did not report it, with researchers warning that serious offending is being missed by …

Mon, 21 Sep 2026
Australia’s security gap is a network problem
Networking and security teams are converging fast across APJ to meet a more complex threat landscape. Hear more at HPE Networking Day Sydney. For …

Mon, 21 Sep 2026
Aussie mobile telcos face ‘automatic’ customer compensation for outages
Key points A senate committee reviewing outages that hit triple zero calls has recommended mandatory reliability and performance standards for telcos, …

Sun, 20 Sep 2026
Exclusive: Shellharbour-based Leisure Coast Kitchens listed by Kairos ransomware group
Hackers have published employee driver’s licenses, tax file numbers, and customer correspondence, with more data to come. • Fri, 18 Sep 2026 • Security …

Sun, 20 Sep 2026
Australian government launches consultation period on the future of AI in the country
Canberra is looking for feedback on its approach to AI and its infrastructure in Australia, from data centre growth to consumer costs. • Fri, 18 Sep …

Fri, 18 Sep 2026
Optus may ban smart glasses in stores, offices
Optus is contemplating cyber security policies to regulate the use of smart glasses in its stores and offices, with a ban on the devices possible.

Fri, 18 Sep 2026
VIDEO: AI companies would need to report ‘rogue’ incidents under proposed national standards | ABC NEWS

YouTube player

The Prime Minister is travelling to the United States, where he’ll meet with world leaders to discuss online safety and artificial intelligence. After stark warnings from industry heavyweights this week calling on AI to slow down, the government’s also released more detail on proposed safety standards.

Fri, 18 Sep 2026
AUSCERT Week In Review for 18th of September
September is MFA Month, making it the perfect time to review one of the simplest and most effective cyber security measures available: multi-factor …

Wed, 16 Sep 2026
Judge orders parties to probe use of AI to prepare evidence – Proctor
Cairns bailiff takes on new role after admission sitting Shayne Vigorelli was one of six lawyers admitted to the Supreme Court of Queensland as a …

Tue, 15 Sep 2026
Australia’s outdated technology is vulnerable to AI hacking attacks, signals chief says
One of Australia’s top intelligence agencies has warned that AI attacks could exploit the country’s old technology, as the government negotiates its guardrails on artificial intelligence’s rapid development.

Tue, 15 Sep 2026
VIDEO: Cybersecurity spy chief sounds alarm over AI | ABC NEWS

YouTube player

The Director-General of the Australian Signals Directorate says Australia needs an AI ‘early warning system’ to defend against the dangers of the emergent technology. Abigail Bradshaw also struck a more positive tone, urging organisations to embrace AI for its defensive capabilities.

Tue, 15 Sep 2026
Scam alert: Scammers are impersonating ASIC via SMS. Scammers are sending SMS messages impersonating ASIC and urging recipients to call a fake phone number. The messages falsely state there… | ASIC
Scam alert: Scammers are impersonating ASIC via SMS. Scammers are sending SMS messages impersonating ASIC and urging recipients to call a fake phone …

Tue, 15 Sep 2026
Optus outage attributed to hardware failure at exchange
Key points A hardware failure at an Optus exchange in Victoria caused a voice outage lasting about one hour and 16 minutes on Friday. • The outage …

Tue, 08 Sep 2026
Digital platforms to be targeted as part of NSW crackdown on organised crime operations
NSW’s Premier has announced a raft of measures to combat the facilitation of serious crimes, such as gang-related murder. • Mon, 07 Sep 2026 • …

Mon, 14 Sep 2026
Exclusive: Penfold Motors latest car dealer to fall victim to the Storm ransomware group
Victorian car dealership says it is contacting its customers after their contact and vehicle details were compromised by hackers. • Mon, 14 Sep 2026 • …

Mon, 14 Sep 2026
ATO employee charged over alleged disclosure of information to organised crime groups
A Gold Coast man who worked with the Australian Taxation Office (ATO) has been charged over the alleged disclosure of information to organised crime …

Fri, 11 Sep 2026
Cyber Wardens program to shut down as government funding ends
COSBOA CEO says lessons learned from the program “will help shape what comes next” as she celebrates assisting 23,150 small businesses. • Fri, 11 Sep …

Fri, 11 Sep 2026
Nick Scali security breach: What it means for customer information
Furniture giant Nick Scali has confirmed New Zealand customers’ personal details were held on systems affected by a security breach last month. In an …

Thu, 10 Sep 2026
RentTech companies asking tenants for personal details ‘completely outside’ new Victorian laws
The Consumer Policy Research Centre (CPRC) identified rental platforms that encouraged hopeful tenants to share an “excessive” amount of personal information, or asked them questions that were “completely outside” the new rules.

Thu, 10 Sep 2026
VIDEO: Data breach exposes millions of students, teachers and parents | 9 News Australia

YouTube player

Millions of people, including school students, have had their data exposed in a data breach on an education website.

Thu, 10 Sep 2026
VIDEO: AI transforms cyber crime threat in Australia | 7NEWS

YouTube player

There’s a new warning tonight: artificial intelligence is about to make cyber criminals far more dangerous. One of Australia’s most respected cyber security figures has told 7NEWS that AI has transformed the potential for large-scale hacking.

Wed, 09 Sep 2026
NDIS data may have ended up in Palantir’s analytics platform as part of efforts to curb fraud
The Australian Criminal Intelligence Commission, which has access to NDIA data, used Palantir as part of a multi-agency fraud taskforce

Wed, 09 Sep 2026
Exclusive: The Gentlemen strikes Sharp Office as company confirms incident investigation
A ransomware group claims to have hacked a Broadmeadow-based office technology supplier that works with Newcastle Airport and Royal Life Saving …

Wed, 09 Sep 2026 04:32:15 GMT
Australian Cyber Aware – As It Was 2608 – August 2026
This monthly review provides a curated summary of cybersecurity, privacy, AI, fraud, governance, risk, and compliance developments in Australia and …

Tue, 08 Sep 2026
Digital platforms to be targeted as part of NSW crackdown on organised crime operations
NSW’s Premier has announced a raft of measures to combat the facilitation of serious crimes, such as gang-related murder. • Mon, 07 Sep 2026 • …

Tue, 08 Sep 2026
Late patching of Metabase SQLi bug claims Sydney’s Mathspace
Key points Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted instance …

Fri, 04 Sep 2026
ACMA fines Telstra for SIM swapping prevention misses
Key points ACMA has fined Telstra $277,000 for failing to use required identity authentication processes to prevent SIM swapping fraud. • The fraud …

Tue, 08 Sep 2026
Vocus hit by Australia Singapore Cable break
Key points Vocus is grappling with a cable break on its Australia Singapore Cable (ASC) system between Perth and Singapore, following a shunt fault on …

Tue, 08 Sep 2026
Tabcorp appoints new CISO
Key points Tabcorp has named Maxine Harrison as its new chief information security officer, following the former leader’s departure in July. • Harrison …

Tue, 08 Sep 2026
Hundreds of old, vulnerable Exchange servers remain in Australia
Key points 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft’s …

Mon, 07 Sep 2026
‘Now measured in the millions’: The common process being used to scam Australians
in brief Scammers are exploiting the growing use of CAPTCHAs to trick people into running malicious code outside their browser. • An expert has practical …

Fri, 04 Sep 2026
VIDEO: Experts sound alarm on rise of fake digital IDs | 9 News Australia

YouTube player

There’s a warning tonight about a rise in fake digital IDs being sold to teenagers. Cyber safety experts say it’s putting vulnerable Victorians at risk of having their identities stolen.

Fri, 04 Sep 2026
Aussie government announces cyber security labelling scheme for smart devices
The federal government has launched a pilot scheme that will allow Australians to compare the cyber security of smart devices before buying them. • …

Fri, 04 Sep 2026
The Next Wave of Australian Privacy Reform: Key Pr… | Clayton Utz
Modernised Definitions: Casting a Wider Net The Exposure Draft Bill would amend and clarify some of the foundational definitions in the Privacy Act …

Thu, 03 Sep 2026
Labor’s privacy reforms are the boldest we’ve had in years. But there’s a hole to plug
Shifting the emphasis from individuals upholding privacy standards to harmful and invasive business practices is the right move. But an existing …

Thu, 03 Sep 2026
In brief: cyberthreat detection and reporting in Australia
Threat detection and reporting Internal policies and procedures What policies or procedures must organisations have in place to protect data or …

Thu, 03 Sep 2026
Telstra sowed seeds for its July mobile outage in 2020. Six years on they sprouted.
When Telstra engineers embarked on a simple server chassis replacement exercise in 2020, they could barely have contemplated the complex chain of …

Wed, 02 Sep 2026
Exclusive: NSW Health denies Medusalocker data breach claims
Ransomware actor claims hack of government department, but evidence suggests no malicious activity has occurred… But patient data from multiple …

Wed, 02 Sep 2026
NT gov starts path to digital driver’s licence
Key points The Northern Territory government plans to offer digital driver’s licences built to internationally recognised standards by the end of the …

Wed, 02 Sep 2026
Privacy Act overhaul to tighten 72-hour breach reporting deadline
Key points Draft legislation would give Australian organisations 72 hours to notify the Information Commissioner of an eligible data breach, replacing …

Tue, 01 Sep 2026
A Cautionary Tale About Data Breach Claims, Verification and Carhartt
You’re not going to believe this, but turns out you can’t always take criminals at their word. Actually, I’ll walk that back a bit as it may not even …

Tue, 01 Sep 2026
Treasury warned Government not to rush new school assessment tool before data breach
Treasury warned the Government not to rush its new school assessment tool – months before a security flaw made the records of 276 students accessible. …

Tue, 01 Sep 2026
Expired anti-spam domain bites NZ’s national stadium, Eden Park
Key points Eden Park’s DNS configuration referenced an expired domain, spamcontrol.co.nz, letting consultant Alex Shakhov capture DMARC reports for a …

 

 


Australian Information and Cyber Security Videos 2026

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

Mobile networks finally get a disaster backup

Consumers can now expect better connectivity during disasters after Telstra, Optus and TPG Telecom implemented temporary disaster roaming (TDR) … [...]

ASX-listed fintech firm discloses cyber incident impacting client data

An Australian ASX-listed fintech has disclosed a cyber incident which it says has impacted both client and other data. • Wed, 07 Oct 2026 • … [...]

NSW National Parks web app accessed by OpenAI agent

Key points An OpenAI agent is under investigation after a "misalignment" incident on a National Parks and Wildlife Service web app in June. • Current … [...]

CSIRO finds permanent CISO

Key points CSIRO has appointed Luke Forsyth, formerly a partner in the cyber domain at Deloitte, as its new permanent chief information security … [...]

Unpatched server behind Vic student data breach

Key points A school's delay in patching a critical server vulnerability, flagged by an Australian Signals Directorate alert on October 27 2025, led to … [...]

NT government recovers from lengthy network outage

Key points A territory-wide outage knocked out access to telecommunications and digital systems across key NT government departments and agencies for … [...]

Week in Review for 9th of October 2026

Online fashion retailer ASOS has confirmed that customer information may have been accessed following a cyber incident that saw hackers send … [...]

Medibank facing dual court actions over data hack

Share article A hacker moved undetected through Medibank's network for weeks despite multiple warning flags being raised, a court has been told. The … [...]

Cyber security is changing. Are you keeping pace?

What the future of cyber security looks like and why cyber resilience needs to keep pace with business. Cyber security has become a speed problem, not … [...]

OpenAI bots breach NSW government websites twice | 7NEWS

OpenAI has admitted its AI bots were responsible for a second breach of NSW government websites, accessing non-public historic wildfire data from the National Parks and Wildlife Services app in [...]

Anthropic says AI agents didn’t breach Australian government websites

During a joint parliamentary hearing on artificial intelligence, Anthropic’s head of safeguards, Dave Orr, says that investigations of hundreds of millions of transcripts reveal no unauthorised interactions with Australian government [...]

Home affairs orders review over ‘unacceptable risk’ of AI

The federal government has ordered its departments and agencies to review their aging IT systems in a bid to combat the growing risks posed by artificial intelligence. The crackdown targeting [...]

Australian Information Commission launches smart glasses probe, Kmart product vanishes

Listings for controversial camera glasses have mysteriously vanished from the website of retail giant Kmart after a major probe was launched into … [...]

ANZ releases advice on AI scams and fraud

Major bank ANZ has issued a warning regarding AI and increased levels of scams and fraud, highlighting that the technology is enabling threat actors … [...]

Trusted government data can help counter AI misinformation, says OAIC

The Office of the Australian Information Commissioner has warned that proactive access to trusted government information is increasingly important as … [...]

Report: Aussie government lags behind private sector in breach discovery

The average data breach in Australia takes three days to discover – but government breaches take more than 100. • Tue, 29 Sep 2026 • … [...]

Australian government to invest $3.5m to combat technology-facilitated abuse

The Albanese government to stand up 12 new “innovative” projects as part of its National Plan to End Violence Against Women and Children. • Wed, 30 … [...]

Op-Ed: The rogue agent breach of Medicare highlights the importance of AI literacy and fluency for lawyers

The newsfeed has reached a fever pitch about the dangers of artificial intelligence and “AI slop” in legal practice, with most of it focused on … [...]

Jobseekers exploited by recruitment scammers on LinkedIn

Tony Young is one of many Australians who have applied for work using websites like LinkedIn, only to realise afterwards it was a scam. The former … [...]

Small business delivers e-safety wishlist as risks grow

Small business owners need help - not regulation - to battle growing cyber threats, industry groups say. Business representatives addressed a … [...]

Data breaches and privacy complaints across Queensland's public sector on the rise

The number of data breaches across Queensland's public sector is increasing, including some deemed malicious and intentional, the state's privacy … [...]

Week In Review for 2nd of October 2026

October is Cyber Security Awareness Month, and the Australian Cyber Security Centre (ACSC) is encouraging all Australians and organisations to take … [...]

OpenAI reveals another hack into a government agency in Australia

The disclosure adds to a flurry of AI hacks recently revealed by the company. OpenAI on Friday revealed another hack into a second Australian … [...]

Another NSW government website has been hacked by an OpenAI agent

In brief The breach follows earlier break-ins to the NSW Bureau of Crime Statistics and Research and Medicare statistics. • In this breach, OpenAI's … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading