Australia: Famous for its breaches not beaches
I've seen an uptick in Aussie platforms suffering data breaches, where companies and customers have had their data extracted and shared, waved in front of the media for ransoms and threats. As I write this, ANOTHER company has become a casualty.
I wanted to share the 2026 casualties (so far) to highlight the constant reminder that no data seems to be safe in our modern world. The pain of signing up to a new service is felt by all, having to provide many points of ID and frequently muttering under your breath "why the eff do you need my passport, I'm trying to order a burger ...". At the same time, you receive an email warning you about a new Login session for an app you signed up for 16 year ago. Back then, these were called 'sites' ...
Below I've listed the companies that have suffered breaches alongside any available company announcements, associated articles and a summary of the exposed data points. This list may miss certain breaches, for reasons such as:
- cases not yet announced pending initial investigations
- breaches under deep investigation to uncover the blast radius
- companies carrying on their daily routine, blissfully unaware of the inevitable danger they are in
- or, even worse: companies choosing to publicly disclose their breach
If you are a present or former customer of any of the companies listed below, I recommend you keep a sharp eye on your emails, text messages, phone calls, bank accounts, forms of identity and password notifications. Pretty much be on the ball and watch our for suspicious activity using your identity or credentials. Stay vigilant.
If you were a former customer of these companies and have not been notified, well ... sometimes ignorance is bliss. Otherwise, find those accounts -> login -> clear all known sessions -> clear any personal details you've stored -> delete your account -> hope for the best.
Let's begin.
Jan
Victorian Department of Education
- https://www.vic.gov.au/cyber-incident-impacting-victorian-government-schools
- https://ovic.vic.gov.au/newsitem/ovic-commences-investigation-into-cyber-incident-at-the-department-of-education/
Exposed data
- affected ~1,700 government schools
- student names. department-issued email addresses, encrypted password, school name, year level
Root cause
- database with current and past student information was accessed by an external third-party
Feb
Seagrass Boutique Hospitality Group
- no public company announcement
- https://www.dexpose.io/kairos-targets-seagrass-boutique-hospitality-group-in-australia/
- https://www.hookphish.com/blog/ransomware-group-kairos-hits-seagrass-boutique-hospitality-group/
Exposed data
- not publicly shared
- being a hospitality venue, one would presume limited credit card numbers, emails used in reservations or receipts
Root cause
- unknown
and ...
Hazeldenes
Exposed data
- caused a supply chain crisis across Victoria
- historical operational & corporate information
- impacted parties were contacted
Root cause
- unknown
Mar
Apr
Sun Doctors
Exposed data
- not fully communicated, but common mentions are: basic contact details & health information
- unknown scope, chose to notify 280k customers to be safe
Root cause
- external IT vendor with system access to Sun Doctors was compromised, resulting in partial access
and ...
Generation Life
- https://genlife.com.au/news-and-insights/important-update-27-april-2026
- follow up: https://genlife.com.au/news-and-insights/important-update-17-may-2026
Exposed data
- unknown, only those affected customers were contacted
Root cause
- unauthorised access via external service provider
May
Melbourne International Film Festival (MIFF)
- https://miff.com.au/storage/assets/2026/06/miff-statement-2-june-2026.pdf
- https://ia.acs.org.au/article/2026/film-festival-hack-leaves-thousands-fearing-identity-theft.html
Exposed data
- name, email address, residential address, phone number
- affected 26.7k customers
Root cause
- unauthorized access to a client system from a third party (Ferve)
Jun
Partnered Health
- https://www.itnews.com.au/news/medical-clinic-chain-partnered-health-hit-by-data-theft-627401
- https://partneredhealth.com.au/partnered-health-recent-cyber-incident/
Exposed data
- name, DOB, address, contact details
- medicare number, private health insurance number, veteran card number, concession card number
- medical information, treatment & consultation notes, referrals, test results
Root cause
- unknown :(
and ...
Elina Medical Weight Loss Clinic
Exposed data
- not made clear, though given HotDoc's use case (booking private GP consultations & providing medical history), I would think: mobile number, email, address, first + last name, potentially medicare number
- based off hacker claims (not Elina's): company information & patient records
Root cause
- unauthorized access to their HotDoc platform
Jul
Lifeline
Exposed data
- more than >10k records
- names, dates of birth, workplace email addresses, phone numbers and contact numbers
- the affected individuals seemed to be Lifeline staff & volunteers, not help seekers
and ...
Accounting and Adviser Services (AAS)
- unfortunately no public announcement from the company themselves
- https://ia.acs.org.au/article/2026/tax-and-superannuation-data-allegedly-stolen-in-data-breach.html
Exposed data
- ~33.9k records
- allegedly a range of client & company data points, including: TFNs, portfolio values, PII, company names, business addresses
Root cause
- unknown
and ...
Origin Energy
Exposed data
- wait for it ... 900,000 current AND former customer records were accessed (oof!)
- names, addresses, DOBs, phone numbers, last 4 digits of credit card, last 3 digits of bank accounts
Root cause
- unknown, as of 28/07/26: Our review into this incident is continuing
Findings
2026 started off with a cyber-bang, and Healthcare was hit hard, particularly between June - July. Third party vendors remain frequent entry points and prone to attacks. Origin's single page covering all incident updates is welcome, however any positivity on web design is massively outweighed by the sheer mass of affected customers. Still at this point (10/08/26), there is no update on the root cause nor any sort of compensation. Bills are still coming in!
The root causes are not always announced to the masses, presumably to safeguard company faults or to intentionally not publicize which door they left open. This all leaves customers with a feeling of hopelessness & distress. Companies have to investigate their (my) data being leaked, hackers have potentially exfiltrated data meanwhile we twiddle our thumbs onto the next distraction.
Winding down, please note this is not a definitive list. New incidents are reported monthly, if not weekly. Though this should not be the norm ... yet here we are, deep into the 3rd quarter of 2026 and we've become so desensitized to data theft that it's not spoken about as urgent as it should be. Nothing a few World Cup games can't fix!
The devil you know
If you come across an article or email notification regarding a breached service, then it's never good news. It sucks. But you can make it just slightly better by sharing that news with others or perhaps elderly/vulnerable people you know who could be using that affected service.
Speaking of, this page could be the one-stop option we're looking for. It's a historical collection of Aus breaches with filtering & associated information about the who/what/when/how. I recommend giving it a look.
Lastly, the breaches do give companies, albeit destructively, the push to review their security practices to prevent further attacks. Tightening up internal employee permissions, increased vendor assessments, increasing monitoring capabilities, data deletion policies, RBAC and CBAC. These are all methods to be followed and consistently refined. Otherwise, we'll just have to back to the ol' days of transferring files over floppy disks. What could possibly go wrong?
Sources and other breaches discovered
- many google searches
- https://ochrehealth.com.au/news/ochre-health-investigation-into-online-data-claims/
- https://www.youxpowered.com.au/cyber-incident + https://www.secure-iss.com/newsroom/444-000-australians-financial-data-exposed-by-a-company-they-didn-t-know-had-it - >400k customers data stolen through a broker platform