lost-number

Australia: Famous for its breaches not beaches

I've seen an uptick in Aussie platforms suffering data breaches, where companies and customers have had their data extracted and shared, waved in front of the media for ransoms and threats. As I write this, ANOTHER company has become a casualty.

I wanted to share the 2026 casualties (so far) to highlight the constant reminder that no data seems to be safe in our modern world. The pain of signing up to a new service is felt by all, having to provide many points of ID and frequently muttering under your breath "why the eff do you need my passport, I'm trying to order a burger ...". At the same time, you receive an email warning you about a new Login session for an app you signed up for 16 year ago. Back then, these were called 'sites' ...

Below I've listed the companies that have suffered breaches alongside any available company announcements, associated articles and a summary of the exposed data points. This list may miss certain breaches, for reasons such as:

If you are a present or former customer of any of the companies listed below, I recommend you keep a sharp eye on your emails, text messages, phone calls, bank accounts, forms of identity and password notifications. Pretty much be on the ball and watch our for suspicious activity using your identity or credentials. Stay vigilant.

If you were a former customer of these companies and have not been notified, well ... sometimes ignorance is bliss. Otherwise, find those accounts -> login -> clear all known sessions -> clear any personal details you've stored -> delete your account -> hope for the best.

Let's begin.

Jan

Victorian Department of Education

Exposed data

Root cause


Feb

Seagrass Boutique Hospitality Group

Exposed data

Root cause

and ...

Hazeldenes

Exposed data

Root cause


Mar


Apr

Sun Doctors

Exposed data

Root cause

and ...

Generation Life

Exposed data

Root cause


May

Melbourne International Film Festival (MIFF)

Exposed data

Root cause


Jun

Partnered Health

Exposed data

Root cause

and ...

Elina Medical Weight Loss Clinic

Exposed data

Root cause


Jul

Lifeline

Exposed data

and ...

Accounting and Adviser Services (AAS)

Exposed data

Root cause

and ...

Origin Energy

Exposed data

Root cause


Findings

2026 started off with a cyber-bang, and Healthcare was hit hard, particularly between June - July. Third party vendors remain frequent entry points and prone to attacks. Origin's single page covering all incident updates is welcome, however any positivity on web design is massively outweighed by the sheer mass of affected customers. Still at this point (10/08/26), there is no update on the root cause nor any sort of compensation. Bills are still coming in!

The root causes are not always announced to the masses, presumably to safeguard company faults or to intentionally not publicize which door they left open. This all leaves customers with a feeling of hopelessness & distress. Companies have to investigate their (my) data being leaked, hackers have potentially exfiltrated data meanwhile we twiddle our thumbs onto the next distraction.

Winding down, please note this is not a definitive list. New incidents are reported monthly, if not weekly. Though this should not be the norm ... yet here we are, deep into the 3rd quarter of 2026 and we've become so desensitized to data theft that it's not spoken about as urgent as it should be. Nothing a few World Cup games can't fix!

The devil you know

If you come across an article or email notification regarding a breached service, then it's never good news. It sucks. But you can make it just slightly better by sharing that news with others or perhaps elderly/vulnerable people you know who could be using that affected service.

Speaking of, this page could be the one-stop option we're looking for. It's a historical collection of Aus breaches with filtering & associated information about the who/what/when/how. I recommend giving it a look.

Lastly, the breaches do give companies, albeit destructively, the push to review their security practices to prevent further attacks. Tightening up internal employee permissions, increased vendor assessments, increasing monitoring capabilities, data deletion policies, RBAC and CBAC. These are all methods to be followed and consistently refined. Otherwise, we'll just have to back to the ol' days of transferring files over floppy disks. What could possibly go wrong?

Sources and other breaches discovered

#app security #aus breaches #aussie data #data breach #floppy disks #security