Latest cyber news, threats, security, and guidelines. Stack up.

Incidents

Thu 27 Aug

AFP, WAPF and FBI charge two WA men over alleged open-source supply-chain syndicate

Joint AFP, Western Australia Police Force and FBI release: two West Australian men were charged on 26 August 2026 with a combined 14 offences after Perth search warrants. Police allege a syndicate inserted malicious code into software on an open-source repository that other developers then pulled in. The AFP estimates more than 1,000 organisations globally, more than 500,000 credentials, and at least 300 GB of data, with remediation costs in the hundreds of millions of dollars. The FBI statement in that release names the group TeamPCP. The men are not named in the AFP release. The investigation continues; further arrests have not been ruled out. NEW GTIG/THN (Sep 2026): Google Threat Intelligence Group tracks TeamPCP as Altered Spider / UNC6780 and describes credential stealers SANDCLOCK and DUSTMAKER plus an autonomous multi-agent framework used in a large-scale credential harvest completed in under six hours.

AFP media release

australia supply chain

Incidents

Wed 26 Aug

Boston Scientific: cybersecurity incident disrupting manufacturing, orders and shipping

Boston Scientific's customer update page (latest posted 30 August 2026 8:25 p.m. ET) says it identified a cybersecurity incident on 25 August that caused a network outage and disruption to certain on-premise operating systems and business applications, including manufacturing, order processing and shipping. The company filed an 8-K. It is working with CrowdStrike and other third-party experts. As of the 30 August update it sees no indication of unauthorised activity in its environment related to this incident since 25 August; cloud-based systems are not impacted; the unauthorised activity is limited to certain on-premise systems. Existing implantable CRM device function and previously activated remote monitoring are described as not impacted; new remote-monitoring activations for some cardiac devices are disrupted. No ransomware group had claimed the incident in SecurityWeek's 31 August report. Actor identity is unknown on this desk.

Boston Scientific customer update (30 Aug 2026)

breaches

Incidents

Fri 21 Aug

Origin Energy: unauthorised access affecting about 900,000 customers

Origin Energy confirmed unauthorised access to personal information of approximately 900,000 current and former customers in July 2026. Categories include name, address, date of birth, contact phone, account details, and partial payment data (last four digits of a credit card or last three of a bank account). On 21 August 2026 Origin said a completed review found about 60 customers had full bank account numbers accessed, about 100 had an ID document number accessed (number only, no scans), and about 15,000 had government concession-scheme numbers accessed. Origin told ABC the alleged attacker had not publicly leaked customer data. The company is working with ASD's ACSC, the National Office of Cyber Security, AFP and OAIC; a criminal investigation continues. Earlier reporting linked the incident to a former Accenture Manila call-centre worker; Accenture declined to comment to ABC.

ABC News (quotes Origin 21 Aug update)

breaches australia

Incidents

Thu 20 Aug

Oz Hair and Beauty: unauthorised access to the online order platform

Oz Hair and Beauty's official statement says its online purchase and order platform was briefly accessed by an unauthorised third party. Limited personal information of some customers who purchased before August 2026 was involved: full name, email and/or mobile, and purchase data (currency, total spend, purchase location, customer creation date). The company says credit cards, passwords, payment information and invoice details were not accessed. It reported the incident to ACSC, OAIC and New Zealand's Office of the Privacy Commissioner. Customers not emailed by 22 August 2026 were, on that statement, not identified as impacted on the investigation to date. The company has not published a count of affected records.

Oz Hair and Beauty statement

breaches australia

Incidents

Wed 19 Aug

Quest Apartment Hotels: unauthorised access via a third-party provider

Quest identified unauthorised access on 17 August 2026 to a database through a vulnerability at a third-party service provider. Its statement says the incident is contained. Records involved are from before June 2025 and primarily names, email addresses and/or other contact details, with a small number of dates of birth. The company statement does not list payment card data and does not publish a count of affected records. Quest said it notified the OAIC and ACSC. Magazine reporting that put the figure around 1.5 million is secondary and unconfirmed by Quest.

Quest official statement

breaches supply chain australia

Incidents

Tue 18 Aug

SIA Medical Centre (Vic): Rhysida claims patient records; OAIC and ACSC notified

Cyber Daily (18 August 2026) reports Victorian multi-clinic operator SIA Medical Centre is investigating unauthorised access after the Rhysida ransomware group listed it on 12 August and claimed roughly 20,000 patient medical records (names, dates of birth, Medicare numbers, clinical notes, insurance and WorkCover files) plus staff identity documents, credentials, HR and banking material, offered for six bitcoin with a threatened publication date of 19 August. An SIA spokesperson said the organisation engaged cyber experts to contain the incident and assess personal information accessed; it has become aware an unknown third party named it online and published a small number of documents, is notifying those individuals, and has informed the Office of the Australian Information Commissioner and the Australian Cyber Security Centre. Distinct from other Rhysida cards on this desk (e.g. Berlin state-network).

Cyber Daily (18 Aug 2026)

australia identity

Incidents

Mon 17 Aug

Brighton East Dental Clinic: unauthorised access to on-premises patient files

Brighton East Dental Clinic's official notice says ASD's ACSC alerted it on 13 August 2026 to a potential incident. On 17 August 2026 the clinic identified unauthorised access to data on on-premises file servers through its firewall, contained that access, and analysed leaked data. It assesses the access occurred in early April 2026 and involves records from before April 2026: patient contact details (name, address, date of birth, email, mobile), treatment plans, oral X-rays, referrals and treatment history, and private health insurance membership numbers. The clinic has not published a count of affected records. It says it notified OAIC, ACSC and Victoria Police, partnered with IDCARE, and that remediation is complete. This desk does not take actor names or leak sizes from secondary leak-site indexes.

Brighton East Dental Clinic notice

breaches australia

Incidents

Thu 13 Aug

Nick Scali (ASX: NCK): security incident; systems taken offline

Nick Scali Limited's 13 August 2026 ASX release says it is investigating a security incident and elected to take certain systems offline. The company said it was bringing those systems back online, continuing to complete sales orders and deliveries, with slower-than-normal customer response times. At the time of the release, Nick Scali said it did not have any evidence of unauthorised access to customer data. It notified the Australian Cyber Security Centre and the Australian Federal Police, and said further updates would follow as appropriate. Secondary media quoting the company (including SMH) describe the event as a cyberattack mid the prior week that forced manual order handling; those reports are consistent with the ASX notice on operational disruption. Separate secondary claims of ransom demands or confirmed customer-data access are not stated in the ASX release and are not treated as verified facts on this desk.

Nick Scali ASX release (13 Aug 2026)

australia retail

Incidents

Mon 8 Jun

UWA Callista student system: credentials exposed, unauthorised access on 28 May

The University of Western Australia's own notice says that on 28 May 2026, UWA IT identified unauthorised external access to Callista, the university's Student Information Management System, after system access credentials were unintentionally exposed online. UWA says it secured the system and removed the vulnerability. Exposed fields, on that notice, include name, UWA student ID, UWA staff ID if applicable, home and mobile numbers, date of birth (day and month only), personal email, postcode, and enrolment status as at 2 April 2026, for some prospective students, current students and recent graduates. UWA says financial details were not involved, that it found no evidence of malicious use, and that it emailed affected people on 8 June 2026. UWA password resets were not required. ASD's ACSC had not published a matching alert at last check.

UWA Callista notice

breaches australia

Incidents

Thu 7 May

Instructure Canvas: Free-For-Teacher path, ShinyHunters claim, AU campuses offline

Instructure detected unauthorised activity in Canvas on 29 April 2026 and a second access on 7 May 2026 that changed pages some students and teachers saw after login. The vendor says both used a Free-For-Teacher account path, took Canvas into maintenance, remediated the privilege-escalation routes, and permanently discontinued Free-For-Teacher. Fields named on the vendor FAQ include usernames, email addresses, course names, enrolment information, and messages; Instructure says core learning data (course content, submissions, credentials) was not compromised, and the US Education Department FSA alert (12 May, updated 29 May) repeats that there is no evidence passwords, dates of birth, government identifiers, or financial information were exposed. ShinyHunters claimed the campaign; Instructure later said it reached an agreement with the unauthorised actor, that data was returned with shred logs, and that customers should not engage the actor. SMH (13 May) put the haul at roughly 3.65 TB across 8809 institutions worldwide, including at least 122 in Australia; Trend Micro separately counted 122 Australian institutions among 8809. Patch posture for customers: rotate Canvas integrations, LTI tools, SSO connectors, and API keys; review logs for 25 April–8 May 2026.

Instructure Security Incident Update & FAQs

australia cloud identity