Incident
Published 2026-09-10
Verified 2026-09-19

Way Forward (AU charity): payments suspended after third-party CMS cyber incident

Cyber Daily (10 September 2026) reports Australian financial-hardship charity Way Forward disclosed a cyber incident at an external customer-management platform provider. In a 9 September statement the charity said payment arrangements initiated through the affected system were unavailable, clients were notified as a precaution, and creditors were asked for a temporary payment moratorium so client credit reports stay unaffected. A spokesperson later told Cyber Daily the provider’s initial analysis indicated impacted information related mostly to the provider’s own company, still subject to change while the provider investigation continues. No OAIC notice or named vendor was fetched on this pass; treat data-impact scope as provisional. Primary: Cyber Daily quoting Way Forward; company website returned a challenge page this pass.

Product
Way Forward customer-management / payment processing (third-party platform)
Versions
n/a (third-party service incident; not a product CVE)
Exploited in Australia?
unknown
Patch to
n/a for other operators: verify third-party CMS/payment vendors; watch for phishing against notified Way Forward clients

Primary: Cyber Daily — Way Forward third-party CMS incident (10 Sep 2026) · Vendor: Way Forward (charity site; statement via Cyber Daily quote) · Webber Insurance AU breaches list (September 2026 entry)

breaches australia identity