2019 Data Breaches in Australia
Plenty of Fish (PoF) – December 2019
Primus Realty – December 2019
Amazon Ring – December 2019
Vistaprint – December 2019
800 Australians in Vistaprint data breach – Web-to-print giant Vistaprint has discovered around 800 of its Australian customers were on the online data breach first revealed in an Australia-exclusive by Print21 last week, and at the time thought to not include any local customers.
Monash IVF Group – December 2019
Fears over patient data breach after cyberattack on Monash IVF – One of Australia’s largest IVF providers has warned patients that it could not rule out the possibility their personal information may have been breached following a widespread cyberattack on staff emails last month.
ANU – November 2019
Nord VPN Breach – November 2019
AIS, Sport Australia – November 2019
AIS, Sport Australia investigate potential data breach – The AIS and Sport Australia are investigating a potential breach of an agency email account after it was hacked last week.
ZoneAlarm – November 2019
Monash IVF Group – November 2019
NSW Labor Headquarters – November 2019
NSW Labor Headquarters Reported For possible Data Breach – The NSW Labor party could be dragged into the troubles of an embattled Sydney mayor after he was accused of breaching data privacy laws and misusing the electoral roll.
Adobe – October 2019
GET – October 2019
Google – October 2019
Optus – October 2019
Sydney IT Contractor – October 2019
Sydney IT contractorcould face jail over data breaches affecting 270,000 people
‘Trusted inside access’ – Sydney IT contractor arrested over Landmark White data breach
Victorian Hospitals – October 2019
Surgeries delayed and patient security fears after cyber attack on Victorian hospitals
Multiple Victorian hospitals hacked in suspected ransomware attack
Zynga – October 2019
Social games company Zynga reveals data breach – Zynga has disclosed a data breach that may have compromised millions of account login details for its popular Words With Friends and Draw Something games.
Words With Friends Data Allegedly Stolen In Breach That Could Affect 218 Million Users
DoorDash – September 2019
Get – September 2019
‘Alarming’ Data Breach Exposes 50,000 Students In Ticketing Website Bungle
Data breach suffered by online service used by SASS, SciSoc, St John’s College
TGI Fridays – September 2019
Web.com – August 2019
Imperva – August 2019
PAY ID – August 2019
Personal banking information at risk following fresh data breach
PayID breach sees customers’ banking information hacked – Tens of thousands of customers’ personal banking details are at risk after scammers broke into a new payment database.
BUPA – Sonic HealthPlus (SHP) – August 2019
Sensitive personal data of hundreds of visa applicants accidentally leaked in email mishap – The personal health information of 317 people applying for Australian visas was accidentally emailed to a member of the general public, an ABC investigation has revealed.
Myki – August 2019
Watchdog slams Public Transport Victoria for Myki data breach
‘Shocking’ myki privacy breach for millions of users in data release
TAFE NSW – August 2019
Cloud Union – New Zealand – August 2019
Ecommerce service exposed passports, ID details of users – S3 bucket included details of individuals included in the Dow Jones Watchlist
Air New Zealand – August 2019
Air New Zealand staffer falls for phishing attack – Customer info stolen two weeks after airline praised for data privacy.
Neoclinical – August 2019
Sephora – July 2019
AAMC Loss Assessor – July 2019
NAB – July 2019
NAB reveals 13,000-person data breach at 6PM Friday – Dataset uploaded to the servers of two service providers.
NAB admits thousands had personal data breached, blaming ‘human error’
Equifax – July 2019
MYOB – July 2019
MYOB in payslip privacy bungle – Blamed on cloud system “glitch”
Commonwealth Bank – July 2019
Comm Bank slapped over failed security – Missing bank statements cause concern about customer privacy
British Airways – July 2019
British Airways faces record $329m fine over data breach – Punished under GDPR
Queensland Health – July 2019
MEGT & Ability English – July 2019
Education services provider confirms data breach – Student information system provider left data in open S3 bucket
Insurance House – June 2019
GeelongPort – June 2019
Nagle Catholic College WA – June 2019
Parents’ financial details stolen in cyber attack on Geraldton Catholic school
Geraldton’s Nagle Catholic College swept up in cyber attack targeting parent banking details
Nagle Catholic College parents targeted in cyber attack on Geraldton high school
Specsavers Qld – June 2019
Symantec – June 2019
Australian Catholic University – June 2019
Revenue NSW – June 2019
Australian National University – June 2019
China ‘behind’ huge ANU hack amid fears government employees could be compromised
ANU breach a risk for security officials as China becomes key suspect
Almost 20 years of personal data was stolen from ANU. It could show up on the dark web
19 years’ worth of personal data stolen from ANU – It could be sold on the dark web
Microsoft – May 2019
Patch now against wormable ‘BlueKeep’ remote desktop flaw: ACSC – Spectre of another WannaCry-style epidemic raised
Princess Polly – May 2019
Aussie fashion e-tailer Princess Polly suffers data breach – Card info may have been captured as it was entered into site
Canva – May 2019
Canva under cyber-attack, with reportedly as many as 139 million users affected
Aussie Canva Hit By Massive Data Breach: User Details Stolen
Canva criticised after data breach exposed 139m user details
“Marketing fluff”: What startups can learn from Canva’s data-breach response
Instagram – May 2019
Instagram hit by two privacy breaches in a week – The Facebook-owned company fails it users.
Instagram has a MAJOR personal data breach 50 million users have had their personal details shared
Perth socialite Melissa Graham held to ransom after Instagram privacy breach
CCH software – May 2019
Wolters Kluwer takes down cloud services after malware infection – Impacts Australian users of CCH software
Binance – May 2019
Binance hackers shift stolen bitcoin, identity still unclear: researchers – Funds now sitting in several digital wallets
Twitter – May 2019
WhatsApp – May 2019
WhatsApp flaw allowed spyware injection via calls | Pegasus comes calling whether you answer or not
WhatsApp urges upgrade after ‘serious’ security breach allowed hackers to put spyware on phones
WhatsApp major security flaw could let hackers access phones
WhatsApp security breach likely a government surveillance attack, company says
WPA3 Dragonfly – April 2019
Wipro – April 2019
Speedrun.com – April 2019
Australia Post – March 2019
AusPost’s Bill Scanner caught up in Gmail privacy sweep – Works with Google to ensure API permissions aren’t revoked
ASUS – March 2019
ASUS users targeted in large supply chain attack – Users infected via software update utility
ASUS releases fix after ShadowHammer malware attack – But some users unable to update to non-backdoored software
Bank of Queensland – March 2019
Bank warns of reported third-party data breach – The Bank of Queensland has announced that it has been made aware of a personal data breach by a third party provider
Kathmandu – March 2019
Credit cards cancelled as Kathmandu reveals online store hacked
Data breaches have possibility to ruin customer relationships
Citrix – March 2019
Melbourne Hospital – February 2019
CoffeeMeetsBagel – February 2019
9Honey – February 2019
Toyota Australia – February 2019
Toyota Australia hit by cyber attack – takes down email and other systems
Millions of customers’ data accessed in second Toyota hack – Tokyo sales subsidiaries raided
AMP – February 2019
LandMark White – February 2019
Home loan details of 100,000 customers hacked in major data breach
Valuation firm hit by data breach LandMark White pleads for long share suspension
Embattled LandMark White shares drop 10.6 pc after data breach
NAB pulls plug on LandMark White as home loan breach scandal grows
Centrelink keeps LandmarkWhite, says data breach hit ‘very small’ client group
LandMark White counts cost of data breach – LandMark White still unsure of financial impact
LandmarkWhite knew of IT weakness in 2017, a year before data breach
LandmarkWhite faces regulator scrutiny over IT response, disclosure
LandMark White CEO exits after data breach – two directors step down from board
LandMark White’s data breach just the beginning for cyber criminals
Department of Parliamentary Services – February 2019
Security breach strikes parliament’s IT network – all passwords reset
Political party networks caught up in parliament’s IT breach – but no evidence of electoral interference
Bunnings – February 2019
Bunnings exposed staff performance database – individual staffer did unwanted homework
Facebook – January 2019
Apple Shuts Down Facebook Data Collecting App – Since 2016, Facebook has been asking users to install a “Facebook Research” VPN that lets the company monitor their phone and online activity, according to Tech Crunch
Apple punishes Facebook over app that paid users to hand over data
Facebook stored millions of user passwords in plain text – hundreds of millions of users to be notified
Facebook says up to 111,813 Aussies in last year’s security breach
Facebook’s lax security has left millions of users with a lot to worry about
Global Hacking Scare – January 2019
Global hacking scare nets Queensland MP, Surf Life Saving as millions of passwords breached – websites belonging to Queensland’s Deputy Opposition Leader, a real estate business and Surf Life Saving Australia are among thousands of pages caught up in the latest international data breach
SkoolBag – January 2019
Optus – January 2019
Collection #1 – January 2019
Breach Exposes a Record 773 Million Email Addresses – The massive trove of leaked data, which was posted to a hacking forum, also includes 21,222,975 unique passwords.
Experts comment on record 772mil-user data breach – Cybersecurity expert and founder of website Have I Been Pwned Troy Hunt broke the news recently that the largest ever database of breached login details have been leaked on the dark web.
Cyber watchdog warns on dark web PS data – The Australian Cyber Security Centre (ACSC) has urged organisations and individuals across the Australian Public Service to check if their email addresses and/or passwords are included on recently released lists of stolen data.
Fisheries Queensland – January 2019
Fisheries Qld blames bad update for password ‘fault – allowed fisherman to get into any account.
First National Real Estate – January 2019
Department of Planning and Environment, NSW Major Projects – January 2019
Victorian Government – January 2019
Marriott Hotel Group / Starwood – January 2019
Early Warning Network – January 2019
Big W – January 2019
Hawthorn Football Club – January 2019
Nova Entertainment – January 2019
Nova notifies listeners of data breach – Nova Entertainment has admitted that listeners’ data from the period of May 2009 to October 2011 has been “publicly disclosed”.
My Health Records – January 2019
Critics want My Health Record delayed again after recording 42 data breaches this year.
As My Health Record opt-out ends, security concerns continue
Victorian Public Servants – January 2019
Victorian Public Servants hit by massive data theft – The work details of 30,000 of Victorian public servants were stolen from a government directory in a data breach just days before Christmas.