Modern fraud isn't an event. It's an industrialised campaign that begins weeks before the payment.
The transaction is where fraud ends, not where it happens. This paper shows how to disrupt the campaign weeks before the payment, not document it after.
44 threat reports across Australia and New Zealand. A worm-like npm supply-chain attack with a 2-billion-download blast radius. The Origin Energy breach, and an aggressive ransomware wave led by The Gentlemen. Group-IB’s monthly intelligence report for July 2026 maps exactly who is targeting the Australia and New Zealand (ANZ) region right now — and what they will do next.
Group-IB’s intelligence report for July 2026 maps exactly who is targeting the Australia and New Zealand (ANZ) region right now — and what they will do next.
Synopsis
Drawing on Group-IB’s proprietary Threat Intelligence, dark web monitoring, and incident response data, this report details the ransomware, data-leak, infostealer, fraud, initial-access, and hacktivist activity shaping the region’s risk landscape between 1 and 31 July 2026.
This month, the ANZ region absorbed both financially driven cybercrime and geopolitical spillover. Australia bore the brunt with 89% of the 44 recorded incidents, while ransomware dominated the threat picture — 67% of incidents involved data encryption and extortion, followed by data sales and access-broker activity. The report gives security leaders a concise, evidence-based picture of the threats that matter, and a forward look at where August is likely to lead.
Every figure in this report is sourced from Group-IB’s own intelligence collection. It is written for defenders who need to prioritise, not just observe.
Key Findings and Insights
The Shai-Halud npm supply-chain worm redefined the risk.
On 4 August a compromised maintainer account poisoned the foundational keyv and cacheable npm namespaces, spreading across 444 packages and 1,381 versions with a combined reach of more than 2 billion monthly downloads. The worm subverts trusted publishing to retain valid cryptographic provenance — meaning signed, provenance-valid packages can no longer be assumed safe.
Ransomware pressure kept climbing across the region.
Group-IB recorded 22 ransomware incidents in July, a 4.7% rise on June. All were rated “orange” severity, and four resulted in confirmed data leaks. The Gentlemen, Kairos, and Qilin were the most active groups.
Real Estate and Manufacturing were the most-hit ANZ sectors.
Real Estate and Construction led with six ransomware activities, followed by Manufacturing and Professional Services. Food and Beverage processors drew repeat attention from The Gentlemen.
The Origin Energy breach was the month’s most significant incident.
One of Australia’s largest energy providers moved from “investigating a potential incident” to confirming unauthorised access and disclosure of some customer data. The self-identified attacker claims a compromised employee login into a vendor-supplied customer management system was the entry point — a claim that remains unverified by Origin.
Infostealers drove a large-scale credential-theft campaign.
Nearly 187,000 account compromises were logged across ANZ, led by Vidar, RedLine, and LummaC2. ArechClientV2 continues its month-on-month climb, absorbing displaced market share through malvertising, SEO-poisoned downloads, and ClickFix-style fake-update lures.
Initial access brokers advertised entry to major Australian businesses.
Underground activity revealed sophisticated broker operations, including xp10itrs selling access to an Australian consumer finance group, and Newsudo offering RDP access to an Australian manufacturer.
Cross-border data sales exposed over 1.6 million Australian records.
A single database offering contained 1,616,285 Australian records alongside UK, Canada, and US data spanning 2025–2026, while hacktivist group Отряд Разрушения Инфраструктуры claimed 2.7 million corporate records and an alleged government-site breach affecting 1.5 million student records.
INC Blog attacked Partnered Health Group and claimed leaked data from Lifeline Australia, a critical mental-health service provider — underscoring the sensitivity of healthcare-sector exposure in the region.
Who Must Read This Report
CISOs and security leaders in Australia and New Zealand who need to prioritise defensive investment against the threats actually targeting the region.
SOC and threat intelligence teams looking for current tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK — including T1486 (Data Encrypted for Impact) and the exfiltration techniques seen in July’s hacktivist incidents.
Fraud and financial-crime teams at banks, fintechs, and payment providers tracking compromised bank-card dumps and the Telegram-based distribution networks behind them.
Risk, compliance, and board-level stakeholders who need a clear, evidence-based read on regional cyber risk and its regulatory implications.
Software and DevSecOps teams responsible for open-source dependency risk in the wake of the Shai-Halud npm supply-chain attack.
Government and critical infrastructure operators assessing nation-state and hacktivist spillover from the Middle East regional conflict.
Know who’s targeting your region before they reach your network.
Download the ANZ Threat Landscape for July 2026 for the full breakdown of ransomware groups, infostealer trends, data leaks, initial-access activity, and the Adversary of the Month — sourced from Group-IB’s Threat Intelligence.
Relevant reports
We see the full picture of the evolving cyber threat landscape thanks to unique tools for monitoring the infrastructure used by cybercriminals and data from battlefields: