ANZ Threat Landscape Report, July 2026
← Research Hub

ANZ Threat Landscape Report, July 2026

44 threat reports across Australia and New Zealand. A worm-like npm supply-chain attack with a 2-billion-download blast radius. The Origin Energy breach, and an aggressive ransomware wave led by The Gentlemen. Group-IB’s monthly intelligence report for July 2026 maps exactly who is targeting the Australia and New Zealand (ANZ) region right now — and what they will do next.

Group-IB’s intelligence report for July 2026 maps exactly who is targeting the Australia and New Zealand (ANZ) region right now — and what they will do next.

Synopsis

Drawing on Group-IB’s proprietary Threat Intelligence, dark web monitoring, and incident response data, this report details the ransomware, data-leak, infostealer, fraud, initial-access, and hacktivist activity shaping the region’s risk landscape between 1 and 31 July 2026.

 

This month, the ANZ region absorbed both financially driven cybercrime and geopolitical spillover. Australia bore the brunt with 89% of the 44 recorded incidents, while ransomware dominated the threat picture — 67% of incidents involved data encryption and extortion, followed by data sales and access-broker activity. The report gives security leaders a concise, evidence-based picture of the threats that matter, and a forward look at where August is likely to lead.

 

Every figure in this report is sourced from Group-IB’s own intelligence collection. It is written for defenders who need to prioritise, not just observe.

Key Findings and Insights

The Shai-Halud npm supply-chain worm redefined the risk.The Shai-Halud npm supply-chain worm redefined the risk.

On 4 August a compromised maintainer account poisoned the foundational keyv and cacheable npm namespaces, spreading across 444 packages and 1,381 versions with a combined reach of more than 2 billion monthly downloads. The worm subverts trusted publishing to retain valid cryptographic provenance — meaning signed, provenance-valid packages can no longer be assumed safe.

Ransomware pressure kept climbing across the region.Ransomware pressure kept climbing across the region.

Group-IB recorded 22 ransomware incidents in July, a 4.7% rise on June. All were rated “orange” severity, and four resulted in confirmed data leaks. The Gentlemen, Kairos, and Qilin were the most active groups.

Real Estate and Manufacturing were the most-hit ANZ sectors.Real Estate and Manufacturing were the most-hit ANZ sectors.

Real Estate and Construction led with six ransomware activities, followed by Manufacturing and Professional Services. Food and Beverage processors drew repeat attention from The Gentlemen.

The Origin Energy breach was the month’s most significant incident.The Origin Energy breach was the month’s most significant incident.

One of Australia’s largest energy providers moved from “investigating a potential incident” to confirming unauthorised access and disclosure of some customer data. The self-identified attacker claims a compromised employee login into a vendor-supplied customer management system was the entry point — a claim that remains unverified by Origin.

Infostealers drove a large-scale credential-theft campaign.Infostealers drove a large-scale credential-theft campaign.

Nearly 187,000 account compromises were logged across ANZ, led by Vidar, RedLine, and LummaC2. ArechClientV2 continues its month-on-month climb, absorbing displaced market share through malvertising, SEO-poisoned downloads, and ClickFix-style fake-update lures.

Initial access brokers advertised entry to major Australian businesses.Initial access brokers advertised entry to major Australian businesses.

Underground activity revealed sophisticated broker operations, including xp10itrs selling access to an Australian consumer finance group, and Newsudo offering RDP access to an Australian manufacturer.

Cross-border data sales exposed over 1.6 million Australian records.Cross-border data sales exposed over 1.6 million Australian records.

A single database offering contained 1,616,285 Australian records alongside UK, Canada, and US data spanning 2025–2026, while hacktivist group Отряд Разрушения Инфраструктуры claimed 2.7 million corporate records and an alleged government-site breach affecting 1.5 million student records.

Healthcare targeting raised acute privacy concerns.Healthcare targeting raised acute privacy concerns.

INC Blog attacked Partnered Health Group and claimed leaked data from Lifeline Australia, a critical mental-health service provider — underscoring the sensitivity of healthcare-sector exposure in the region.

Who Must Read This Report

CISOs and security leaders in Australia and New Zealand who need to prioritise defensive investment against the threats actually targeting the region.CISOs and security leaders in Australia and New Zealand who need to prioritise defensive investment against the threats actually targeting the region.

SOC and threat intelligence teams looking for current tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK — including T1486 (Data Encrypted for Impact) and the exfiltration techniques seen in July’s hacktivist incidents.SOC and threat intelligence teams looking for current tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK — including T1486 (Data Encrypted for Impact) and the exfiltration techniques seen in July’s hacktivist incidents.

Fraud and financial-crime teams at banks, fintechs, and payment providers tracking compromised bank-card dumps and the Telegram-based distribution networks behind them.Fraud and financial-crime teams at banks, fintechs, and payment providers tracking compromised bank-card dumps and the Telegram-based distribution networks behind them.

Risk, compliance, and board-level stakeholders who need a clear, evidence-based read on regional cyber risk and its regulatory implications.Risk, compliance, and board-level stakeholders who need a clear, evidence-based read on regional cyber risk and its regulatory implications.

Software and DevSecOps teams responsible for open-source dependency risk in the wake of the Shai-Halud npm supply-chain attack.Software and DevSecOps teams responsible for open-source dependency risk in the wake of the Shai-Halud npm supply-chain attack.

Government and critical infrastructure operators assessing nation-state and hacktivist spillover from the Middle East regional conflict.Government and critical infrastructure operators assessing nation-state and hacktivist spillover from the Middle East regional conflict.

Know who’s targeting your region before they reach your network.

Download the ANZ Threat Landscape for July 2026 for the full breakdown of ransomware groups, infostealer trends, data leaks, initial-access activity, and the Adversary of the Month — sourced from Group-IB’s Threat Intelligence.