Australian Organisations Hit by Multi-Target Data Breaches
In a wave of alleged breaches being claimed against major Australian organisations across both government and commercial sectors, threat actor group HIME666 reports gaining unauthorised access to credentials and internal URLs belonging to the Queensland Department of Education, South Australian Government, Victoria Police, the Australian Federal Police, the Australian Federal Police Association, and the Commonwealth Superannuation Corporation - signalling widespread exposure across critical systems.
Smishing Triad Expands Its Global Phishing-as-a-Service Operation
A fast-growing SMS-phishing syndicate “The Smishing Triad” continues broadening its reach by refining and distributing its custom “Lighthouse” smishing kit through a private Telegram channel, with Australia remaining a prime target. Active since 2023, the group now offers more than 500 templates designed to steal victims’ payment data.
Ransomware, DDoS and Hacktivism Pressure Intensifies Across AUNZ
Cyber disruptions targeting several Australian organisations continued throughout the month, driven by active ransomware, DDoS and hacktivist groups including DragonForce, Kairos and Akira. Notable incidents included an attack against Canva and multiple claims issued by DieNet and HIME666 across various organisations.
Cyber risks are escalating across Australia and New Zealand, and organisations that stay informed stay protected. This month’s Intelligence Insights delivers essential visibility and strategic foresight to help you anticipate emerging threats and build long-term resilience in an increasingly unpredictable landscape.
Subscribe to stay up to date with the latest cyber threat trends