
Get 24/7 incident response assistance from our global team
- APAC: +65 3159 4398
- EU & NA: +31 20 890 55 59
- MEA: +971 4 540 6400
- LATAM: +56 2 275 473 79
Get 24/7 incident response assistance from our global team
Please review the following rules before submitting your application:
1. Our main objective is to foster a community of like-minded individuals dedicated to combatting cybercrime and who have never engaged in Blackhat activities.
2. All applications must include research or a research draft. You can find content criteria in the blog. Please provide a link to your research or research draft using the form below.

Group-IB’s monthly threat intelligence report on the cybercriminal, hacktivist and nation-state activity targeting Australia and New Zealand between 1 and 31 August 2026. It documents 53 threat events across the region — led by a 8.7% rise in ransomware, a healthcare-sector surge, and the sudden emergence of Storm Ransomware — all sourced from Group-IB’s own intelligence collection.
August was defined by one word: intensification.
A brand-new group, Storm Ransomware, claimed five Australian victims in under three weeks and tied Qilin as the region’s most active operator — in its very first month. Healthcare became the most-targeted sector, with attacks more than tripling July’s count. And a Telegram-based carding ecosystem aimed squarely at Australian banks came into full view.
Australia was named in 89% of events. Every ransomware incident was rated amber severity — substantial business impact, real regulatory exposure.
Every figure here comes from Group-IB’s own collection. Written for defenders who need to prioritise, not just observe.
Group-IB documented 53 threat events across Australia and New Zealand in August 2026, including 25 ransomware incidents, 16 data-leak publications and 4 hacktivism events. Australia was named in 89% of events.
A ransomware group first observed by Group-IB on 13 August 2026. In its first month it claimed five Australian victims across agriculture, automotive and construction, tying Qilin as the region’s most active operator and running a Tor-based data-leak site.
Healthcare, with seven ransomware events — more than triple July’s count — spanning dental, medical, pharmaceutical and health-platform organisations.
They fell 90.13% to 26,766 records, mirroring an 86% global drop, because these counts reflect when stealer logs surface and are processed — not a like-for-like fall in infections. Figures typically rise as later logs are ingested.
Qilin and Storm Ransomware tied as the most active in August, followed by The Gentlemen and Cl0p.
Yes. The August 2026 ANZ Threat Landscape is a free download via the form on this page.