AUNZ Threat Landscape Report, August 2026
← Research Hub

AUNZ Threat Landscape Report, August 2026

A ransomware group that appeared from nowhere and tied for #1. Healthcare attacks tripled. Group-IB maps who targeted Australia and New Zealand in August 2026.

What is the Group-IB APAC Threat Landscape Report?

Group-IB’s monthly threat intelligence report on the cybercriminal, hacktivist and nation-state activity targeting Australia and New Zealand between 1 and 31 August 2026. It documents 53 threat events across the region — led by a 8.7% rise in ransomware, a healthcare-sector surge, and the sudden emergence of Storm Ransomware — all sourced from Group-IB’s own intelligence collection.

Synopsis

August was defined by one word: intensification.

 

A brand-new group, Storm Ransomware, claimed five Australian victims in under three weeks and tied Qilin as the region’s most active operator — in its very first month. Healthcare became the most-targeted sector, with attacks more than tripling July’s count. And a Telegram-based carding ecosystem aimed squarely at Australian banks came into full view.

 

Australia was named in 89% of events. Every ransomware incident was rated amber severity — substantial business impact, real regulatory exposure.

 

Every figure here comes from Group-IB’s own collection. Written for defenders who need to prioritise, not just observe.

Storm Ransomware went from zero to #1 in weeks.Storm Ransomware went from zero to #1 in weeks.

A group Group-IB first observed on 13 August claimed five Australian victims — Agrimac, Sharp Motor Group, Westco Motors Cairns, Ramsey Bros and 3-point Australia — tying Qilin as the region's most active operator in its debut month.

Healthcare was August's hardest-hit sector.Healthcare was August's hardest-hit sector.

Seven ransomware events — more than triple July — spanning dental, medical, pharmaceutical and health-platform targets, from Rhysida's attack on SIA Medical Centre to The Gentlemen hitting Vitex Pharmaceuticals.

Ransomware kept climbing.Ransomware kept climbing.

25 incidents across ANZ, up 8.7% month-on-month, all rated amber severity, with Qilin and Storm leading and Australia absorbing 24 of the 25.

A carding ecosystem locked onto Australian banks.A carding ecosystem locked onto Australian banks.

Group-IB exposed the linked Heisenberg, ExcelYard and Zaynlior operations — a Telegram-based network selling stolen cards and hosting phishing content aimed directly at Australian banks.

Cross-border data sales widened.Cross-border data sales widened.

Databases tied to New Zealand Sotheby's Realty, Binance Australia and Top Education Group were listed — while Group-IB verified one high-profile claim (a dfat[.]gov[.]au leak) as false.

Compromised-account volume fell 90% — but don't relax.Compromised-account volume fell 90% — but don't relax.

Records dropped to 26,766 as bulk log dumps cleared, mirroring an 86% global fall. Beneath the headline, 84 Australian and 24 New Zealand corporate-access groups were still flagged.

Rhadamanthys was the quiet riser.Rhadamanthys was the quiet riser.

Against a 90% market collapse, Rhadamanthys stealer grew 19% and AMOS more than doubled — the growth shape of emerging or returning families worth watching into September.

OT targeting reached New Zealand.OT targeting reached New Zealand.

Pro-Russian group Z-Pentest claimed operational-technology access at Nelson Aviation College, as hacktivism events across ANZ doubled month-on-month.

Who Must Read This Report

CISOs and security leaders across Australia and New Zealand prioritising defence against the threats actually hitting the region.CISOs and security leaders across Australia and New Zealand prioritising defence against the threats actually hitting the region.

SOC and threat intelligence teams who need current tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK.SOC and threat intelligence teams who need current tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK.

Fraud and financial-crime teams at banks and fintechs tracking the ANZ carding ecosystem and compromised-card channels.Fraud and financial-crime teams at banks and fintechs tracking the ANZ carding ecosystem and compromised-card channels.

Government and critical infrastructure operators assessing nation-state and OT-focused hacktivist activity.Government and critical infrastructure operators assessing nation-state and OT-focused hacktivist activity.

Risk, compliance, and board stakeholders who need an evidence-based read on regional cyber risk and its regulatory implications.Risk, compliance, and board stakeholders who need an evidence-based read on regional cyber risk and its regulatory implications.

Frequently asked questions

How many cyber threats did Group-IB track in ANZ in August 2026?

arrow_drop_down

Group-IB documented 53 threat events across Australia and New Zealand in August 2026, including 25 ransomware incidents, 16 data-leak publications and 4 hacktivism events. Australia was named in 89% of events.

Who is Storm Ransomware?

arrow_drop_down

A ransomware group first observed by Group-IB on 13 August 2026. In its first month it claimed five Australian victims across agriculture, automotive and construction, tying Qilin as the region’s most active operator and running a Tor-based data-leak site.

Which sector was most targeted in ANZ in August 2026?

arrow_drop_down

Healthcare, with seven ransomware events — more than triple July’s count — spanning dental, medical, pharmaceutical and health-platform organisations.

Why did compromised-account numbers fall so sharply?

arrow_drop_down

They fell 90.13% to 26,766 records, mirroring an 86% global drop, because these counts reflect when stealer logs surface and are processed — not a like-for-like fall in infections. Figures typically rise as later logs are ingested.

Who was the most active ransomware group?

arrow_drop_down

Qilin and Storm Ransomware tied as the most active in August, followed by The Gentlemen and Cl0p.

Is the report free to download?

arrow_drop_down

Yes. The August 2026 ANZ Threat Landscape is a free download via the form on this page.