Article
Australian Cyber Security Breaches
From Optus and Medibank to Mathspace in 2026, Australian breaches keep repeating the same gaps: unpatched tools, missing MFA, third-party access, and data kept too long. A preventative audit, IT training, and a compliance system close those gaps before you are the next notice.

Australian organisations keep landing in the same news cycle. A product, a lender, an airline, a law firm, or a health network loses control of personal information. Customers get a letter. The OAIC gets a notification. Boards ask how it happened. The honest answer is usually unglamorous: an unpatched tool, a login without multi-factor authentication, a contractor who could see too much, or records that should have been deleted years ago.
This page is a sourced ledger of recent Australian cyber security incidents, from household names to the education-platform breach reported this week. It is written for founders shipping vibe-coded apps, small businesses without a security owner, and enterprise IT teams that already have staff and still need an external preventative programme.
The photograph in the hero is from 7NEWS coverage of the Mathspace breach (8 September 2026). Credit: 7NEWS. Mathspace's own account is in its incident notice.
AL Phesda Interactive does preventative work. We audit systems, train existing IT, and help you put compliance controls in place. We do not sell incident response, forensics, or a promise to un-hack a live breach. If you are in an active incident, start with the Australian Cyber Security Centre, then book a Discovery Session for the rebuild that stops the next one.
Mathspace, September 2026
Online learning platform Mathspace confirmed on 3 September 2026 that unauthorised parties accessed an internal reporting system and downloaded information on students, parents or guardians, and school staff, including some Mathspace staff records. Chief technology officer Alvin Savoy told 7NEWS that 1,079,819 people in Australia and New Zealand were affected.
The company's own notice says unauthorised access dated back to 10 August 2026, and that information was downloaded from an Australian reporting database on 27 August. Passwords, academic records and results, single sign-on tokens, and other customer authentication credentials were not exposed. Depending on the record, exported fields included names, email addresses, usernames, and login metadata.
Cyber Daily reported that the attacker exploited an unpatched vulnerability in a self-hosted Metabase installation. The advisory had been public since 6 August. Mathspace said its internal vulnerability-notification process did not catch it. That is the lesson for every team running reporting software, admin dashboards, or a vibe-coded app with an open /admin route: patching and access control are the product, not a later sprint.
Mathspace notified the OAIC, ASD's ACSC, New Zealand's Office of the Privacy Commissioner, and New Zealand's National Cyber Security Centre. If you run internal analytics, a CRM export tool, or an AI-generated admin panel, this is the incident to put in front of your board this quarter. Start with a cyber security audit for the organisation, or a vibe coding audit if the weak surface is an AI-generated app.
The Australian pattern, in numbers
The OAIC's 2025 Notifiable Data Breaches figures recorded 1,205 notifications, an 8% rise on 2024 and the highest annual total since the scheme began in 2018. Of those, 716 were attributed to malicious or criminal activity. Health service providers were the most commonly affected sector, with 225 notifications.
Scale is not a defence. Optus, Medibank, and Qantas had resources most Australian businesses will never have. Mathspace shows that a specialised product with more than a million education users can still lose control of a reporting tool. Startups and SMBs are not too small to be interesting. They are often the easier target.
Major Australian incidents, sourced
Each row below is a published fact pattern, not a courtroom finding unless a regulator has already filed. Where the OAIC has closed inquiries without a formal investigation, that is stated. Use the links. Do not treat this ledger as legal advice.
Qantas, June 2025
Qantas disclosed a cyber incident affecting about 5.7 million unique customers after a social engineering attack on an overseas third-party contact centre using a Salesforce-linked environment. On 16 July 2026 the OAIC completed preliminary inquiries and did not open a formal investigation, concluding the information obtained did not reveal omissions or failings that would support a likely Privacy Act breach by Qantas. The lesson is still operational: staff and vendors can be socially engineered, third-party platforms inherit your customer records, and training plus access design are preventative work, not a poster on the wall.
MediSecure, 2024
Former electronic-prescription provider MediSecure notified a ransomware incident that the OAIC later described as affecting approximately 12.9 million individuals, the largest number notified under the NDB scheme at the time. See the OAIC statement on the MediSecure breach. The National Cyber Security Coordinator publicly tied the compromise to a third-party vendor. The company later entered voluntary administration. Health and identity data does not get less sensitive because a vendor collapsed.
Latitude Financial, March 2023
Non-bank lender Latitude disclosed a cyber incident in mid-March 2023 that widened, within days, from hundreds of thousands of records to about 14 million, including millions of driver licence numbers. ABC News reported Latitude would not pay a ransom. A large share of the stolen records related to former customers and old applications. Retaining identity documents indefinitely is a privacy and security decision, not an archive habit.
Optus, September 2022
Optus announced on 22 September 2022 that a cyberattack had compromised personal information of millions of current and former customers. On 8 August 2025 the Australian Information Commissioner filed Federal Court civil penalty proceedings, alleging Optus seriously interfered with the privacy of approximately 9.5 million Australians by failing to take reasonable steps to protect personal information. The alleged facts are before the court. Public reporting has long described an unauthenticated API as the entry. For a product team, that is APP 11 in engineering language: do not leave a customer-data interface on the public internet without credentials.
Medibank, October 2022
Medibank notified a cyber attack in which threat actors accessed personal information of millions of current and former customers, including health claims data for a subset, later published on the dark web. The OAIC filed Federal Court proceedings in June 2024, alleging Medibank seriously interfered with the privacy of 9.7 million Australians. Reporting at the time described stolen contractor credentials used against a VPN that did not enforce MFA. That control is still the cheapest preventative item on most Australian stacks.
HWL Ebsworth, April 2023
Law firm HWL Ebsworth, used by dozens of government agencies, was hit by the ALPHV/BlackCat ransomware group. ABC News and The Guardian reported terabytes of data claimed stolen and later published, including material tied to government clients. Professional services firms hold other people's secrets. A preventative audit of identity, backups, and privileged access is cheaper than explaining a client-file leak to a department.
Ticketmaster / Live Nation, May 2024
Live Nation's SEC filing confirmed unauthorised activity in a third-party cloud database environment containing Ticketmaster data, identified on 20 May 2024. ABC News reported the Department of Home Affairs was investigating a cyber incident involving Ticketmaster, with Australian customers among those potentially affected. The wider Snowflake-customer campaign was widely described as stolen credentials against cloud data stores that lacked MFA. If your warehouse, analytics tenant, or vibe-coded backend has a shared password and no second factor, you are in that story.
What these incidents share
Strip the brand names and the same surfaces remain:
- Unpatched software and forgotten admin tools. Mathspace's Metabase instance. Every staging site, reporting dashboard, and AI-generated admin panel that nobody owns.
- Identity without MFA. Contractor VPNs, cloud warehouses, shared mailboxes, default admin on a vibe-coded app.
- Third parties who can see your customers. Contact centres, prescription vendors, service providers holding driver licences.
- Data kept past its use. Latitude's historic applicant records. APP 11 and APP 4 are preventative design, not a cleanup after the letter goes out.
- People who can be socially engineered. Qantas's contact-centre path. Staff training is a control, not a nice-to-have video.
Those are the surfaces a cyber security audit ranks for websites, email, cloud, and devices. They are the seven surfaces a vibe coding audit inspects on an AI-generated app: auth and secrets, access control, privacy, payments, debt, reliability, hosting. When a new AI or CRM project changes collection, a Privacy Impact Assessment is how you change the design before go-live. Framework work sits on Essential Eight adoption and NIST CSF adoption.
Startups, small businesses, and enterprise
Startups and vibe-coded products
Cursor, Lovable, Bolt, v0, Replit, and Copilot will ship a login screen. They will not patch Metabase for you, enforce row-level access, or tell you that last month's advisory applied to your reporting box. If strangers can sign up, you are in production. The standard vibe coding audit is $200 + GST for one eligible app. Rescue work is quoted from the report. Read why vibe-coded apps fail if you need the engineering argument first.
Small businesses without a security owner
Most Australian NDB notifications are not Optus-scale. They are mailboxes without MFA, backups that never restore, and WordPress plugins left open. A one-off SMB audit from $1,300 + GST gives you a ranked list in plain English. We then train the people you already have, and quote hardening item by item. Detail: what a cyber security audit covers.
Enterprise and in-house IT
We are not a replacement security operations centre. We are the external preventative programme your IT team can use when they need an honest baseline, staff awareness that is not theatre, and a compliance system mapped to Essential Eight or NIST CSF. You keep the tickets. We help you close the gaps insurers, tenders, and APP 11 actually ask about.
Request a Discovery Session. You leave with a plan either way.
Australian cyber breach FAQs
Does AL Phesda respond to live cyber attacks?
No. We do preventative audits, hardening, IT training, and compliance systems. If you are in an active incident, report it through cyber.gov.au and your legal advisers. After containment, we can audit what failed and help you build the controls that should have been there.
Are small businesses really targeted in Australia?
Yes. OAIC notification volume is at a record high, and attackers assume smaller teams skip MFA, patching, and tested backups. You do not need to be a household name. You need to look slightly harder than the next mailbox.
How is a vibe coding audit different from a cyber security audit?
A vibe coding audit reviews one AI-generated app: the repo, hosting, auth, privacy, and debt. A cyber security audit reviews the organisation: websites, email, cloud accounts, and devices. Many startups need both. Prices are published on each service page.
Do we need a Privacy Impact Assessment after a headline like Mathspace?
A PIA is for a specific project that changes collection, use, or disclosure, including AI tools and new reporting databases. It is not a substitute for patching. If you are about to ship something that holds student, health, or customer records, read when to conduct a PIA and scope the assessment before go-live.
Where should we start this week?
Book a Discovery Session. Bring the stack you actually run: the vibe-coded app, the Microsoft 365 tenant, the reporting tool nobody patched. We will tell you whether the next step is a $200 app audit, an SMB cyber audit, a PIA, or Essential Eight adoption, and quote before work starts.