Recomputed on every load

Ransomware Claims Against Australian Organisations

By Nick Forshteyn · CISO AI
Figures as at 2 October 2026, from a file read 2 October 2026

Ransomware groups have posted 531 Australian organisations on their leak sites, by 109 different groups. 487 of those are from 2023 onward, when the tracker's systematic coverage begins; the 44 listings before that are historical cases going back to 2016. 169 were posted in the last twelve months, 15% more than the 147 in the twelve before. The typical month brings 13 claims, and the busiest in the last two years was November 2024 with 20.

Every row on this page is a claim made by a criminal group on its own site, recorded by the public tracker ransomware.live. Nothing here is verified. Groups list organisations they never breached, list them during negotiations, and get names and countries wrong. Where we have written a brief on a listing it says "claims" for that reason, and so does this page.

Claims per month

5 10 15 20 November 2024: 20 claims December 2024: 16 claims January 2025: 18 claims Jan 2025February 2025: 16 claims March 2025: 9 claims April 2025: 10 claims Apr 2025May 2025: 6 claims June 2025: 14 claims July 2025: 5 claims July 2025August 2025: 11 claims September 2025: 7 claims October 2025: 15 claims Oct 2025November 2025: 12 claims December 2025: 14 claims January 2026: 8 claims Jan 2026February 2026: 15 claims March 2026: 8 claims April 2026: 20 claims Apr 2026May 2026: 20 claims June 2026: 11 claims July 2026: 15 claims July 2026August 2026: 19 claims September 2026: 12 claims October 2026: 0 claims Oct 2026

Australian organisations first seen on a leak site in each of the last 24 months, by the date the tracker recorded the post. Hover a column for the figure.

Who is posting now

22 groups posted an Australian organisation in the last 90 days, 45 claims between them against 51 in the 90 days before. 12 of them had not posted an Australian victim in the quarter before that. The most active this quarter is thegentlemen with 9 claims. This is the present tense, not a forecast: which group posts next depends on whose affiliates compromised whom months ago, and the sequence of Australian posts does not predict it.

GroupClaims, last 90 daysQuarter before
thegentlemen 9 Also active last quarter
qilin 7 Also active last quarter
Storm 6 Not seen the quarter before
settra 3 Not seen the quarter before
kairos 2 Also active last quarter
L Group 2 Not seen the quarter before
chaos 1 Not seen the quarter before
clop 1 Not seen the quarter before
cmdorganization 1 Also active last quarter
Deadlock 1 Not seen the quarter before

Over the whole file, 43 groups have posted exactly one Australian organisation and never returned. The groups that keep coming back are few:

GroupClaims, all timeMost recent
qilin 43 24 September 2026
lockbit3 35 6 October 2024
incransom 26 12 August 2026
clop 25 12 August 2026
akira 21 14 January 2026
alphv 21 24 November 2023
ransomhub 20 17 March 2025
dragonforce 18 11 July 2026
safepay 17 20 July 2026
lynx 16 5 January 2026

Sectors, last twelve months

Of the 169 organisations posted in the last twelve months, the tracker could place 159 in a sector and 10 it could not. Professional Services leads with 23.3% of the classified claims. For an Australian business the question this answers is not "am I a target", which every sector is, but how often organisations like yours have been posted lately.

  • Professional Services 37 · 23.3%
  • Retail & E-Commerce 28 · 17.6%
  • Healthcare 17 · 10.7%
  • Technology 17 · 10.7%
  • Manufacturing 16 · 10.1%
  • Agriculture and Food Production 8 · 5%

The latest claims

The 15 most recent, newest first. 5 listings have a brief, written from the listing alone and worded as the claim it is.

SeenGroupOrganisation, as listedSectorBrief
30 September 2026 lamashtu Virtual Ideasvirtualideas.com.au Technology Read the brief
28 September 2026 threeam stjames.wa.edu.austjames.wa.edu.au Education Read the brief
24 September 2026 qilin Zig Inge Groupwww.prospecthillcamberwell.com.au Unclassified Read the brief
24 September 2026 krybit www.jonesthegrocer.comwww.jonesthegrocer.com Retail & E-Commerce Read the brief
17 September 2026 settra pacificabs.compacificabs.com Professional Services Read the brief
16 September 2026 qilin Reddrop Groupwww.reddrop.com.au Unclassified No brief yet
16 September 2026 qilin Thorndale Foundationwww.thorndale.com.au Unclassified No brief yet
16 September 2026 kairos Leisure Coast Kitchens Retail & E-Commerce No brief yet
15 September 2026 thegentlemen Alchin Long Groupalchinlong.com Unclassified No brief yet
7 September 2026 thegentlemen Sharp Officesharpoffice.com.au Professional Services No brief yet
3 September 2026 Storm Macquarriemacquarrie.com.au Financial Services No brief yet
3 September 2026 settra verveportraits.com.auverveportraits.com.au Retail & E-Commerce No brief yet
29 August 2026 qilin The Frame Groupwww.framegroup.com.au Retail & E-Commerce No brief yet
28 August 2026 qilin DigiGroundwww.digiground.com.au Technology No brief yet
27 August 2026 chaos singleton.comsingleton.com Unclassified No brief yet

What this page can and cannot say

  • Claims, not breaches. A listing means a group said it has an organisation's data. Some listings are true, some are exaggerated, some are false, and this page cannot tell which. It reports what was posted.
  • The country is inferred. The tracker tags a victim's country from its website and public records, and gets it wrong sometimes; a Canadian law firm has sat in the Australian file. The counts here carry that error.
  • Dates are when the tracker saw the post. A group may have posted days earlier, and the incident itself is usually weeks or months before that.
  • Groups rename and reorganise. A group that "disappears" from the table has often reappeared under another name, and a "new" group may be an old one's affiliates. The tables use the names the tracker uses.
  • No forecast. Which group posts the next Australian victim is not predictable from this data, and the page does not try. A rate is a fact; a prediction would be a guess with a decimal point.

Method

The source is ransomware.live's public API, its file of every victim tagged Australian, which our news worker reads every three hours for its own leak-site feed and caches. This page reads that cache and computes every figure above at request time, so the numbers and the sentences describing them can never disagree. Months are counted by the tracker's discovery date. The file holds a few listings from before the tracker existed, added by hand; the page counts them but dates its coverage from the first year with at least 50 listings. A sector the tracker could not determine is counted but never ranked. The page is cached for fifteen minutes.

Comments

No comments yet.

To comment, confirm your email once. We send a sign-in link; no password to remember.

Your name appears with your comment; your email never does. By continuing you accept our terms and privacy policy.

Written analysis by Nick Forshteyn. The automated briefings, including those written from these listings, are published separately.