File-borne breach events · Oceania
Australia: documented file-borne breach events
Australia documents breach vectors in court rather than in press releases: the regulators' filings against FIIG Securities, RI Advice and Australian Clinical Labs each name the file or the email, and the university at the centre of the 2018 ANU breach published its own attack chain.
Overview
What the record shows
Australia's file-borne record is written mostly by its regulators' litigation. The corporate regulator's pleadings against FIIG Securities name the exact archive and the script inside it, and the Federal Court's February 2026 judgment made that the first Australian civil penalty for cybersecurity failures under financial services licence obligations. The court's agreed facts in the RI Advice case list email delivered ransomware and a phishing campaign that put a credential capturing file behind a cloud storage link. The privacy regulator's filing against Australian Clinical Labs records a phishing email as the attack vector for the country's first Privacy Act penalty.
The Australian National University's own 2019 incident report remains the most transparent account any victim organisation in the region has published, and it is also a lesson in reading vectors precisely: the report states the initial infection was a spear-phishing email which did not require user interaction, and it is the second, third and fourth campaigns that delivered malicious Word documents.
Australia's other headline incidents are excluded on the regulators' own evidence. The Optus breach is documented as an exposed API endpoint, and the Qantas incident as phone based social engineering, neither of which is a file.
Documented events
File-borne incidents in Australia
Most recent first. Every entry cites the public record it is drawn from.
-
GO2 Health: Phishing email opened a Brisbane clinic's main mailbox to an attacker
The main reception mailbox at the Everton Park practice was accessed in April 2026. Because the mailbox auto archives, exposure was confined to twelve months of correspondence, which included some patients' Department of Veterans Affairs identification numbers, medical history and referrals; the primary patient records system was not reached. The regulator was notified in May and patients in July 2026, and no evidence of publication or misuse was reported.
The documented vector. Phishing email that led to compromise of the practice's main mailbox. The practice's own statement says it became aware of unauthorised access to one of its email mailboxes via a phishing email, and engaged external experts to investigate and contain the incident. The statement does not specify what the message carried, and this entry does not fill that in.
How this class of vector is removed
The vector class the practice named, a phishing message reaching a shared clinical mailbox, crosses the boundary as a file. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to its format's known good specification before it reaches a busy reception desk, which is a control that does not depend on the reader spotting the message. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the statement does not say what the message carried.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- healthcare
-
FIIG Securities Limited: A zip archive holding a disguised script opened the breach behind Australia's first cyber penalty
From 19 May 2023 the attacker used the downloaded script to fetch a second stage and establish persistence, reached a privileged account by 23 May, and exfiltrated about 385 gigabytes including driver's licences, passports, tax file numbers and bank details, with around 18,000 clients notified. The ALPHV group published data in June 2023. In February 2026 the Federal Court imposed a 2.5 million dollar penalty, the first Australian civil penalty for cybersecurity failures under financial services licence obligations.
The documented vector. Zip archive containing a JavaScript file named to look like a security agreement. The corporate regulator's statement of claim records that an employee downloaded a zip file while browsing the internet, and that the archive contained a JavaScript file named "second ranking general security agreement 85822.js", which invoked the Windows script host. The archive and the disguised script are documented in the pleadings rather than in the judgment.
How this class of vector is removed
This class of vector, an executable script hidden inside an archive and named to look like a routine business document, is addressed at the download boundary: an ICAP hop routes web downloads through the CDR pipeline, where the archive is opened and its contents assessed, and a raw script, which has no document format to be rebuilt against, is quarantined or blocked by policy rather than delivered under its filename. Foresight scores the structure ahead of that decision. The mapping is held at medium confidence because a script is policy handled rather than rebuilt.
ICAP ClientContent Disarm and ReconstructionForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight
- banking
Source: Australian Securities and Investments Commission · Source: Federal Court of Australia · Source: Australian Securities and Investments Commission
-
Australian Clinical Labs Limited (Medlab Pathology): Phishing email recorded as the vector behind Australia's first Privacy Act penalty
The Quantum ransomware group compromised the Medlab Pathology network on or before 25 February 2022, exfiltrated 86 gigabytes and published it to the dark web by June 2022, exposing passport numbers, health information and payment card details for at least 223,269 individuals. In October 2025 the Federal Court imposed 5.8 million dollars in civil penalties, the first ever under the Privacy Act. The commissioner's filing also records that the company relied on its mail platform's built in malware detection and retained firewall logs for one hour.
The documented vector. Phishing email addressed to an employee, per the Information Commissioner's court filing. The Australian Information Commissioner's concise statement records that the company's forensic provider concluded the attack vector was a phishing email addressed to an employee. The commissioner records that conclusion while criticising the adequacy of the engagement that produced it, and this entry carries the finding with that qualification attached rather than as a finding of the court.
How this class of vector is removed
The vector class recorded in the filing, a phishing email reaching an employee, crosses the trust boundary as a file: the message and anything it carries. A CDR hop on inbound mail rebuilds carried content to its format's known good specification and applies policy outcomes to the message, which is a different control from the platform malware detection the filing describes, because it does not depend on recognising the threat. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the record does not state what the message carried.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- healthcare
Source: Office of the Australian Information Commissioner · Source: Office of the Australian Information Commissioner
-
RI Advice Group Pty Ltd: Court's agreed facts document email delivered ransomware and a credential capturing file behind a cloud link
Nine cyber incidents across the licensee's authorised representative practices were put before the Federal Court, which in May 2022 made the first Australian finding that a financial services licensee had breached its licence obligations through cybersecurity failures. The agreed contributing failures included no filtering or quarantining of emails and absent or outdated antivirus. The licensee paid 750,000 dollars in costs and was ordered to engage a cybersecurity expert.
The documented vector. Phishing emails linking to a cloud storage folder holding a credential capturing file; a separate incident in the same findings was ransomware delivered by email. The statement of agreed facts annexed to the Federal Court's 2022 judgment records that phishing emails were sent to over 150 clients asking recipients to click a link to a cloud storage folder, and that the folder contained a file that was capturing credentials. The same agreed facts record an earlier incident where a practice's reception computer was hit by ransomware delivered by email.
How this class of vector is removed
Both documented classes of vector here sit on the mail path. Ransomware delivered by email is removed by rebuilding inbound attachments to their format's known good specification before delivery, and where the message instead points at a file in cloud storage, an ICAP hop routes that download through the same rebuild. The court's agreed facts note that no filtering or quarantining of email was in place, which is the control layer this maps to, and the relay applies allow, warn, quarantine and block outcomes there.
Email CDR RelayContent Disarm and ReconstructionICAP ClientGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- banking
-
The Australian National University: Campaign against university systems used malicious Word attachments to harvest credentials
A sophisticated actor operated inside ANU's network for about six weeks from November 2018, targeting the domain holding human resources, financial and student administration records. ANU initially feared up to 19 years of personal records had been taken; later forensics indicated substantially less, though the exact records could not be determined. The university disclosed the breach in June 2019 and published a detailed public incident report in late 2019, which remains the authoritative account.
The documented vector. Malicious Word documents that sent users' credentials to attacker infrastructure when opened. ANU's incident report documents that the initial infection was an interaction-less spear-phishing email, and that the attackers' second, third and fourth spear-phishing cycles then delivered malicious Word document attachments. In the report's words, the user opened the attached Word document and the credentials were sent to the remote server, with all attachments in those cycles using the same technique.
How this class of vector is removed
The documented file-borne stages of this campaign, malicious Word attachments carrying credential-harvesting code, belong to a class of vector that is removed by deterministic CDR rebuild: each attachment is rebuilt to the format's known-good specification with macros and active content stripped, so the document that reaches the user cannot call out to attacker infrastructure. The Email CDR Relay applies the rebuild on inbound mail. The campaign's initial interaction-less email sits outside this class, which is why this entry maps the attachment cycles and not the whole intrusion.
Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- education
Source: The Australian National University · Source: ABC News
Scope
How to read this page
Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.
This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.
Elsewhere in the region

