---
title: 2019's cyber security breaches in Australia
description: Cyber security breaches in Australia are growing at an incredible pace, take a look at some of the biggest breaches of 2019 so far.
image: https://www.themissinglink.com.au/hubfs/Cyber%20security%20breaches%20img.jpg
---

[Cyber Security.](https://www.themissinglink.com.au/news/tag/cyber-security) 16.10.19

# 2019's cyber security breaches in Australia

Cyber security breaches in Australia rose by almost [80% in 2018](https://bdoaustralia.bdo.com.au/acton/attachment/18110/f-6eba696f-b266-4b04-a4a0-a4d2d025c351/1/-/-/-/-/1113_18_19-Cybersecurity-Report.pdf?sid=TV2:HNlOXky45). Due to the increase in the number of cyber breaches, it has exposed a vulnerability for Australian businesses. Over [60% of organizations in Australia](https://www.cmo.com.au/article/661080/report-data-breaches-rise-australian-businesses-ill-prepared/) do not have the resources necessary to respond to cyber security attacks. Companies have been urged to place a more significant investment in cyber security awareness and incident management.

In order to increase awareness that a cyberattack can affect anyone, here is our list of high-profile breaches that affected Australian businesses in 2019.

 

#### **PayID **

PayID allows banking customers to use their mobile number or email address as a form of identification for payment. This circumvents the need to provide a BSB and account number. This freedom came with a price when more than [90,000 users](https://www.smh.com.au/business/banking-and-finance/payid-in-new-breach-affecting-customers-at-big-four-banks-20190821-p52jby.html) had their bank account details and personal data leaked after PayID was hacked via Credit Union Australia.

The good news is that no financial transactions took place and the information that was stolen cannot be used to facilitate financial payments.

 

#### **LandMark White**

LandMark White is an independent property valuation and consulting organization based in Sydney.

Early this year, personal details, driver’s licenses and property valuations of 275,000 individuals were made available on the dark web by Stephen Grant, a trusted contractor of the firm. Grant was arrested under the suspicion that he gained unauthorized access to the firm’s database and documents that he uploaded to the dark web. It is estimated to have cost LandMark White close to [$8 million](https://www.smh.com.au/national/nsw/trusted-inside-access-sydney-it-contractor-arrested-over-landmark-white-data-breach-20191002-p52wup.html).

 

#### **Canva**

Canva is one of Australia’s biggest software companies. It is an online service that can be used to design and create content, logos, or other marketing collateral.

On May 24, Canva experienced a security breach. According to the hacker behind the attacks, data for roughly 139 million users was taken. The stolen data included details such as customer usernames, email addresses and locations. Password hashes were also present for [61 million users](https://www.zdnet.com/article/australian-tech-unicorn-canva-suffers-security-breach/).

 

#### **Puma**

Puma’s Australian online store was taken down after it was discovered to have been [infected by the Magecart malware](https://www.itnews.com.au/news/puma-pulls-down-malware-infested-australian-webstore-524513). Hackers managed to disguise the malware on Puma’s website and could steal the shoppers' credit card information during the checkout process.

 

#### **Australian Catholic University**

Australian Catholic University was the target of a [cyberattack on 22 May 2019](https://www.acu.edu.au/about-acu/news/2019/june/cyber-attack-on-acu-it-systems). The data breach affected staff email accounts and the University system was also compromised.

The data breach originated from a phishing attack, where an email had been spoofed, making it appear to have been sent from inside ACU. This tricked users into clicking on a link where they were asked to enter their credentials on a fake ACU login page.

Staff login credentials were obtained successfully via the attack and were used to access email and bank account details of the staff members.

 

#### **Princess Polly**

Princess Polly, an Australian online fashion retailer, fell victim to a [data breach](https://www.itnews.com.au/news/aussie-fashion-e-tailer-princess-polly-suffers-data-breach-525998) that exposed customers' personal and payment information. The company has claimed that they do not store payment information on the website, they said the attackers might have captured payment details when shoppers entered them into the site. There is also speculation that the attackers may have also taken passwords, usernames, shipping and billing details.

In this ever-growing cyber landscape, threats are lurking at every turn. [Security Awareness Training](https://www.themissinglink.com.au/enterprise-cyber-security-security-awareness-training) is essential as it ensures that employees are fully aware of the consequences of failing to protect their organization from outside attacks.

If you would like to [learn more](https://www.themissinglink.com.au/contact-us) about Security Awareness Training or how your business can improve its [security posture](https://www.themissinglink.com.au/enterprise-cyber-security), speak with one of our security experts today.

[![Missing-Link-CTAs_3-04](https://www.themissinglink.com.au/hs-fs/hubfs/Missing-Link-CTAs_3-04.jpg?width=820&name=Missing-Link-CTAs_3-04.jpg)](https://www.themissinglink.com.au/asd-8-assessment)

If you liked this article, you may also like:

[How to create an application whitelisting policy](https://www.themissinglink.com.au/news/how-to-create-an-application-whitelisting-policy)

[Security Culture & Awareness](https://www.themissinglink.com.au/news/security-culture-and-awareness)

[Patching is key to the ASD Essential 8: Do it right in 7 steps](https://www.themissinglink.com.au/news/patching-is-key-to-the-asd-essential-8)

**Author**

[Kendall King](https://www.themissinglink.com.au/news/author/kendall-king)

Account Executive

share

[**](http://www.linkedin.com/shareArticle?mini=true&url=https://www.themissinglink.com.au/news/australian-cyber-security-breaches-in-2019) [**](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.themissinglink.com.au%2Fnews%2Faustralian-cyber-security-breaches-in-2019) [**](https://www.twitter.com/share?url=https%3A%2F%2Fwww.themissinglink.com.au%2Fnews%2Faustralian-cyber-security-breaches-in-2019)

![The Missing Link](https://www.themissinglink.com.au/hubfs/TML-Infy-Core-Logo-RGB-Org%20-%20Edited.png)

- Featured Services
- [SmartCLOUD](https://www.themissinglink.com.au/smartcloud)
- [SmartPROTECT](https://www.themissinglink.com.au/smartprotect)
- [Application Security ](https://www.themissinglink.com.au/application-security)
- [RPA](https://www.themissinglink.com.au/ai-automation-services/ai-powered-automation/rpa-as-a-service)
- [Managed Detection ](https://www.themissinglink.com.au/managed-detection-and-response)
- [Managed IT ](https://www.themissinglink.com.au/managed-it-services)
- [Cloud Security Services](https://www.themissinglink.com.au/cloud-security-services)
- [Managed IT Security](https://www.themissinglink.com.au/managed-security-services)
- [Managed IT Sydney](https://www.themissinglink.com.au/managed-it-services-sydney)
- [Managed IT Melbourne](https://www.themissinglink.com.au/managed-it-services-melbourne)

- Legal
- [Terms & Conditions​](https://www.themissinglink.com.au/terms-and-conditions)
- [Fair Use Policy](https://www.themissinglink.com.au/fair-use-policy)
- [Terms of Use](https://www.themissinglink.com.au/terms-of-use)
- [Privacy Policy](https://www.themissinglink.com.au/privacy-policy)
- [Acceptable Usage Policy](https://www.themissinglink.com.au/acceptable-usage-policy)
- [Cookie Policy](https://www.themissinglink.com.au/cookie-policy)
- [Vulnerability Disclosure Policy](https://www.themissinglink.com.au/vulnerability-disclosure-policy)

- More
- [Contact Us ​](https://www.themissinglink.com.au/contact-us)
- [Careers](https://www.themissinglink.com.au/careers)
- [Government ​](https://www.themissinglink.com.au/government)
- [Sitemap ](https://www.themissinglink.com.au/our-sitemap)

##### Acknowledgement of Country

The Missing Link acknowledges the Traditional Owners of the land where we work and live. We pay our respects to Elders past, present and emerging. We celebrate the stories, culture and traditions of Aboriginal and Torres Strait Islanders of all communities who also work and live on this land.

**

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Kendall King",
    "url" : "https://www.themissinglink.com.au/news/author/kendall-king"
  },
  "dateModified" : "2020-08-31T00:52:32.669Z",
  "datePublished" : "2019-10-16T22:32:15.000Z",
  "headline" : "2019's cyber security breaches in Australia",
  "image" : [ "https://www.themissinglink.com.au/hubfs/Cyber%20security%20breaches%20img.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.themissinglink.com.au/news/australian-cyber-security-breaches-in-2019",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.themissinglink.com.au/hubfs/TML-Infy-Core-Logo-RGB-Org%20-%20Edited.png"
    },
    "name" : "The Missing Link"
  }
}
```

```json
{
  "@context" : "https://schema.org/",
  "@type" : "WebSite",
  "name" : "The Missing Link",
  "potentialAction" : {
    "@type" : "SearchAction",
    "query-input" : "required name=search_term_string",
    "target" : "https://www.themissinglink.com.au/results{search_term_string}"
  },
  "url" : "https://www.themissinglink.com.au/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "Organization",
  "logo" : "https://www.themissinglink.com.au/hubfs/svgs/TML_Logo-Aust-UK.svg",
  "name" : "The Missing Link",
  "sameAs" : "https://www.linkedin.com/company/the-missing-link-pty-ltd/",
  "url" : "https://www.themissinglink.com.au/"
}
```