Between April and June 2026, a series of cyber security incidents affected organisations across the financial, healthcare, education, government, manufacturing, retail and community sectors.
While some organisations successfully contained attacks before they caused major disruption, others experienced large-scale data breaches, operational shutdowns and the exposure of highly sensitive information.
These incidents serve as a reminder that cyber threats are no longer limited to large enterprises.
Businesses of every size are being targeted, often through third-party providers, stolen credentials or ransomware attacks.
Below are the ten most significant cyber security incidents reported during the quarter, based on their reach, operational impact and potential financial and reputational consequences.
One of the largest incidents during the quarter affected the Queensland Department of Education after the ShinyHunters threat group compromised a third-party cloud provider.
The breach exposed student and staff information, including names, email addresses and school locations. While no financial information was reported as compromised, the scale of the incident created significant opportunities for phishing and identity-based attacks.
Why it matters:
This breach highlights how vulnerabilities within third-party providers can have widespread consequences, even when an organisation’s own systems remain secure.
The Melbourne International Film Festival confirmed it was responding to claims that hackers had accessed information belonging to more than 340,000 customers.
With such a large customer database potentially exposed, affected individuals face increased risks of phishing attempts, identity fraud and scams impersonating trusted organisations.
Why it matters:
Large customer databases remain highly valuable targets for cyber criminals due to their potential for future fraud and social engineering attacks.
Booking.com disclosed that hackers had gained access to customer information through a third-party compromise.
The exposed data included customer names, email addresses, physical addresses and booking details. The information was then used to launch highly convincing phishing campaigns targeting travellers.
Why it matters:
Supply chain attacks continue to grow because compromising one trusted provider allows attackers to target thousands of organisations and customers simultaneously.
Ochre Health confirmed patient information from its Tuggeranong clinic may have been compromised after attackers allegedly breached a third-party platform.
More than 25,000 patient records were reportedly stolen before being offered for sale on a hacking forum.
Why it matters:
Medical information is among the most valuable forms of personal data. Once exposed, patients can face identity theft, fraud and long-term privacy concerns.
A cyber incident forced two Mackay Sugar mills in North Queensland to halt operations.
Unlike many cyber attacks that focus solely on data theft, this incident disrupted manufacturing operations, highlighting the growing risk to operational technology and critical infrastructure.
Why it matters:
Operational downtime often results in immediate financial losses, production delays and supply chain disruption that extend well beyond the initial attack.
Generation Life confirmed customer information had been affected following a cyber attack first identified in April.
The organisation confirmed investment operations continued as normal, with client investments and funds remaining secure.
Why it matters:
Financial organisations rely heavily on customer trust. Even where core systems remain unaffected, customer data breaches can result in significant reputational damage.
Queensland accounting firm Kennedy McLaughlin confirmed it had been targeted by the Qilin ransomware group.
Client financial and banking information was later published online, increasing the risk of fraud and identity theft.
Why it matters:
Professional services firms hold large volumes of confidential financial information, making them attractive targets for ransomware operators.
The NSW Rural Fire Service experienced a cyber security incident involving historical organisational data.
Although emergency response capabilities remained fully operational, historical records were likely compromised.
Why it matters:
Government agencies must protect both active and archived information, as historical data can still be valuable to attackers.
The Canvas learning platform suffered a criminal cyber attack that affected schools, universities and vocational education providers across Australia and internationally.
As a widely used education platform, the incident demonstrated how a single compromise can impact multiple institutions simultaneously.
Why it matters:
Shared technology platforms can quickly become high-value targets because one breach affects thousands of users.
Gregory Jewellers confirmed a cyber incident after threat actors claimed to have stolen more than 500 GB of company data.
The volume of stolen information suggests customer records, employee information and commercial documents may have been exposed.
Why it matters:
Retailers continue to be attractive targets due to the combination of customer information, payment data and commercially sensitive business information they manage.
Several additional organisations also experienced cyber security incidents during the quarter, including:
While these incidents had a smaller reach or more limited operational impact, they reinforce that cyber attacks continue to affect organisations across every industry.
Several clear trends emerged throughout the quarter.
Third-party providers continue to be one of the weakest links in many organisations’ cyber security strategies, with multiple breaches originating from external software or cloud platforms. Healthcare, education and financial services remain frequent targets due to the value of the information they hold, while ransomware groups continue to prioritise organisations where operational disruption creates pressure to pay.
The incidents also demonstrate that cyber attacks are no longer solely about stealing data. Increasingly, attackers aim to disrupt operations, damage reputations and exploit trusted relationships between organisations and their customers.
Building cyber resilience requires more than technology alone. Organisations should regularly review supplier security, enforce multi-factor authentication, maintain secure backups, train employees to recognise phishing attempts and continuously monitor their environments for suspicious activity. Taking a proactive approach can significantly reduce both the likelihood and impact of a cyber incident.
Cyber threats continue to evolve, but your business doesn’t have to face them alone.
Whether you’re looking to strengthen your cyber security, reduce business risk or ensure your organisation is prepared to respond to emerging threats, Perigon One can help. Our team works with businesses across Australia to deliver practical, proactive cyber security solutions that protect your people, systems and data.
Ready to strengthen your organisation’s cyber resilience?
Book a strategic conversation with Perigon One to identify potential risks, enhance business continuity, and ensure your technology supports long-term growth with confidence.