September brought a run of NZ and Australian incidents that are more useful than the usual breach headlines, because each one maps to a specific, trainable failure mode. Here is the two-minute version of each, and the one thing worth changing in your own organisation as a result.
1. A Perth school breach shows how wide "personal data" really runs
St James Anglican School in Perth reported a cyberattack in mid-September that exposed student and family contact details, bank details, medical information and student photos. The school notified the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
The detail worth sitting with is the range. A school is not a bank, but its breach reads like one: financial data, health data, images of children. Almost every SME holds a similar spread without thinking of itself as a data business — payroll bank accounts, sick leave records, site photos, emergency contacts. We cover what that exposure costs in the real cost of a data breach for NZ SMEs. Full analysis below in this series: what the St James breach means for any organisation holding family data.
2. An insider charge in NSW corrections
A NSW corrections officer was charged over alleged unauthorised access to inmate information — 85 restricted-data offences alleged. Allegations, not findings; the courts will decide. But the pattern is the classic insider one: legitimate credentials, illegitimate curiosity.
The trainable point: access reviews and audit logging are not compliance theatre. They are how this conduct gets detected and prosecuted at all. Our take on the wider pattern: insider access: the threat your firewall cannot see.
3. An unverified ransomware claim against a software supplier
Actors associated with Storm ransomware reportedly claimed to have compromised customers of Auto-IT, a dealer management software provider. As of writing there is no direct incident notice from the company, and a claim on a leak site is not a confirmed breach — criminal groups routinely exaggerate.
The reason it still matters: if your business runs on a handful of specialist SaaS suppliers, your incident response plan has to work even when the supplier has said nothing yet. We walk through that scenario in when your software supplier gets a ransomware claim, and the general pattern in supply chain attacks through vendors.
4. The ASD warning: legacy tech plus AI-enabled attackers
The head of the Australian Signals Directorate warned that legacy technology is leaving Australia exposed to AI-enabled intrusion and automation at scale. Strip the geopolitics and the operational claim is simple: attackers now automate reconnaissance and exploitation cheaply, so the old systems you have been meaning to replace get found faster than ever. More in legacy systems in the age of AI-assisted attackers.
5. Fake recruiters delivering malware to IT professionals
On 18 September, Australia's cyber agency issued an advisory on North Korean campaigns — tracked as WaterPlum, also called Contagious Interview — targeting IT professionals through fake recruitment approaches that deliver malware. Your developers and IT staff are being head-hunted by people whose job offer is an infection chain. Breakdown and staff briefing points: the fake recruiter attack targeting your IT team.
And New Zealand?
No major new confirmed public NZ breach surfaced in this window. That is not evidence of safety — NZ incidents often surface late or never, and the Privacy Commissioner's notification threshold means plenty of smaller events stay quiet. The May Canvas/Instructure incident that touched NZ education users is a reminder that most NZ exposure arrives through offshore suppliers anyway.
Practical takeaway
- Map what personal data you actually hold — the school breach range (financial, medical, images) is a good checklist
- Review who has access to sensitive records and whether that access is logged and reviewed
- Ask your critical SaaS suppliers how they would notify you of an incident — before one is claimed
- Brief technical staff on recruitment-lure malware this week; it is aimed at them personally
- Put one hour into the legacy-system list you have been avoiding
Awareness training exists to turn news like this into instinct. SecureAZ runs short, NZ/AU-specific modules and phishing simulations that cover exactly these patterns — start a free 45-day trial.