
Regional & Sector Threat Intelligence | Ransomware, Dark Web, Vulnerability & AI-Enabled Threats
Australian and New Zealand healthcare providers were targeted by a broad, opportunistic mix of ransomware‑as‑a‑service (RaaS) affiliates during the assessment period (1 Mar – 1 Sep 2026), with no single actor emerging as dominant. Internal leak‑site monitoring identified 11 listings involving Australian healthcare organisations during the assessment period, spanning nine ransomware brands, and one listing involving a New Zealand healthcare organisation.
The period’s most significant confirmed incident, an INC Ransom attack on a national GP and skin‑cancer clinic network, illustrates the pattern seen across the sector: initial access through compromised credentials or exposed services, followed by exfiltration of Medicare, health‑insurance and clinical data, then double‑extortion via a dark‑web leak‑site posting.
Government cyber authorities in both countries, together with CERT Tonga, issued a joint advisory in March 2026 formally warning that the INC Ransom affiliate network was sustaining a campaign against Oceania healthcare and professional‑services organisations, a warning borne out by incidents recorded through to the end of the assessment period.
Third‑party and supply‑chain exposure emerged as a recurring theme: multiple general‑practice clinics using the same patient‑booking platform were compromised by the same threat actor within days of each other, and dark‑web monitoring identified at least one large, unverified claim of a bulk Australian patient‑data set offered for sale.
Key takeaway: Identity and access (stolen credentials, exposed remote-access services and shared third-party platforms) remain the dominant route into ANZ healthcare networks, not novel exploitation.
National indicators, regulatory environment and the INC Ransom regional advisory
REGIONAL THREAT LANDSCAPE
ASD/ACSC: FY2024–25
Ransomware vs. health sector doubled
ASD’s Annual Cyber Threat Report FY2024–25 recorded 84,700+ cybercrime reports and 1,200+ incidents responded to nationally (all sectors); ransomware incidents against the health sector doubled year-on-year.
ACSC: INC RANSOM ADVISORY
11 incidents, Jul 2024–Dec 2025
ACSC responded to 11 INC Ransom incidents in Australia over that window, predominantly against healthcare and professional-services organisations, forming the basis for the March 2026 joint advisory.
NZ NCSC: Q1 2026
3 “C2” incidents
NZ recorded its first highly significant (C2) incidents since 2021/22 in Q1 2026; sector attribution not published. Included for national threat-environment context.
Regulatory environment
THREAT ACTOR LANDSCAPE
Australia: healthcare leak-site listings by group (6-month internal monitoring window)

Note: group names on the x-axis are shown as recorded in internal monitoring (e.g. ‘incransom’ = INC Ransom); the same convention applies to group names on the Ransomware Landscape slides.
Reading this chart correctly
Counts are leak-site listings tracked by internal monitoring across a rolling 6-month window. They are not independently confirmed breaches unless separately corroborated (see Publicly Reported Incidents).
INC Ransom’s 3 listings sit alongside a March 2026 government advisory naming it the most persistent threat to Oceania healthcare, and the two data points independently reinforce each other.
No single group dominates: 8 of 9 groups recorded exactly one listing, consistent with opportunistic, access-driven targeting rather than a sector-specific campaign by any one actor.
Rhysida and SafePay are independently corroborated by named public reporting against a Victorian medical centre and a NSW dental/orthodontic practice respectively; the remainder are leak-site-tracked only.
Joint advisory, 6 March 2026: the Australian Signals Directorate’s ACSC, New Zealand’s NCSC and CERT Tonga jointly warned that the INC Ransom affiliate network was sustaining a campaign against Oceania healthcare and professional-services networks. The advisory is the primary official source for this section.
AUSTRALIA
NEW ZEALAND
Background
Qilin is a Ransomware-as-a-Service (RaaS) operation, emerging in 2022 and becoming a dominant threat in 2025 and 2026. It is known for a versatile and advanced codebase. Initially written in Go, Qilin has evolved into a Rust-based encryptor, improving performance and evasion capabilities, and now targets Windows, Linux and ESXi environments.
Notable TTPs
High-profile healthcare incident: a 2024 attack on a UK medical laboratory services provider severely disrupted multiple NHS hospitals, demonstrating Qilin’s potential impact on patient care. Included as global context; not an ANZ-specific incident.
Background
INC has grown into a major RaaS operation, with over 800 victims listed on its leak site since 2023 according to public leak-site tracking, and is a significant, officially recognised regional threat (see the March 2026 joint advisory covered earlier in this section). Affiliates typically gain entry through spear-phishing, purchasing credentials from initial-access brokers, or exploiting vulnerabilities in unpatched edge devices (e.g. Citrix, Fortinet).
Notable TTPs
Recent ANZ incident: claimed an attack on a national GP and skin-cancer clinic network operating 60+ clinics in Australia, of which 21 were confirmed affected, highlighting the group’s direct threat to local healthcare providers. See Ransomware Landscape for the validated, current-period detail on this incident.
Background
One of the most prolific groups in 2026, this RaaS is known for aggressive, multi-channel extortion tactics. At its peak, the group was the second most productive ransomware operation globally. It operates with a clear organisational structure and a generous affiliate model, attracting many collaborators.
Notable TTPs
Healthcare exposure: healthcare accounts for approximately 4.4% of the group’s publicly listed victims (leak-site tracking, 2025–2026). This is below the sector’s share of global ransomware victims; TheGentlemen is included here as a high-volume opportunistic actor with one ANZ healthcare listing in the period, not as a healthcare-focused group.
Australia and New Zealand healthcare leak-site activity, incident types and confirmation status
RANSOMWARE LANDSCAPE
Timeline: healthcare leak-site listings by month

1 Mar – 1 Sep 2026 is this report’s assessment period; the timeline shows months with tracked listings, so May (zero listings) is omitted.
Group × healthcare listings
| incransom | 3 | Confirmed: GP network, dental practiccommunity health org. |
| spacebears | 1 | Leak-site tracked |
| rhysida | 1 | Confirmed: medical centre |
| thegentlemen | 1 | Leak-site tracked |
| threeam | 1 | Leak-site tracked |
| qilin | 1 | Leak-site tracked |
| lockbit5 | 1 | Leak-site tracked |
| dragonforce | 1 | Leak-site tracked |
| safepay | 1 | Confirmed: dental/orthodontic practic |
14 FEB 2026, PRE-PERIOD BACKGROUND ((before 1 Mar 2026; background only))
Actor: LockBit5
A regional (AU/NZ) air-medicine not-for-profit; publicly reported on 19 Feb 2026 following the actor’s claim. Falls before this report’s 1 March assessment start and is retained only as immediate background, not presented as a current-period incident.
14 APR 2026, IN ASSESSMENT PERIOD
Actor: thegentlemen
Healthcare-sector victim recorded on the actor’s leak site. No independent public reporting located beyond leak-site monitoring; treated as a leak-site claim, not an independently corroborated breach.
Qilin leads ransomware activity across the ANZ region, followed by Cl0p and TheGentlemen, while a broader pool of active groups maintains a distributed threat landscape.
Active ransomware groups in ANZ, all sectors (2026)

6–10 Mar 2026
Dental/orthodontic practice (NSW)
SafePay lists the practice 6 Mar; staff details, addresses and patient payment plans published 10 Mar.
9–12 Jun 2026
General practice clinic (ACT)
Threat actor “2019” claims 25,000+ patient records via a shared third-party booking platform; data offered on a hacking forum.
22 Jun 2026
Weight-management clinic (VIC)
Same actor (“2019”) compromises two accounts on the same shared booking platform; incident contained quickly.
23 Jun – 31 Jul 2026
National GP network (multi-state)
Intrusion discovered 23 Jun, publicly disclosed 15–16 Jul; INC Ransom lists the network 30 Jul and publishes 11 files 31 Jul. 21 clinics affected across five states and territories.
Apr 2026 (disclosed Jul)
Medical centre (QLD)
One internal inbox compromised in April; Department of Veterans’ Affairs (DVA) numbers and other data accessed. Patients notified nearly three months later.
2–18 Aug 2026
Medical centre (VIC)
Rhysida lists it 12 Aug, claiming ~20,000 patient records. Organisation confirms it is investigating.
2–18 Aug 2026
Dental practice (VIC)
INC Ransom lists the practice 12 Aug and publishes 37 GB of data: X-rays, specialist correspondence and records for 600+ patients spanning 2003–2025.
| Date | Sector / Entity type | Actor | Status |
| 6–10 Mar 2026 | Dental/orthodontic practice (NSW) | SafePay | Corroborated |
| 9–12 Jun 2026 | General practice clinic (ACT) | “2019” | Corroborated |
| 22 Jun 2026 | Weight-management clinic (VIC) | “2019” | Confirmed by org. |
| 23 Jun 2026 | National GP network – intrusion | INC Ransom | Confirmed by org. |
| 15–16 Jul 2026 | National GP network – disclosed | INC Ransom | Confirmed by org. |
| 30 Jul 2026 | National GP network – leak-site listing | INC Ransom | Corroborated |
| Apr 2026 (disc. Jul) | Medical centre (QLD) | Unattributed | Confirmed by org. (limited) |
| 14 Apr 2026 | Healthcare-sector org. (NZ) | TheGentlemen | Leak-site claim |
| 12–18 Aug 2026 | Medical centre (VIC) | Rhysida | Claimed; org. investigating |
| 12–18 Aug 2026 | Dental practice (VIC) | INC Ransom | Corroborated |
| Apr 2026 | Aboriginal community health org. (VIC)* | INC Ransom | Confirmed by org. (contained) |
* Community health / social-services organisation; included for Aboriginal and Torres Strait Islander (ATSI) community-health relevance rather than as a clinical provider. Entity names are withheld throughout this report; the national GP network’s intrusion, disclosure and leak-site listing are shown as separate rows because each date is independently corroborated.
“Corroborated” indicates independent agreement across multiple public sources. “Leak-site claim” indicates a ransomware group’s own, unconfirmed statement. “Confirmed by org.” indicates the affected organisation itself has acknowledged the incident.
Ranking by impact requires separating what an organisation has confirmed from what a threat actor has claimed. The table below ranks this period’s AU incidents by confirmed scope and regulatory engagement, with claimed-but-unconfirmed figures shown separately. Entity names are withheld; incidents are identified by sector, entity type and location only.
| Rank | Sector / entity type | Basis for ranking | Confirmed / claimed |
| 1 | National GP network (multi-state) | 21 clinics across NSW, VIC, QLD, WA & ACT; full breadth of data types (Medicare, veteran-status, insurance & medical records, referrals, pathology); reported to privacy & cyber regulators and police; court injunction obtained. | Confirmed by org. |
| 2 | General practice clinic (ACT) | 25,000+ patient records already posted on a hacking forum. | Claimed only – org. has not confirmed scope. |
| 3 | Medical centre (VIC) | ~20,000 records claimed; patient, staff identity, HR, financial and legal data. | Claimed only – org. investigating. |
| 4 | Dental practice (VIC) | 37 GB published (not just claimed): X-rays, correspondence and records for 600+ patients spanning 2003–2025. | Data published by actor. |
| 5 | Dental/orthodontic practice (NSW) | Staff and “hundreds” of patient payment/treatment records across 6 clinics. | Data published by actor. |
| 6 | Weight-management clinic / medical centre / community health org. (VIC, QLD) | Each explicitly described as limited, contained, or affecting a single account/inbox. | Confirmed by org. (limited impact). |
Impact-ranking methodology
Incidents are ranked using:
Confirmed impact — organisational disclosures and/or multiple independent sources (e.g., clinics affected, data types, regulator notifications).
Claimed impact — threat-actor posts only (e.g., leak sites/forums) where the organisation has not confirmed the full scope.
Status labels show Confirmed, Corroborated, or Claimed only. Higher ranks may reflect potential impact from actor claims—not verified damage.
Regional context: the single largest confirmed healthcare breach across the broader ANZ picture remains a national patient-portal provider (NZ), with 99,416 confirmed affected patients (revised down from an initial 126,000 estimate), 91% concentrated in one region. It predates this report’s 1 March 2026 assessment window (incident: Dec 2025) and is not counted in the AU ranking above; it is covered as regulatory background under Regional Threat Landscape.
Underground activity, third-party exposure and the emerging use of AI against ANZ healthcare targets

Fig. 1 — Internal CTI dark-web monitoring capture, 28 Aug 2026. Forum handle and platform identifiers redacted from this caption; no patient records are shown.
UNVERIFIED · 28 AUG 2026
Internal dark-web monitoring identified a forum listing advertising a claimed 428,000-record dataset from an Australian healthcare provider, described by the seller as containing patient contact details, appointment and booking histories and patient notes, for approximately US$1,100.
Analyst assessment: Internal validation could not independently verify the claim. No official breach notifications, regulatory disclosures, or media reports were identified. As such, this is treated as an unsubstantiated assertion from underground sources, not a confirmed incident.

Fig. 2 — Historical context: 12 May 2025 listing (pre-period)
A separate listing offered a CSV of 30,000+ Australian contact records described by the seller as healthcare-related leads (US$130). Predates this report’s 1 March 2026 assessment window and is retained only as background on the ongoing commodity market in Australian contact data adjacent to healthcare. Record-level sample data has been cropped from this capture; no organisation is named in the listing itself.

Fig. 3 — Dark-web post offering stolen Australian healthcare records (17 June 2026)
A compromise of a Victorian weight-management clinic by the actor “2019” was publicly reported on 22 June 2026 (see Notable incidents). Based on internal correlation, CYFIRMA assesses that the 17 June forum listing and the 22 June reported incident concern the same organisation. The forum poster’s handle differs from “2019” and the relationship between the two handles has not been established. The seller’s claimed scale (28,400+ patients) substantially exceeds the scope the organisation has acknowledged (two compromised accounts, contained); the organisation’s account is treated as the confirmed position and the forum claim as unverified.

Fig. 4 — Unverified dark-web claim: Australian organisation data offered for sale (July 2026)
CYFIRMA observed a dark-web forum post dated 11 July 2026, where a threat actor advertised stolen data from an Australian crisis support organisation, claiming 10,600+ records compromised. CYFIRMA’s monitoring identified that the exposed data fields included personal and system-related information. The actor included sample data to substantiate the claim. CYFIRMA assesses this as an unverified claim, as no official breach notification, regulatory disclosure, or media reporting has been identified to corroborate the listing.

Fig. 5 — Unverified Australian data listing (9 June 2026)
CYFIRMA observed an unverified dark-web forum post (9 June 2026) where threat actor “2019” claimed 700,000+ records stolen from 25,000+ patients of an Australian healthcare network. Exposed fields included appointment details, patient identifiers and address information. No official breach confirmation has been identified. This is assessed to be the same event as the ACT general-practice clinic incident publicly reported on 12 June (see Notable incidents); the forum post predates the public reporting by three days.
Healthcare Dark Web Chatter by Threat Category

Internal monitoring recorded a low volume of healthcare-related dark-web chatter across the period — between 1 and 8 categorised mentions a month — so the series below is indicative only.
Assessment: healthcare-related chatter in the period concentrated on extortion and initial-access themes. The August web-exploit uptick warrants monitoring of internet-facing systems but is not, on its own, an indicator of imminent attacks.
Shared booking-platform exposure: a repeatable pattern
Two Australian general-practice clinics (an ACT clinic, 9–12 Jun 2026, and a Victorian weight-management clinic, 22 Jun 2026) were compromised within a week of each other by the same threat actor (“2019”), in both cases through accounts on the same shared patient-booking platform (name withheld). This is a textbook third-party/supply-chain exposure pattern: a single platform compromise or credential-stuffing campaign against shared infrastructure can cascade into multiple, unrelated clinics simultaneously, independent of each clinic’s own security posture.
EXPLOITED ACCESS ROUTES (GLOBAL PATTERN)
MEDICAL DEVICE / IoMT EXPOSURE (GLOBAL CONTEXT)
WHAT THIS MEANS FOR ANZ HEALTHCARE
OBSERVED: ANZ-SPECIFIC COMMENTARY
Following the national GP network incident (disclosed July 2026), industry commentary reported to a cybersecurity trade publication noted that threat actors are “increasingly leveraging generative AI to automate highly targeted phishing campaigns, spoof clinical communications, and execute attacks at unprecedented speed,” and advised patients and clinics connected to affected services to independently verify unsolicited requests. This is analyst commentary made in direct response to a confirmed ANZ healthcare incident, not a documented technical finding of AI use in that specific attack.
EMERGING RISK: GLOBAL RESEARCH & INDUSTRY WARNINGS
WHAT THIS ASSESSMENT DOES NOT CLAIM
Strategic observations, predictions, recommendations and sources
STRATEGIC OUTLOOK
Access, not exploitation, is the common thread
Where an initial-access vector has been publicly reported for this period’s corroborated incidents, it has been compromised credentials, a phished account or a shared third-party platform rather than novel technical exploitation; the vector for the national GP network intrusion has not been publicly confirmed. This is consistent with the pattern the ACSC/NCSC joint advisory describes for INC Ransom.
Third-party and platform risk is under-assessed
A shared-platform-linked compromise of two unrelated clinics in the same week shows that a clinic’s own security posture is not sufficient on its own: shared booking, EHR and communications platforms are a live, demonstrated route into multiple providers at once.
Regulatory consequences are landing, not just accumulating
The May 2026 Privacy Commissioner finding against a national patient-portal provider and the national health system operator, and the March 2026 Federal Court approval of a A$250 million settlement involving a major health insurer, show 2026 as the year earlier breaches convert into formal findings, settlements and case law for the sector.
Reading the ransomware picture honestly
No single ransomware group dominates ANZ healthcare targeting: 8 of the 9 groups tracked against Australian healthcare recorded exactly one listing each in the monitoring window. This is consistent with opportunistic, RaaS-affiliate-driven targeting (INC Ransom, Qilin and peers all operate an affiliate model) rather than a coordinated campaign against the sector specifically. The exception is INC Ransom, whose 3 listings plus the March 2026 government advisory make it the only actor with both quantitative and official-source support as the standing regional threat.
Third-party booking and practice-management platforms will produce further multi-clinic incidents (likely)
The shared-platform-linked compromises in June 2026 demonstrate a repeatable pattern: one platform compromise, multiple unrelated clinic victims. With a small number of platforms serving a large share of Australian general practice, further clustered incidents tied to a single shared vendor are likely through 2027.
INC Ransom will remain the most consistently documented threat to ANZ healthcare (highly likely)
INC Ransom is the only actor in this assessment with both a formal government advisory and multiple independently tracked incidents (a national GP network, a dental practice and a community health organisation). Its RaaS affiliate model and demonstrated Oceania focus point to continued targeting.
Regulatory findings from 2025 incidents will continue to surface through 2026–2027 (highly likely)
The May 2026 Privacy Commissioner ruling against a national patient-portal provider and the national health system operator, and the March 2026 settlement approval for a major health insurer (over three years after its 2022 breach), indicate a multi-year lag between incident and formal regulatory or judicial resolution; expect further findings tied to 2025-era incidents, including a separate e-prescription-service breach, to land through this window.
AI-enabled social engineering will be cited more often in incident commentary before it is technically confirmed in ANZ healthcare cases (likely)
Industry commentary already links AI-enabled phishing to the national GP network incident’s aftermath. Expect this framing to become standard in breach communications and advisories even where forensic attribution of AI tooling to a specific ANZ healthcare intrusion remains unconfirmed, a gap analysts should continue to flag explicitly.
Likelihood terms follow CYFIRMA’s standard scale (remote / unlikely / realistic possibility / likely / highly likely). Predictions are analyst assessments based on the intelligence available at the time of writing, not statements of fact about future events.
Harden identity & access
Extend risk assessment to shared platforms
Prepare for regulatory scrutiny
Priority action: organisations using shared booking or practice-management platforms should confirm with their vendor whether any related account compromise has occurred, independent of whether their own clinic has observed suspicious activity.
Methodology
Key sources