www.nsw.gov.au NSW Treasury Staffer Allegedly Exfiltrates 5600 Sensitive Documents
Article Content
- •Over 5600 sensitive documents were allegedly exfiltrated by an NSW Treasury staff member.
- •The breach was detected through internal security monitoring on April 16, 2026.
- •A 45-year-old man has been arrested and charged, with all stolen data reportedly secured.
A staff member of the NSW Treasury is accused of exfiltrating over 5600 sensitive documents from multiple state departments. The breach was detected through internal security monitoring, which identified a suspected transfer of confidential commercial and financial information to an external server. NSW Police were notified of the incident on April 16, 2026, and launched an investigation under Strike Force Civic. A 45-year-old man was arrested in Sydney's CBD and charged with accessing and modifying restricted data. All allegedly stolen data has reportedly been located and secured, with no external compromise to the agency's systems. The NSW Chief Cyber Security Officer is coordinating a whole-of-agency response as per the state’s cybersecurity plan. Currently, there is no impact on any NSW government services.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track NSW Government in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…