NSW Treasury Staffer Allegedly Exfiltrates 5600 Sensitive Documents

NSW Treasury Staffer Allegedly Exfiltrates 5600 Sensitive Documents

First seen 21 Apr 2026, 07:00 UTC Itnews.Auwww.nsw.gov.auNsw.AuThemandarin.Au 51.8

Article Content

Browse articles
ThreatCluster

A staff member of the NSW Treasury is accused of exfiltrating over 5600 sensitive documents from multiple state departments. The breach was detected through internal security monitoring, which identified a suspected transfer of confidential commercial and financial information to an external server. NSW Police were notified of the incident on April 16, 2026, and launched an investigation under Strike Force Civic. A 45-year-old man was arrested in Sydney's CBD and charged with accessing and modifying restricted data. All allegedly stolen data has reportedly been located and secured, with no external compromise to the agency's systems. The NSW Chief Cyber Security Officer is coordinating a whole-of-agency response as per the state’s cybersecurity plan. Currently, there is no impact on any NSW government services.

Key Points: • Over 5600 sensitive documents were allegedly exfiltrated by an NSW Treasury staff member. • The breach was detected through internal security monitoring on April 16, 2026. • A 45-year-old man has been arrested and charged, with all stolen data reportedly secured.

Timeline

2026-04-16
NSW Treasury reported data breach to NSW Police.
2026-04-17
Police launched investigation under Strike Force Civic.
2026-04-20
Man arrested and charged with accessing restricted data.
2026-04-21
NSW Treasury confirms all stolen data is secured.