Skip to content
NSW Treasury Staffer Allegedly Exfiltrates 5600 Sensitive Documents

NSW Treasury Staffer Allegedly Exfiltrates 5600 Sensitive Documents

First seen 21 Apr 2026, 07:00 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 22, 2026 at 06:36 UTC
  • •Over 5600 sensitive documents were allegedly exfiltrated by an NSW Treasury staff member.
  • •The breach was detected through internal security monitoring on April 16, 2026.
  • •A 45-year-old man has been arrested and charged, with all stolen data reportedly secured.

A staff member of the NSW Treasury is accused of exfiltrating over 5600 sensitive documents from multiple state departments. The breach was detected through internal security monitoring, which identified a suspected transfer of confidential commercial and financial information to an external server. NSW Police were notified of the incident on April 16, 2026, and launched an investigation under Strike Force Civic. A 45-year-old man was arrested in Sydney's CBD and charged with accessing and modifying restricted data. All allegedly stolen data has reportedly been located and secured, with no external compromise to the agency's systems. The NSW Chief Cyber Security Officer is coordinating a whole-of-agency response as per the state’s cybersecurity plan. Currently, there is no impact on any NSW government services.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 172d ago How this analysis works

Timeline

2026-04-16
NSW Treasury reported data breach to NSW Police.
2026-04-17
Police launched investigation under Strike Force Civic.
2026-04-20
Man arrested and charged with accessing restricted data.
2026-04-21
NSW Treasury confirms all stolen data is secured.

More articles in this cluster (5)

Following this threat?

Track NSW Government in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed