Australian Retail Threat Report · 2026

Before its your Breach

A leadership guide to the cyber threats reshaping Australian Retail.

Four real breaches. Australia’s most recognised retail brands. Every one of them preventable – and dissected, control by control in this report.

Get the Report

Each one could have been stopped

This report dissects exactly what happened — then re-examines each breach against the architecture that would have contained it.

Real Incident Analysis

Sydney Tools, Total Tools, Stan Cash, The Iconic, and Dan Murphy's. Every breach dissected with timelines, attack vectors, and the specific controls that were missing.

Regulatory exposure mapped

Privacy Act reform, mandatory ransomware reporting now in force, PCI DSS 4.0 active, and OAIC breach notifications at their highest level ever.

What would have changed

Each breach re-examined against the architecture that would have contained it. No ambiguity. No abstraction. No hypotheticals.

Incident Ledger

Four breaches. One pattnern.

None of these took sophistication. An open database. An unguarded checkout. Recycled passwords. A trusted vendor. Each was avoidable — and together they map exactly where Australian retail is being hit.

34 M
Orders Exposed
38 K
Cards Compromised
15 K+
Accounts Drained
20 day
ransom deadline

Work with people who've done it before

Scoping a deployment, mid-rollout with another provider, or starting again after a stalled project. We'll give you an honest read on what it takes to get it done.

Discuss your deployment See how we work
Image placeholder