🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇦🇺 AU › Other
Other sector · leaderboard
Own the Other leaderboard
The top banner across the Other overview and every Other record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

Toll Group

🇦🇺 Melbourne, VIC · Toll Holdings (Toll Group) · Record AU-2020-0130
○ Reported — awaiting official confirmation
Reported — awaiting official confirmation. The facts below are drawn from the organisation's own disclosure and credible reporting. Figures are as reported; unknowns are labelled, not estimated by us.
People affected
Not disclosed
Breach date
2020-05
Regulator
OAIC (notified)
Trust tier
B · Reported

Data exposed

Personal information of past and present employees Company-confirmed
Details of commercial agreements with current and former enterprise customers Company-confirmed

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

In May 2020 the logistics company Toll Group was hit by the Nefilim ransomware — its second ransomware incident that year. Toll confirmed the attacker had downloaded data from a corporate server, including personal information of past and present employees and details of commercial agreements with some enterprise customers [toll-itnews]. Toll declined to pay the ransom, and stolen data was subsequently published on the dark web [toll-acs].

Timeline

  • 2020-05 — Nefilim ransomware attack; Toll confirmed data had been downloaded from a corporate server [toll-itnews].
  • 2020-05 — Stolen data was posted to a dark-web leak site after Toll refused to pay [toll-acs].

Current status

Disclosed. Toll did not publish a count of affected individuals, so no figure is asserted here. Figures and data types are as reported by the company and credible media [toll-itnews], [toll-acs].

Why it matters

A major trans-Tasman logistics operator, hit twice in one year, with confirmed exfiltration and dark-web publication of employee data — an early, high-profile example of double-extortion ransomware in the region.

GGOVERN Tabletop Exercises · Govern house Strengthen your cyber resilience — rehearse the decisions that matter. Book a Discovery Call →