🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇦🇺 AU › Finance
Finance sector · leaderboard
Own the Finance leaderboard
The top banner across the Finance overview and every Finance record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

Firstmac

🇦🇺 Brisbane, QLD · Firstmac Limited · Record AU-2024-0130
○ Reported — awaiting official confirmation
Reported — awaiting official confirmation. The facts below are drawn from the organisation's own disclosure and credible reporting. Figures are as reported; unknowns are labelled, not estimated by us.
People affected
Not disclosed
Breach date
2024-04
Regulator
OAIC (notifiable)
Trust tier
B · Reported

Data exposed

Name, date of birth, address, email and phone number Company-confirmed
External bank account details (BSB and account number) and driver licence number Media-reported

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

In April–May 2024 the non-bank lender Firstmac notified customers of a data breach after the EMBARGO ransomware group published stolen data on the dark web [fm-bitdefender], [fm-cyberdaily]. Firstmac confirmed that personal information — names, dates of birth, addresses, email addresses and phone numbers — had been compromised; reporting on the leaked trove also described external bank account details (BSB and account number) and driver licence numbers [fm-bitdefender], [fm-cyberdaily].

Timeline

  • 2024-04 — Data stolen; EMBARGO listed Firstmac data on its leak site late April [fm-cyberdaily].
  • 2024-05 — Firstmac notified affected customers [fm-bitdefender].

Current status

Disclosed. Firstmac did not publish a count of affected individuals, so no figure is asserted here. The volume of leaked data reported by the attacker is not a reliable measure of how many people were affected [fm-cyberdaily].

Why it matters

A lender holds exactly the identity and banking data that enables fraud — names, dates of birth, and account details together. A double-extortion ransomware group publishing it raises the risk for those affected.

GGOVERN Tabletop Exercises · Govern house Rehearse the breach before it reaches the balance sheet. Book a Discovery Call →