🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇦🇺 AU › Retail
Retail sector · leaderboard
Own the Retail leaderboard
The top banner across the Retail overview and every Retail record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

Sydney Tools

🇦🇺 Sydney, NSW · Sydney Tools Pty Ltd · Record AU-2025-0203
○ Reported — awaiting official confirmation
Reported — awaiting official confirmation. The facts below are drawn from the organisation's own disclosure and credible reporting. Figures are as reported; unknowns are labelled, not estimated by us.
People affected
Not disclosed
Breach date
2025-03
Regulator
OAIC (notifiable)
Trust tier
B · Reported

Data exposed

~34 million customer and order records exposed via a misconfigured database Media-reported

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

In March 2025 researchers reported that hardware retailer Sydney Tools had left a database misconfigured and publicly accessible, exposing around 34 million customer and order records [cybernews-st]. This was an exposure through misconfiguration rather than a hack. The number of distinct individuals affected was not officially confirmed and is not estimated here.

Timeline

  • 2025-03 — Misconfigured database found publicly exposing ~34M records [cybernews-st].

Current status

Reported; access reportedly closed after disclosure. Figures reflect the researcher findings. [cybernews-st]

Why it matters

A textbook cloud-misconfiguration exposure — a reminder that breaches don’t always require an attacker, just a setting left open.

GGOVERN Tabletop Exercises · Govern house Strengthen your cyber resilience — rehearse the decisions that matter. Book a Discovery Call →