Melbourne-based broker ThinkMarkets has been hit by the Chaos ransomware group, which stole 512GB of data. The breach includes employee passports and customer KYC records, posing a major risk to the Australian financial services firm and its clients worldwide.
Inotiv has confirmed a major data breach after a Qilin ransomware attack exposed the personal, financial and health information of over 9,000 people. The hit on this large US research company highlights rising supply chain risks across the pharmaceutical and healthcare sectors.
Critical React flaw React2Shell is under active state sponsored exploitation, allowing unauthenticated remote code execution across thousands of web apps. ACSC and US CISA have issued urgent warnings, calling on Australian organisations to patch immediately.
12th December 2025 Cyber Update: Melbourne Broker ThinkMarkets Hit by Chaos Ransomware
Melbourne-based broker ThinkMarkets has been hit by the Chaos ransomware group, which stole 512GB of data. The breach includes employee passports and customer KYC records, posing a major risk to the Australian financial services firm and its clients worldwide.
Cyber News Centre's cyber update for 12th December 2025: Melbourne-headquartered online trading broker ThinkMarkets has become the latest Australian financial services firm to be targeted by a ransomware attack, with the emerging Chaos group claiming to have stolen a significant volume of sensitive data.
ThinkMarkets is a multi-regulated online brokerage firm established in 2010, with headquarters in Melbourne and London. The company provides CFD trading services across forex, stocks, and cryptocurrencies to clients in over 165 countries and holds 10 regulatory licenses, including from the Australian Securities and Investment Commission (ASIC).
The Update and Why It Matters
Update: The Chaos ransomware group listed ThinkMarkets on its dark web leak site earlier this week, claiming to have exfiltrated 512 gigabytes of data from the Australian broker. The threat actors have reportedly published the data online after ransom negotiations failed. The compromised information is extensive, containing highly sensitive corporate and personal records. According to security researchers who have viewed the data, the leak includes internal human resources files, details of customer disputes, legal advice, and confidential trading information.
Most alarmingly, the breach exposed scans of employee passports and know-your-customer (KYC) verification documents for a number of the firm’s clients. The Chaos group, first observed in February 2025, is a relatively new ransomware-as-a-service (RaaS) operation actively recruiting affiliates on Russian-speaking forums. The group employs a double-extortion model, threatening to publish stolen data if ransom demands, which have been as high as $300,000 in previous attacks, are not met. ThinkMarkets has not yet issued a public statement on the incident.
Why it Matters: This attack on an ASIC-regulated broker highlights the significant and growing threat to Australia’s financial services sector. The exfiltration of passport scans and KYC documents creates a severe risk of identity theft and financial fraud for both employees and clients of ThinkMarkets. For Australian investors, it is a stark reminder that even regulated financial entities are vulnerable to sophisticated cyber attacks.
The incident also underscores the operational risk posed by emerging RaaS groups like Chaos, which can quickly scale their attacks and cause widespread damage. The breach serves as a critical warning for the entire financial supply chain, demonstrating that robust security measures are essential to protect sensitive client data and maintain trust in the digital economy.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Inotiv has confirmed a major data breach after a Qilin ransomware attack exposed the personal, financial and health information of over 9,000 people. The hit on this large US research company highlights rising supply chain risks across the pharmaceutical and healthcare sectors.
Critical React flaw React2Shell is under active state sponsored exploitation, allowing unauthenticated remote code execution across thousands of web apps. ACSC and US CISA have issued urgent warnings, calling on Australian organisations to patch immediately.
A significant supply chain attack has struck the US financial sector, with fintech vendor Marquis Software Solutions confirming a ransomware incident that exposed the sensitive data of hundreds of thousands of customers from dozens of American banks and credit unions.
South Korean e-commerce giant Coupang has confirmed a massive data breach exposing the personal information of 33.7 million customers. The incident, which began in June 2025, is one of the largest in the nation's history and is linked to a former employee's active credentials.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!