Medtronic says a third party accessed data in corporate IT systems, while ShinyHunters claims more than nine million records were stolen. The incident did not disrupt products or patient care, but it exposes the widening risk around corporate IT, identity data and medical technology supply chains.
Australia’s A$25bn AI wager, Bezos’s leap into “physical AI” and Musk’s push to shift data centres into orbit turned this week into a defining moment in the AI global industrial contest, with the Global South emerging as both proving ground and prize in the new AI steel age.
Vercel confirms a security incident after a compromised third-party AI tool's OAuth token allowed attackers to pivot into internal systems, exposing environment variables and API keys across its platform.
12th December 2025 Cyber Update: Melbourne Broker ThinkMarkets Hit by Chaos Ransomware
Melbourne-based broker ThinkMarkets has been hit by the Chaos ransomware group, which stole 512GB of data. The breach includes employee passports and customer KYC records, posing a major risk to the Australian financial services firm and its clients worldwide.
Cyber News Centre's cyber update for 12th December 2025: Melbourne-headquartered online trading broker ThinkMarkets has become the latest Australian financial services firm to be targeted by a ransomware attack, with the emerging Chaos group claiming to have stolen a significant volume of sensitive data.
ThinkMarkets is a multi-regulated online brokerage firm established in 2010, with headquarters in Melbourne and London. The company provides CFD trading services across forex, stocks, and cryptocurrencies to clients in over 165 countries and holds 10 regulatory licenses, including from the Australian Securities and Investment Commission (ASIC).
The Update and Why It Matters
Update: The Chaos ransomware group listed ThinkMarkets on its dark web leak site earlier this week, claiming to have exfiltrated 512 gigabytes of data from the Australian broker. The threat actors have reportedly published the data online after ransom negotiations failed. The compromised information is extensive, containing highly sensitive corporate and personal records. According to security researchers who have viewed the data, the leak includes internal human resources files, details of customer disputes, legal advice, and confidential trading information.
Most alarmingly, the breach exposed scans of employee passports and know-your-customer (KYC) verification documents for a number of the firm’s clients. The Chaos group, first observed in February 2025, is a relatively new ransomware-as-a-service (RaaS) operation actively recruiting affiliates on Russian-speaking forums. The group employs a double-extortion model, threatening to publish stolen data if ransom demands, which have been as high as $300,000 in previous attacks, are not met. ThinkMarkets has not yet issued a public statement on the incident.
Why it Matters: This attack on an ASIC-regulated broker highlights the significant and growing threat to Australia’s financial services sector. The exfiltration of passport scans and KYC documents creates a severe risk of identity theft and financial fraud for both employees and clients of ThinkMarkets. For Australian investors, it is a stark reminder that even regulated financial entities are vulnerable to sophisticated cyber attacks.
The incident also underscores the operational risk posed by emerging RaaS groups like Chaos, which can quickly scale their attacks and cause widespread damage. The breach serves as a critical warning for the entire financial supply chain, demonstrating that robust security measures are essential to protect sensitive client data and maintain trust in the digital economy.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Medtronic says a third party accessed data in corporate IT systems, while ShinyHunters claims more than nine million records were stolen. The incident did not disrupt products or patient care, but it exposes the widening risk around corporate IT, identity data and medical technology supply chains.
Vercel confirms a security incident after a compromised third-party AI tool's OAuth token allowed attackers to pivot into internal systems, exposing environment variables and API keys across its platform.
According to Microsoft’s April 2026 Security Update Guide, the company fixed more than 160 vulnerabilities across Windows, Office and core services, including an actively exploited SharePoint zero‑day and a Defender privilege‑escalation flaw.
The largest DeFi exploit of 2026 has seen $293 million drained from Kelp DAO's LayerZero cross-chain bridge, triggering a $5.4 billion withdrawal panic across the broader ecosystem and exposing critical centralization flaws in modular security.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!