The CL0P ransomware gang has breached Podiatry WA, a key Australian healthcare association, as part of a massive 22-victim global attack wave. The incident highlights the escalating threat of data extortion targeting professional services and healthcare sectors across Australia.
Microsoft has issued an emergency patch for a high-severity zero-day vulnerability (CVE-2026-21509) in Microsoft Office. The flaw, which bypasses key security features, is being actively exploited in targeted attacks, posing a significant risk to organizations globally, including in Australia.
Hayward's HEN Technologies has secured $22 million in Series A funding to scale its AI-driven fire suppression platform. The company's IoT-enabled hardware captures real-world physics data, creating a predictive analytics engine for emergency response.
29th January 2026 Cyber Update: CL0P Ransomware Hits Australian Healthcare Association
The CL0P ransomware gang has breached Podiatry WA, a key Australian healthcare association, as part of a massive 22-victim global attack wave. The incident highlights the escalating threat of data extortion targeting professional services and healthcare sectors across Australia.
Cyber News Centre's cyber update for 29th January 2026: Podiatry WA, a professional association for podiatrists in Western Australia, has been breached by the notorious CL0P ransomware gang.
Podiatry WA is a professional association and public company limited by guarantee based in Australia. It represents podiatrists and chiropodists, promotes foot health, and supports professional development and education for the podiatry profession in Western Australia.
The Update and Why It Matters
Update: The CL0P ransomware group has claimed responsibility for a data breach at Podiatry WA, a professional healthcare association based in Western Australia. The attack is part of a significant global campaign that saw the group list 22 new victims in a single 24-hour period, with 11 of those located in Australia. This aggressive wave of attacks highlights a renewed focus on the professional services and healthcare sectors.
The breach was first reported by cyber industry monitoring experts on January 28, 2026, with the threat actor adding Podiatry WA to its dark web leak site. The full extent of the data stolen remains unknown, but the incident places the sensitive information of the association and its members at significant risk. CL0P, a Russian-speaking cybercrime collective also known as TA505, has a history of large-scale data extortion campaigns and has reportedly amassed over $500 million from its operations.
The group is known for exploiting zero-day vulnerabilities and has recently been observed targeting supply chain vulnerabilities and high-value enterprise infrastructure. This latest campaign follows a reported 525% increase in CL0P's activity in 2025, signaling a major resurgence for the prolific ransomware operator.
Why it Matters: This attack on a professional healthcare body underscores the relentless targeting of Australia's critical sectors. The breach is not an isolated event but part of a coordinated, large-scale assault on Australian organisations, demonstrating the persistent and evolving threat posed by sophisticated ransomware groups like CL0P.
For small and medium-sized businesses (SMBs) within the healthcare supply chain, this incident is a stark reminder of their vulnerability. These organisations are often seen as soft targets due to limited cybersecurity resources. The consequences of such a breach extend beyond financial loss, risking the exposure of sensitive professional and potentially patient-related data, eroding trust, and causing significant operational disruption.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Microsoft has issued an emergency patch for a high-severity zero-day vulnerability (CVE-2026-21509) in Microsoft Office. The flaw, which bypasses key security features, is being actively exploited in targeted attacks, posing a significant risk to organizations globally, including in Australia.
Nike is investigating a massive data breach after the WorldLeaks ransomware group claimed to have stolen 1.4TB of sensitive data, including Jordan Brand design files, supply chain details, and internal documents. The breach poses a significant threat to Nike's IP operations in Australia.
The Everest ransomware group has breached ASRock Rack, a major server hardware vendor, stealing 509GB of sensitive data including firmware, BIOS, and other critical files. The breach creates a significant supply chain risk, potentially allowing attackers to embed vulnerabilities in server hardware.
A newly disclosed vulnerability in Schneider Electric's Foxboro DCS, a widely used industrial control system, could allow attackers to disrupt critical infrastructure operations. The flaw, originally from Intel, affects energy and manufacturing sectors worldwide, including Australia.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!