Menu
Browse

Cyber Incident Victim: Domain Group

Date:

May 2021

Location:

Australia

Summary

Domain Group experienced a phishing attack that compromised its administrative systems, enabling scammers to contact users who had inquired about rental properties. The attackers attempted to deceive individuals into paying deposits through fraudulent websites. The company acknowledged the incident, noting increased public vigilance against such scams but highlighted a rise in similar fraudulent activities following the pandemic. In response, additional security controls and heightened monitoring were implemented to mitigate further risks.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On or around May 19, 2021, Australian digital real estate company Domain Group publicly confirmed a phishing attack targeting its administrative systems. The attackers gained unauthorized access through phishing techniques, enabling them to interact with individuals who had submitted rental property inquiries via Domain’s platform. According to CEO Jason Pellegrino, the scammers exploited this access to contact potential renters by email, directing them to fraudulent websites and instructing them to pay deposits to secure rental properties. The attack specifically leveraged Domain’s communication channels to impersonate legitimate rental processes, though the exact number of affected users or compromised accounts was not disclosed. Domain did not confirm whether any financial losses occurred as a result of the scam attempts.

Cyber Incident Image

Domain Group responded by implementing additional security controls and elevating system monitoring to prevent further unauthorized activity. Pellegrino acknowledged the broader rise in phishing scams during the COVID-19 pandemic, noting that the incident highlighted persistent threats despite increased public awareness of suspicious online behavior. The company emphasized that the attack was isolated to its rental inquiry system and unrelated to a separate health board incident mentioned in its communications. No technical specifics regarding the phishing vector, duration of unauthorized access, or identity of the threat actors were disclosed. Domain’s parent company, Nine Entertainment Co., which holds a 65% ownership stake, was not reported to have been directly impacted by the incident.

Sources
Sources available to members
1 source