Cyber Incident Victim: TAFE NSW
Date:
Aug 2019
Location:
Australia
Summary
A phishing attack compromised the payroll system of TAFE NSW, resulting in the theft of personal bank details belonging to approximately 30 staff members. The breach caused delayed salary payments for affected employees, with the incident attributed to a targeted cyber intrusion aimed at extracting sensitive financial information.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In early August 2019, TAFE NSW experienced a cybersecurity incident involving unauthorized access to its payroll system. The breach resulted in the theft of personal and banking details belonging to staff members. According to institutional statements and affected employees, approximately 30 personnel had their sensitive information compromised during the attack. This theft directly impacted payroll operations, causing delayed salary payments to the affected individuals during the August pay cycle. TAFE NSW characterized the intrusion as a "targeted phishing attack," indicating that deceptive electronic communications likely facilitated initial access to the system. While the exact timeline of the breach wasn't publicly disclosed, the incident came to light when employees reported missing payments and suspected unauthorized access to their financial accounts. The attackers specifically targeted payroll data, suggesting financial motives behind the operation.

TAFE NSW confirmed the breach on August 8, 2019, after conducting preliminary investigations into the payment disruptions. The organization notified impacted staff directly and initiated coordination with relevant authorities, though specific law enforcement or regulatory bodies weren't named in available reports. Institutional responses focused on addressing immediate payroll issues while forensic examinations continued to determine the full scope of compromised systems. No public statements confirmed whether student data or academic systems were affected, with all verified impacts confined to employee payroll information. The incident exposed vulnerabilities in administrative systems handling sensitive financial data, though TAFE NSW didn't disclose technical details about security controls or specific phishing mechanisms exploited. Ongoing investigations sought to identify the perpetrators and establish whether additional data exfiltration occurred beyond the confirmed payroll information theft affecting two dozen staff members.
