CSIDB logo
Incident

LandMark White

Incident posture

Attack window
Jan 2019
Location
Australia
Status
Historical
CIA posture
Available to members
Updated
2025-11-05 00:00

Linked entities

Victim
LandMark White
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity incident at valuation firm LandMark White exposed personal data including property valuations, contact details, and birthdates of approximately 100,000 customers through an exposed programming interface on one of its platforms. Multiple major Australian banks suspended their engagements with the company following the breach, which the firm claimed was isolated to a single system with no evidence of data misuse or compromised financial documents. The incident exacerbated existing financial challenges for the organization, which had already experienced reduced business volumes due to regulatory pressures and broader banking sector turmoil, contributing to a decline in its share price.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around January 23, 2019, LandMark White (LMW), a major valuation firm servicing Australian banks, experienced a data breach involving an exposed programming interface on one of its valuation platforms. The breach resulted in the leakage of personal information belonging to up to 100,000 customers, including property valuations, phone numbers, dates of birth, first and last names, residential addresses, and contact numbers of homeowners, residents, and property agents. LMW confirmed the breach was isolated to a single system, contained no loan application details or financial/identity documents, and showed no evidence of misuse. The company closed the compromised interface on January 23 after identifying it as the source. External advisors verified the breach’s containment, with no ongoing suspicious network activity detected. LMW directors and franchise owners subsequently engaged in talks with clients to address identity theft concerns, while chairman Keith Perrett emphasized continuous communication with business partners regarding what he termed a "complex attack."

The incident triggered significant operational and financial repercussions. By February 13–14, 2019, National Australia Bank (NAB), Commonwealth Bank, and ANZ Banking Group suspended their use of LMW’s services, citing customer data security as paramount. LMW’s share price fell 2.3% to 42.5¢ following NAB’s announcement, compounding existing financial strain. Prior to the breach, LMW had already issued a 25% profit downgrade for the first half of FY2019, attributing reduced valuation volumes to tighter APRA credit regulations and lender reactions to the Banking Royal Commission. The breach exacerbated these challenges, though LMW maintained that disclosed data lacked sensitive financial or identity documents and reiterated the absence of evidence regarding misuse of leaked information.

Sources

Sources available to members: 1 source.

CSIDB