Cyber Incident Victim: Trumpet of Patriots
Date:
Jun 2025
Location:
Australia
Summary
Australia political parties started by mining billionaire Clive Palmer, the United Australia Party, and Trumpets of Patriots disclosed that unauthorized actors gained access to their servers, leading to a ransomware attack that resulted in the possible exfiltration of emails, attachments, and electronically stored documents. The compromised data may include personal information such as email addresses, phone numbers, identity records, banking details, employment history, and confidential documents provided to the parties. The incident was reported to the Office of the Australian Information Commissioner and the Australian Signals Directorate, and the parties stated that notifying all affected individuals is impracticable.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On 23 June 2025 the political parties associated with mining billionaire Clive Palmer, the United Australia Party and the Trumpets of Patriots identified unauthorised access to their servers. The parties stated that the intrusion resulted in access to, and the possible exfiltration of, certain data records. They characterised the incident as a ransomware cyber‑attack. The statement was published on the parties’ website on the same day. The breach was reported to the Office of the Australian Information Commissioner and the Australian Signals Directorate.

The parties warned that the compromised data could include all emails to and from the organisations, together with their attachments, and any documents or records created or held electronically at any time in the past. They noted that personal information such as email addresses, phone numbers, identity records, banking records, employment history and confidential documents might have been exposed. Because they do not keep a complete record of every individual whose data was stored, they determined it impracticable to notify affected persons directly. Individuals were advised to assume that any information they had provided to the parties could have been present on the compromised servers. No further details about the attacker, ransom demand or decryption efforts were disclosed in the statement.
