Menu
Browse

Cyber Incident Victim: Trumpet of Patriots

Date:

Jun 2025

Location:

Australia

Summary

Australia political parties started by mining billionaire Clive Palmer, the United Australia Party, and Trumpets of Patriots disclosed that unauthorized actors gained access to their servers, leading to a ransomware attack that resulted in the possible exfiltration of emails, attachments, and electronically stored documents. The compromised data may include personal information such as email addresses, phone numbers, identity records, banking details, employment history, and confidential documents provided to the parties. The incident was reported to the Office of the Australian Information Commissioner and the Australian Signals Directorate, and the parties stated that notifying all affected individuals is impracticable.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On 23 June 2025 the political parties associated with mining billionaire Clive Palmer, the United Australia Party and the Trumpets of Patriots identified unauthorised access to their servers. The parties stated that the intrusion resulted in access to, and the possible exfiltration of, certain data records. They characterised the incident as a ransomware cyber‑attack. The statement was published on the parties’ website on the same day. The breach was reported to the Office of the Australian Information Commissioner and the Australian Signals Directorate.

Cyber Incident Image

The parties warned that the compromised data could include all emails to and from the organisations, together with their attachments, and any documents or records created or held electronically at any time in the past. They noted that personal information such as email addresses, phone numbers, identity records, banking records, employment history and confidential documents might have been exposed. Because they do not keep a complete record of every individual whose data was stored, they determined it impracticable to notify affected persons directly. Individuals were advised to assume that any information they had provided to the parties could have been present on the compromised servers. No further details about the attacker, ransom demand or decryption efforts were disclosed in the statement.

Sources
Sources available to members
1 source