CSIDB logo
Incident

Trumpet of Patriots

Incident posture

Attack window
Jun 2025
Location
Australia
Status
Unknown
CIA posture
Available to members
Updated
2026-07-18 07:30

Linked entities

Victim
Trumpet of Patriots
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Australia political parties started by mining billionaire Clive Palmer, the United Australia Party, and Trumpets of Patriots disclosed that unauthorized actors gained access to their servers, leading to a ransomware attack that resulted in the possible exfiltration of emails, attachments, and electronically stored documents. The compromised data may include personal information such as email addresses, phone numbers, identity records, banking details, employment history, and confidential documents provided to the parties. The incident was reported to the Office of the Australian Information Commissioner and the Australian Signals Directorate, and the parties stated that notifying all affected individuals is impracticable.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On 23 June 2025 the political parties associated with mining billionaire Clive Palmer, the United Australia Party and the Trumpets of Patriots identified unauthorised access to their servers. The parties stated that the intrusion resulted in access to, and the possible exfiltration of, certain data records. They characterised the incident as a ransomware cyber‑attack. The statement was published on the parties’ website on the same day. The breach was reported to the Office of the Australian Information Commissioner and the Australian Signals Directorate.

The parties warned that the compromised data could include all emails to and from the organisations, together with their attachments, and any documents or records created or held electronically at any time in the past. They noted that personal information such as email addresses, phone numbers, identity records, banking records, employment history and confidential documents might have been exposed. Because they do not keep a complete record of every individual whose data was stored, they determined it impracticable to notify affected persons directly. Individuals were advised to assume that any information they had provided to the parties could have been present on the compromised servers. No further details about the attacker, ransom demand or decryption efforts were disclosed in the statement.

Sources

Sources available to members: 1 source.

CSIDB