The Breach Ledger is a Coastal Cyber research series examining cyber incident trends across Australian industries. Each edition draws on three primary sources: the Webber Insurance named breach register [1] (678 Australian incidents, 2018–2026), OAIC Notifiable Data Breach reports published since the scheme commenced in February 2018 [2], and threat intelligence from the ASD Annual Cyber Threat Report [3]. Together, they map what is happening in a given sector, what the consequences look like in practice, and what organisations are risking by treating security as next year’s budget problem.
This is the Not-for-Profit Edition.
Criminals linked to the LockBit ransomware group breached Pareto Phone, a Brisbane telemarketing company that calls potential donors on behalf of Australian charities. They stole roughly 150 gigabytes of data — more than 320,000 files. [4]
Pareto Phone wasn’t the target because of what it held for itself. It was the target because of who it worked for. Up to 70 charities were caught in the blast radius, including the Australian Conservation Foundation, Amnesty International, the Cancer Council, and the Fred Hollows Foundation. The Australian Conservation Foundation alone had to notify 13,500 supporters. Published data included donor names, dates of birth, addresses, and, for a subset of records swept up in the same breach, police checks, tax file numbers, immigration documents, and passport details. [4]
None of those charities had a cybersecurity failure of their own. They trusted a vendor with their donor list, and the vendor was hacked. Several — Amnesty International, Cancer Council, World Wildlife Fund, and Plan International among them — ended the relationship afterwards.
This is not a hypothetical. It is documented. And Pareto Phone is not the only vendor a not-for-profit has trusted with sensitive data.
- Not-for-profits get breached the same way everyone else does — phishing, ransomware, compromised accounts, and third-party vendors — but with the smallest security budgets of any sector in this series. Six named incidents from 2020 to 2025 span every one of those attack types.
- Supply chain risk is the defining feature of this sector. The Pareto Phone breach is the clearest example anywhere in the Australian breach record of an organisation doing nothing wrong and still wearing the full cost of a partner’s failure.
- The data held is often more sensitive than the organisation’s size would suggest. Court orders, “Working With Vulnerable People” checks, health and disability records, and children’s welfare data sit inside NFPs that may have a handful of IT staff, or none.
- The cost of doing nothing is documented, not theoretical. A hospital network reverting to paper for weeks. Eighty thousand donors notified. A vendor’s failure ending long-standing charity partnerships.
Six named incidents in the Australian breach record since 2020, spanning a scouting organisation, a hospital and aged care network, a children’s charity, a fundraising vendor, a health charity, and an aged care and disability provider.
| Year | Organisation | State | What happened |
|---|---|---|---|
| 2020 | Scouts Victoria [5] | Vic | Staff email accounts compromised via phishing; approximately 900 people’s data accessed, including court orders, criminal history information, and identity documents |
| 2021 | UnitingCare Queensland [6] | Qld | REvil/Sodinokibi ransomware; email and booking systems encrypted, Brisbane hospitals and aged care facilities reverted to manual, paper-based processes for close to two months |
| 2022 | The Smith Family [7] | National | Staff email account compromised in an attempted funds-theft scam; personal and partial payment data of up to 80,000 donors and sponsors potentially accessed |
| 2023 | Pareto Phone [4] | Qld / National | LockBit ransomware attack on a third-party fundraising vendor; 150GB stolen, cascading to up to 70 partner charities including ACF, Amnesty International, and Cancer Council |
| 2024 | Diabetes WA [8] | WA | Compromised user account; telehealth client data including Medicare numbers, diabetes type, and Indigenous status potentially exposed |
| 2025 | CBS Tasmania [9] | Tas | Lynx ransomware; aged care and disability provider’s staff data and a limited number of client records, including “Working With Vulnerable People” identification, published |
No single attack type dominates: phishing, ransomware, a compromised account, and a third-party vendor compromise are all represented in six incidents. The pattern is not the method. It is that every one of these organisations exists to serve people who are, in some way, vulnerable — and the data reflects that.
This is where the sector’s biggest problem shows up before a single incident even happens: the data is thin, and the thinness is itself a finding.
The OAIC’s published sector rankings (Health, Finance, Australian Government, Education, and Legal/Accounting & Management Services) do not include a standalone “not-for-profit” category. [2] Coastal Cyber does not have a verified NFP-specific notification count from the OAIC dashboard, and none was found elsewhere — a not-for-profit’s breach is most likely recorded under whatever activity category it falls into instead (an aged care charity’s breach likely counts toward Health, for instance), which means the sector’s true breach volume is folded into other sectors’ totals and effectively invisible in the OAIC’s own published breakdowns.
The Webber Insurance register shows named NFP incidents in most years of the 2018–2026 window, but, as with the OAIC data, it does not tag incidents by sector in a way that produces a reliable count. Treat the six incidents above as a representative sample, not an exhaustive list.
The practical read: the not-for-profit sector is not a small target that happens to be under-reported. It is a sector whose reporting is structurally scattered across other sectors’ statistics, which makes it easy for a board or an executive team to conclude, wrongly, that NFPs simply aren’t in the data.
A typical Australian not-for-profit — whether a charity, a community services provider, an aged care or disability organisation, or a membership body — holds a data inventory that is often more sensitive than its size or budget would suggest.
- Donor and supporter records: names, addresses, payment details, giving history
- Beneficiary and client welfare data: health conditions, disability status, family circumstances, case notes
- Safeguarding and vetting records: “Working With Vulnerable People” checks, police checks, court orders, custody arrangements
- Volunteer and staff records: background checks, superannuation, payroll
- Children’s data, where the organisation works with minors
- Physical records: paper case files and vetting documents, frequently retained without a documented destruction schedule
The Scouts Victoria incident is the clearest illustration: the exposed data included court orders and criminal history information, held because the organisation’s safeguarding obligations required it to hold that data, not because anyone chose to collect more than necessary. Sensitive data collection is often a compliance requirement for this sector, not a discretionary choice, which makes “just collect less data” an incomplete answer to the risk.
Every other edition in this series states a precise cause split — human error versus malicious attack — drawn from OAIC sector data. This edition can’t do that honestly, because the OAIC doesn’t publish NFP as a distinct sector. [2] Stating a specific percentage here would mean either borrowing a number from a different sector and mislabelling it, or inventing one. Neither is acceptable, so this section states plainly what the named incidents show instead of what a dashboard says.
Of the six incidents above: one traces to phishing (Scouts Victoria), one to ransomware exploiting a technical vulnerability (UnitingCare Queensland), one to an internal account compromise (The Smith Family), one to a compromised account (Diabetes WA), one to ransomware (CBS Tasmania), and one to a third-party vendor’s failure entirely outside the charity’s own control (Pareto Phone). That is a roughly even split across human-targeted attack, technical compromise, and supply chain failure, not a sector with one dominant cause to fix.
The investment implication is different from a sector with a single dominant cause. A school fixing a 74% human-error problem knows where to start. A not-for-profit facing phishing, ransomware, and vendor risk in roughly equal measure needs a baseline across all three: staff awareness, technical resilience (backups, MFA, patching), and a documented process for vetting any vendor that touches donor or client data. There is no single fix here, which is precisely why this sector is easy to under-invest in — there’s no one number to react to.
For a not-for-profit without a dedicated IT security function, the starting point is not a compliance framework. It is these six things.
-
1Vet any vendor that touches donor, client, or beneficiary data before you sign, and again periodically afterPareto Phone’s charity partners had no visibility into the vendor’s security posture until after the breach. A short vendor security questionnaire costs an afternoon.
-
2Implement MFA on email and any system holding client or donor recordsThree of the six incidents in this edition trace back to a compromised account. MFA is the cheapest control against the most common cause.
-
3Verify your backups and test a restore, specifically for the systems that hold case notes or client welfare dataUnitingCare Queensland’s two-month reversion to paper is the outcome a tested backup exists to prevent.
-
4Build a one-page incident response plan that names who calls whomThe regulator, affected clients or donors, the board, and any funding body with its own reporting requirements. Decide this before an incident, not during one.
-
5Review retention and destruction schedules for safeguarding and vetting recordsCourt orders, background checks, and welfare notes should not be retained indefinitely by default; the Privacy Act applies to these records the same as any other personal information.
-
6Commission a professional cyber health assessmentAn independent assessment gives a board or executive team an evidenced picture of risk, in a sector where “we’re too small to be a target” is contradicted by the record above. Coastal Cyber’s Cyber Health Check is designed specifically for not-for-profits and other resource-constrained organisations.
None of these require a security budget most NFPs don’t have. They require deciding, before the next Pareto Phone, which vendors and systems actually hold the data that would hurt the most if it got out.
The organisations in this edition did not, for the most part, make an obvious mistake. Scouts Victoria was phished, the way thousands of organisations are phished every year. UnitingCare Queensland was hit by ransomware that also hit hospitals with far larger security budgets. Pareto Phone’s charity partners trusted a vendor, which is how fundraising has worked for decades.
The question worth sitting with is not whether your organisation could avoid every possible attack — it can’t, and neither could any of the organisations above. It is whether your organisation could show, afterwards, that it had taken reasonable steps: vetted its vendors, tested its backups, trained its staff, and had a plan. That evidence either exists before the incident or it doesn’t exist at all.
The cost of building that evidence is small against the cost of losing donor trust, client trust, or a funding relationship over an incident you couldn’t have entirely prevented but could have been ready for.
That’s because it is. Managing data risk in a not-for-profit isn’t one job — it’s several, spread across a board, a small executive team, IT (where it exists at all), and whoever manages your vendor relationships, in an organisation that runs on donor and community trust. Doing it without a trusted partner is where most not-for-profits stall.
If you’re wondering which thread to pull first, that is exactly the conversation worth having with a GRC professional before you spend a quarter going in circles. A few hours of advice early saves weeks of internal debate and considerable heartache later.
Book a 20-minute conversation
If your organisation’s cyber and privacy posture needs a clear-eyed assessment, start here. No sales process. No commitment. Just clarity on which thread to pull first.