Description

JewishCare NSW, a healthcare provider for the Australian Jewish community, has reported a significant data breach, which was discovered on October 28, 2024. The breach involved a cyber attack that resulted in the exfiltration of sensitive data, some of which has been posted on the dark web. Affected individuals include clients, staff, volunteers, donors, and suppliers, with the scope of the breach varying depending on the individual’s relationship with the organization. Compromised client data includes personal identification details, financial information, health records, legal documents, and service-related data. Donor data exposed includes contact information, donation histories, and potentially sensitive health-related details. Staff and volunteer data affected includes personal contact details, payroll and employment information, background checks, and identification documents. Supplier data exposed includes contact information and financial details such as bank account data. The breach’s full impact is still being assessed, with JewishCare working to identify which individuals are at higher risk. While the exact data exfiltrated per person varies, personal, financial, and medical data were among those compromised. JewishCare has notified individuals whose data has been confirmed as compromised and is continuing to work with cybersecurity experts to investigate the breach further. The organization is also coordinating with Australian authorities, including the Australian Cyber Security Centre (ACSC), Australian Federal Police (AFP), and the Office of the Australian Information Commissioner (OAIC). JewishCare has reassured stakeholders that they are taking all necessary steps to mitigate the impact of this breach and are committed to restoring systems and protecting the data of affected individuals.