Contact Group Hit by Dark Web Data Auction Following Alleged Cyberattack
Tasmania-based technology provider Contact Group, a major multi-sector supplier serving commercial, government, healthcare, and education clients, has been listed on the dark web leak site of the CMD Organization hacking group. The threat actor claims to have stolen sensitive data and is auctioning it, with the highest bid currently at 10 bitcoin (approximately $600,000 USD at current rates).
A sample of the allegedly exfiltrated data, posted by CMD Organization, includes scans of driver’s licenses containing personal details such as names, addresses, signatures, license classes, and document numbers. The auction is set to close in just over six days, though the group has not disclosed further details about the attack or the full scope of the compromised data.
Contact Group, which operates in Hobart, Launceston, and Burnie, has declined to comment on the incident.
Who is CMD Organization?
Emerging in May 2024, CMD Organization is a relatively new cybercriminal group that has rapidly expanded its victim count to 42 listed targets. The group markets itself as a "legitimate" security service, claiming to specialize in identifying corporate vulnerabilities while operating under the guise of improving cybersecurity.
However, cybersecurity firm Beazley Security notes that CMD Organization’s operations began in March 2024 and suggest the group may rely on initial access brokers (IABs) rather than developing its own sophisticated tools. One of its distinctive tactics is public bidding on stolen data, which could drive up ransom demands by creating competition among threat actors. By selling exclusive access to a single buyer, the group may enable attackers to exploit the data before it becomes widely circulated.
This incident highlights the growing trend of auction-based extortion, where cybercriminals monetize breaches through open markets rather than traditional ransom negotiations.
Contact Group (TAS) cybersecurity rating report: https://www.rankiteo.com/company/contactgrouptas
"id": "CON1785464632",
"linkid": "contactgrouptas",
"type": "Breach",
"date": "5/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['Commercial',
'Government',
'Healthcare',
'Education'],
'location': ['Hobart', 'Launceston', 'Burnie'],
'name': 'Contact Group',
'type': 'Technology Provider'}],
'data_breach': {'data_exfiltration': True,
'file_types_exposed': ['Scans of driver’s licenses'],
'personally_identifiable_information': 'Names, addresses, '
'signatures, license '
'classes, document '
'numbers',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personally Identifiable '
'Information (PII)'},
'description': 'Tasmania-based technology provider Contact Group has been '
'listed on the dark web leak site of the CMD Organization '
'hacking group. The threat actor claims to have stolen '
'sensitive data and is auctioning it, with the highest bid '
'currently at 10 bitcoin (approximately $600,000 USD). A '
'sample of the allegedly exfiltrated data includes scans of '
'driver’s licenses containing personal details such as names, '
'addresses, signatures, license classes, and document numbers.',
'impact': {'data_compromised': 'Scans of driver’s licenses (names, addresses, '
'signatures, license classes, document '
'numbers)',
'identity_theft_risk': 'High'},
'initial_access_broker': {'data_sold_on_dark_web': True},
'motivation': 'Financial gain',
'ransomware': {'data_exfiltration': True,
'ransom_demanded': '10 bitcoin (~$600,000 USD)'},
'references': [{'source': 'CMD Organization dark web leak site'},
{'source': 'Beazley Security'}],
'response': {'communication_strategy': 'Declined to comment'},
'threat_actor': 'CMD Organization',
'title': 'Contact Group Hit by Dark Web Data Auction Following Alleged '
'Cyberattack',
'type': 'Data Breach'}