Thorndale Foundation Investigates Data Breach After Qilin Ransomware Listing
The Thorndale Foundation, a disability support organization serving the Nepean and Hawkesbury regions of New South Wales, is probing a data breach after being listed by the Qilin ransomware group on September 15. The foundation confirmed the incident to Cyber Daily, stating it had reported the matter to the Australian Cyber Security Centre (ACSC) and other authorities but declined further comment while investigations remain ongoing.
Qilin, currently the most active ransomware operation in 2026 with an average of 100 victim listings per month, shared six documents as proof of the breach. These included passport scans, a signed confidentiality agreement, an invoice, and a list of names linked to the foundation. However, the group has not disclosed the size of the compromised dataset or a timeline for potential full publication.
Operating under a ransomware-as-a-service (RaaS) model, Qilin provides affiliates access to its infrastructure in exchange for a share of ransom payments. The group has claimed 2,306 victims since its emergence in 2022, with recent activity including a Cisco Secure Firewall Management Center vulnerability and a breach of Sydney-based app developer DigiGround last month.
The Thorndale Foundation, based in Werrington, supports over 200 participants through group homes, employment assistance, disability day programs, and NDIS social activities, serving as a key provider in Western Sydney. The breach’s full impact on the organization and its clients remains under assessment.
Thorndale Foundation cybersecurity rating report: https://www.rankiteo.com/company/thorndale-foundation
"id": "THO1789972050",
"linkid": "thorndale-foundation",
"type": "Ransomware",
"date": "9/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Over 200 participants',
'industry': 'Disability support services',
'location': 'Werrington, New South Wales, Australia',
'name': 'Thorndale Foundation',
'type': 'Non-profit organization'}],
'data_breach': {'data_exfiltration': 'Yes (documents shared by Qilin as '
'proof)',
'file_types_exposed': ['PDF (passport scans)',
'Signed documents',
'Invoice',
'List of names'],
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (passport scans, signed '
'agreements, personal names)',
'type_of_data_compromised': ['Personally identifiable '
'information',
'Confidential documents']},
'date_detected': '2026-09-15',
'date_publicly_disclosed': '2026-09-15',
'description': 'The Thorndale Foundation, a disability support organization '
'serving the Nepean and Hawkesbury regions of New South Wales, '
'is investigating a data breach after being listed by the '
'Qilin ransomware group on September 15. The foundation '
'confirmed the incident and reported it to the Australian '
'Cyber Security Centre (ACSC) and other authorities but '
'declined further comment while investigations remain ongoing.',
'impact': {'data_compromised': 'Passport scans, signed confidentiality '
'agreement, invoice, list of names',
'identity_theft_risk': 'High (personally identifiable information '
'exposed)'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain (ransomware-as-a-service model)',
'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Qilin'},
'references': [{'source': 'Cyber Daily'}],
'regulatory_compliance': {'regulatory_notifications': 'Reported to ACSC and '
'other authorities'},
'response': {'communication_strategy': 'Declined further comment while '
'investigations remain ongoing',
'law_enforcement_notified': 'Yes (Australian Cyber Security '
'Centre, other authorities)'},
'threat_actor': 'Qilin ransomware group',
'title': 'Thorndale Foundation Data Breach Investigation After Qilin '
'Ransomware Listing',
'type': 'Data Breach, Ransomware'}