In February 2021, **Transport for NSW**, an Australian government agency responsible for managing the state’s transport systems, fell victim to a **Clop ransomware attack**. The breach was part of a broader global campaign exploiting vulnerabilities in **Accellion’s File Transfer Appliance (FTA)**, a third-party file-sharing service used by the agency. While the full extent of the data compromise was not publicly disclosed, the attack exposed sensitive internal documents, including employee records, financial data, and potentially customer-related information. The Clop ransomware group, known for double-extortion tactics, threatened to leak stolen data unless a ransom was paid. Although Transport for NSW refused to negotiate, the incident disrupted operations, raised concerns over data security, and prompted an urgent review of cybersecurity protocols. The breach highlighted vulnerabilities in third-party vendor systems and underscored the growing threat of ransomware targeting critical public infrastructure. Authorities warned that the stolen data could be used for further phishing attacks or sold on the dark web, posing long-term risks to both the organization and affected individuals.
TPRM report: https://www.rankiteo.com/company/transport-for-nsw
"id": "tra303092125",
"linkid": "transport-for-nsw",
"type": "Ransomware",
"date": "2/2021",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'transportation',
'location': 'New South Wales, Australia',
'name': 'Transport for NSW',
'type': 'government agency'}],
'data_breach': {'data_encryption': True, 'data_exfiltration': True},
'date_detected': '2021-02',
'description': 'In February 2021, Transport for NSW, an Australian government '
'agency responsible for transport infrastructure, was breached '
'by the Clop ransomware group.',
'impact': {'data_compromised': True},
'motivation': ['financial gain', 'data exfiltration'],
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransomware_strain': 'Clop'},
'threat_actor': 'Clop ransomware group',
'title': 'Transport for NSW Clop Ransomware Breach (2021)',
'type': ['ransomware', 'data breach']}