CSV A.I CyberSecurity Scoring
CSV
Company Information
Website:https://www.courts.vic.gov.au/
Employees number:628
Number of followers:12,820
NAICS:92
Industry Type:Government Administration
Homepage:vic.gov.au
CSV Risk Score (AI oriented)
Between 0 and 549
CSVGovernment Administration
Updated:
30/07/2026
30/07/2026
500/1000
Critical
C
CSV Global Score (TPRM)
xxxx
CSVGovernment Administration
Score locked

CSVCritical
Current Score
500C (CRITICAL)
01000
3 incidents
-116.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
511
SEPTEMBER 2026
510
AUGUST 2026
504
JULY 2026
588
Breach
15 Jul 2026 • CSV
Magistrates’ Court of Victoria, Children’s Court of Victoria and Court Services Victoria: Exclusive: Court Services Victoria confirms Bendigo Law Courts data breach following hacker claims
Bendigo Law Courts Data Breach
498
CRITICAL-90
COU1785378287
Bendigo Law Courts Hit by Data Breach, Thousands of Court Records Exposed
Bendigo Law Courts is responding to a data security incident after hacker 2019 leaked sensitive court records on a popular underground forum. The breach, disclosed on July 15, exposed over 28,600 lines of data related to cases heard at the consolidated court facility, including locations such as Bendigo, Castlemaine, Echuca, Kerang, Kyneton, Maryborough, Mildura, Ouyen, Robinvale, and Swan Hill.
A sample of the stolen data was posted as proof, with the full dataset made freely available on an anonymous hosting service. Court Services Victoria (CSV) confirmed the breach, stating that unauthorized access targeted information used to link participants to online hearings at the Magistrates’ Court of Victoria and the Children’s Court of Victoria between 2022 and 2026.
While the compromised system is separate from the Case Management System (CMS), the exposed data includes publicly available details such as case titles, hearing dates, and participant names as well as non-public information, including email addresses and roles (e.g., lawyers, court staff, observers).
CSV has taken immediate action, shutting down the access point, strengthening security, and notifying relevant authorities. The investigation remains ongoing, with updates to be posted on CSV’s Frequently Asked Questions page.
The hacker, 2019, has a history of targeting Australian organizations, including the Melbourne International Film Festival, a Canberra healthcare clinic, and the Australian Centre for the Moving Image. In 2019, they also breached the Australian Productivity Commission’s email systems, using access to harass journalists. Their motives and identity remain unknown.
Bendigo Law Courts serves the Bendigo and Loddon-Mallee region, hosting state and federal courts alongside legal aid services like Loddon Campaspe Community Legal Centre and Koori Services.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
585
MAY 2026
582
APRIL 2026
579
MARCH 2026
717
Breach
16 Mar 2026 • CSV
VIQ Solutions, Queensland Courts, Victoria Courts, Federal Circuit and Family Court of Australia and Western Australia Courts: Attorney-General's Department contacted Australian Cyber Security Centre when notified of court privacy breach
Federal Court Data Breach Exposes Sensitive Litigant Files in Offshore Security Failure
574
CRITICAL-143
WESAUSDEPVIQCOU1779842049
Federal Court Data Breach Exposes Sensitive Litigant Files in Offshore Security Failure
A significant data breach involving Australian court records has exposed the personal and sensitive information of litigants in at least 146 cases, prompting a formal complaint to Canada’s privacy commissioner. The breach, linked to transcription service provider VIQ Solutions, has raised national security concerns after it was revealed that highly confidential court files were accessed offshore likely in India in violation of Commonwealth contractual obligations and privacy laws.
The incident came to light following an ABC investigation in February, which uncovered that VIQ had subcontracted work to e24 Technologies, a Chennai-based firm specializing in automated transcription, without notifying the courts. The breach was first publicly acknowledged by VIQ in a March 16 press release, after the company entered voluntary administration under McGrathNicol, just weeks after the offshore access was exposed.
### Scope and Impact of the Breach
- Affected Cases: At least 136 Family Court matters and 10 Federal Court cases were transcribed offshore without authorization. The total number of impacted cases across other jurisdictions including Queensland, New South Wales, Victoria, Western Australia, and the South Australian Employment Tribunal remains unclear.
- Unverified Claims: Federal Circuit and Family Court CEO David Pringle told Senate estimates that VIQ had provided inconsistent figures, initially citing 170 affected files before revising the number to 136. However, the courts have been unable to verify these claims, as VIQ has repeatedly failed to provide detailed reports despite multiple requests.
- Lack of Notification: None of the affected litigants have been informed of the breach, with Pringle stating that disclosure could cause "distress" a decision criticized by Greens Senator David Shoebridge, who called the handling of the incident an "unravelling scandal."
### Contractual Failures and Financial Irregularities
Despite the breach and VIQ’s administration, the Federal Court quietly extended its contract with the company by $5.3 million, with the amendment only appearing on the Australian Tenders website on June 24 nearly two years after the original contract expired. Federal Court representative Cara Lawson described the oversight as an "administrative error", admitting that the tender listing had incorrect details, including the wrong start date, supplier name, and contract amount.
Senator Shoebridge condemned the lack of transparency, particularly after the court awarded a separate $451,000 contract to Nous Group for transcription program management also listed just before the estimates hearing. He questioned the court’s competence in managing the crisis, stating that officials had failed to ask "the right questions" as the privatization of transcription services collapsed.
### Breakdown in Oversight and Response
- Communication Failures: Pringle revealed that VIQ’s Canadian parent company cut off its Australian arm without warning, leaving courts scrambling to maintain services. The company also threatened to withdraw support, forcing emergency contingency measures.
- Government Involvement: The Attorney-General’s Department confirmed it had notified the Australian Cyber Security Centre (ACSC) upon learning of the breach.
- Ongoing Issues: Legal practitioners had previously raised concerns about erroneous transcripts, missing dialogue, and delays problems that have persisted amid VIQ’s administration.
The breach underscores systemic vulnerabilities in the outsourcing of sensitive judicial services, with critics arguing that privatization has outpaced oversight. As the fallout continues, the full extent of the exposure and the long-term consequences for affected litigants remains unresolved.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
716
JANUARY 2026
716
DECEMBER 2025
715
NOVEMBER 2025
714
JANUARY 2024
763
Breach
01 Jan 2024 • CSV
Court Services Victoria: Healthcare AuthorityDeals & Corporate GovernanceDigital Health & TechnologyOtherPolicy & Compliance
Victorian Courts Second Data Breach in 2.5 Years
690
CRITICAL-73
COU1785400345
Victorian Courts Disclose Second Data Breach in 2.5 Years
Court Services Victoria (CSV) has reported a second data breach in just over two and a half years, exposing unauthorized access to sensitive information within the Magistrates' Court. The incident involved the compromise of email addresses and other undisclosed data, marking another security lapse for the judicial system.
This follows a previous breach in 2021, raising concerns about the resilience of the state’s court infrastructure against cyber threats. While details on the exact scope and method of the breach remain limited, the disclosure underscores ongoing vulnerabilities in public sector cybersecurity.
The breach was confirmed by CSV, though no specific timeline for the unauthorized access has been provided. The incident highlights the persistent risks faced by government institutions handling sensitive legal and personal data. Further investigations are expected to determine the full impact and prevent future occurrences.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CSV ??
What was CSV's A.I Rankiteo Cyber Score in September 2026 ??
What was CSV's A.I Rankiteo Cyber Score in August 2026 ??
What was CSV's A.I Rankiteo Cyber Score in July 2026 ??
What was CSV's A.I Rankiteo Cyber Score in June 2026 ??
What was CSV's A.I Rankiteo Cyber Score in May 2026 ??
What was CSV's A.I Rankiteo Cyber Score in April 2026 ??
What was CSV's A.I Rankiteo Cyber Score in March 2026 ??
What was CSV's A.I Rankiteo Cyber Score in February 2026 ??
What was CSV's A.I Rankiteo Cyber Score in January 2026 ??
What was CSV's A.I Rankiteo Cyber Score in December 2025 ??
What was CSV's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on CSV's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CSV ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CSV's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?