NRA A.I CyberSecurity Scoring
NRA
Company Information
Website:https://www.nsw.gov.au/reconstruction-authority
Employees number:406
Number of followers:13,515
NAICS:92
Industry Type:Government Administration
Homepage:nsw.gov.au
NRA Risk Score (AI oriented)
Between 550 and 599
NRAGovernment Administration
Updated:
04/04/2026
04/04/2026
575/1000
Very Poor
Ca
NRA Global Score (TPRM)
xxxx
NRAGovernment Administration
Score locked

NRAVery Poor
Current Score
575Ca (VERY POOR)
01000
3 incidents
-84 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
584
MAY 2026
580
APRIL 2026
576
MARCH 2026
575
FEBRUARY 2026
571
JANUARY 2026
568
DECEMBER 2025
564
NOVEMBER 2025
560
OCTOBER 2025
639
Breach
15 Oct 2025 • NRA
New South Wales Reconstruction Authority (RA)
Data breach exposes personal details of over 2,000 linked to NSW Resilient Homes Program
555
HIGH-84
NSW5232652101525
The New South Wales Reconstruction Authority (RA) experienced a data breach involving the Northern Rivers Resilient Homes Program (RHP), where a former temporary employee improperly uploaded sensitive personal information of 2,031 individuals to an unauthorized AI tool. The exposed data included personally identifiable details linked to participants of the RHP, a program designed to assist flood-affected residents in rebuilding resilient homes. The breach was caused by internal human error, specifically the mishandling of data by an employee with temporary access. While the exact nature of the compromised data (e.g., financial records, addresses, or identification numbers) was not fully disclosed, the incident highlights vulnerabilities in employee data governance and third-party tool misuse. The RA confirmed the breach but did not specify whether the exposed data was further exploited or accessed by malicious actors. The incident underscores risks associated with insider threats and the need for stricter controls on data sharing, particularly with external platforms.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
638
AUGUST 2025
635
JULY 2025
633
MARCH 2025
710
Breach
12 Mar 2025 • NRA
Northern Rivers Resilient Homes Program (under NSW Reconstruction Authority)
AI-linked data breach in Northern Rivers Resilient Homes Program, New South Wales
621
CRITICAL-89
NSW2432924100625
A major data breach occurred in the Northern Rivers Resilient Homes Program, managed by the NSW Reconstruction Authority (RA), after a former contractor improperly uploaded sensitive data to ChatGPT between 12–15 March 2025. The exposed file contained over 12,000 records, including personal details (names, addresses, contact info) and health data, potentially affecting up to 3,000 individuals. While no evidence suggests third-party access, the breach triggered a forensic investigation by Cyber Security NSW and an independent review to assess delays in notification (spanning months). The RA has strengthened AI usage policies and is offering free identity support (ID Support NSW) and compensation for document replacement costs. The incident highlights risks of unauthorized AI platform use in handling sensitive government program data, with long-term reputational and operational consequences for the authority.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2022
762
Breach
16 Jun 2022 • NRA
NSW Reconstruction Authority (RA)
NSW Reconstruction Authority Data Breach Exposes Personal Information of 3,000 Flood-Affected Residents
668
CRITICAL-94
NSW0902109100625
A major data breach at the NSW Reconstruction Authority (RA) exposed the private information of up to 3,000 northern NSW residents affected by the 2022 floods. The breach occurred in March 2024 when a former contractor uploaded a spreadsheet containing over 12,000 rows of data from the Northern Rivers Resilient Homes Program to ChatGPT. The leaked data included names, addresses, email addresses, phone numbers, and sensitive personal and health information of program applicants—individuals seeking home buybacks or flood-resilience upgrades.While there is no confirmed public exposure of the data, the RA acknowledged the risk could not be ruled out. The authority delayed notifications due to the complexity of identifying all affected individuals and verifying the scope of the breach. Investigations involved Cyber Security NSW and forensic analysts, with the NSW Minister for Recovery expressing regret over the incident. The RA began contacting impacted residents in the week following the disclosure, offering support but facing criticism for the delayed response and potential reputational harm to the affected community.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for NRA ??
What was NRA's A.I Rankiteo Cyber Score in May 2026 ??
What was NRA's A.I Rankiteo Cyber Score in April 2026 ??
What was NRA's A.I Rankiteo Cyber Score in March 2026 ??
What was NRA's A.I Rankiteo Cyber Score in February 2026 ??
What was NRA's A.I Rankiteo Cyber Score in January 2026 ??
What was NRA's A.I Rankiteo Cyber Score in December 2025 ??
What was NRA's A.I Rankiteo Cyber Score in November 2025 ??
What was NRA's A.I Rankiteo Cyber Score in October 2025 ??
What was NRA's A.I Rankiteo Cyber Score in September 2025 ??
What was NRA's A.I Rankiteo Cyber Score in August 2025 ??
What was NRA's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on NRA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with NRA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view NRA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?