Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Services Australia

Services Australia Vendor Cyber Rating & Cyber Score

servicesaustralia.gov.au

We deliver Medicare, Centrelink and Child Support payments and services.


Services Australia A.I CyberSecurity Scoring

Services Australia
Company Information
Website:http://www.servicesaustralia.gov.au
Employees number:7,772
Number of followers:111,881
NAICS:92
Industry Type:Government Administration
Homepage:servicesaustralia.gov.au
Services Australia Risk Score (AI oriented)
Between 650 and 699
logo
Services AustraliaGovernment Administration
Updated:
05/06/2026
650/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Services Australia Global Score (TPRM)
xxxx
logo
Services AustraliaGovernment Administration
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Services Australia
Services AustraliaWeak
Current Score
650B (WEAK)
01000
2 incidents
-70.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
650Before Incident
MAY 2026
649Before Incident
APRIL 2026
647Before Incident
MARCH 2026
643Before Incident
FEBRUARY 2026
642Before Incident
JANUARY 2026
711Before Incident
Breach
01 Jan 2026Services Australia
Centrelink: Exclusive: Centrelink denies hacker claims of cyber attack

Centrelink Data Allegedly Leaked on Cybercrime Forum

638After Incident
CRITICAL-73
SER1780648898
Centrelink Data Allegedly Leaked on Cybercrime Forum A threat actor known as 2019 listed sensitive Centrelink data for sale on a cybercrime forum, as uncovered by threat researcher Dark Web Informer. The leaked records appear to originate from Centrelink’s Advice of Death form, which is used to report deaths and adjust payments for surviving family members. The compromised data includes highly personal details of over 2,100 deceased individuals, such as: - Full names, dates of birth and death - Medicare and Centrelink reference numbers - Home and hospital addresses - Next-of-kin details (names, phone numbers, addresses) - Aboriginal/Torres Strait Islander status - Funeral director and estate executor information - Signatures and declaration dates of notifiers Instead of demanding a ransom, the threat actor is offering the data for a one-time sale, accepting cryptocurrencies (Bitcoin, Ethereum, or Monero). Services Australia, the agency overseeing Centrelink, denied any breach of its systems, stating: “Our platforms and systems remain secure and have not been compromised.” The agency acknowledged monitoring dark web activity and suggested the data may have been exposed through a third-party compromise. It is working with the Australian Cyber Security Centre and other authorities to assess risks and implement additional security measures for affected individuals.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Personal details of over 2,100 deceased individualsBrand Reputation Impact: Potential reputational damage to Services AustraliaIdentity Theft Risk: High risk for next-of-kin and affected individuals
DATA BREACH
Full namesDates of birth and deathMedicare and Centrelink reference numbersHome and hospital addressesNext-of-kin details (names, phone numbers, addresses)Aboriginal/Torres Strait Islander statusFuneral director and estate executor informationSignatures and declaration dates of notifiersNumber Of Records Exposed: 2,100Sensitivity Of Data: Highly sensitive personal and financial informationData Exfiltration: YesPersonally Identifiable Information: Yes
DECEMBER 2025
778Before Incident
Breach
10 Dec 2025Services Australia
Services Australia may get powers to rein in data breach exposure

Services Australia Third-Party Data Breach Notification Powers

710After Incident
CRITICAL-68
SER1765340155
Services Australia Seeks New Powers to Compel Third-Party Breach Disclosures Amid Rising Cyber Threats Services Australia, which manages data for 27.5 million Australians, is pushing for expanded authority to require third parties to disclose breaches involving government identifiers, such as Medicare and Centrelink numbers. The move follows a dramatic surge in notifiable data breaches—from seven in 2022–23 to 82 in 2024–25—primarily driven by phishing attacks where individuals unknowingly shared credentials with impersonators. While the agency established response plans after the 2022 Optus and Medibank breaches, it currently lacks legal power to compel third parties to report incidents involving its identifiers. A federal audit recommended legislative reforms to mandate timely notifications, with support from the Attorney-General’s Department and the Office of the Australian Information Commissioner (OAIC). The audit also revealed systemic delays in breach reporting: 71% of the 165 notifiable data breaches (NDBs) reported to the OAIC between 2018–19 and 2024–25 were disclosed 50 or more days after detection. Internal reviews dating back to 2023 found Services Australia frequently missed the 30-day statutory assessment deadline, though the agency claims to have addressed these gaps by October 2023. In June 2025, Services Australia introduced a new "data breach mailout service" to directly notify affected individuals via mail or digital channels, though its effectiveness remains under evaluation. The proposed reforms aim to close gaps in breach transparency, particularly where third-party custodians hold sensitive government-linked data.
INCIDENT DETAILS -
TYPE
Data BreachCredential Theft
IMPACT
Personal informationmyGov sign-in credentialsMedicare numbersCentrelink reference numbersIdentity Theft Risk: High
DATA BREACH
Personal informationGovernment identifiersCredentialsSensitivity Of Data: HighPersonally Identifiable Information: Yes
NOVEMBER 2025
778Before Incident
OCTOBER 2025
778Before Incident
SEPTEMBER 2025
778Before Incident
AUGUST 2025
778Before Incident
JULY 2025
778Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Services Australia ?
?
What was Services Australia's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Services Australia's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Services Australia's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Services Australia ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Services Australia's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?