惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
C
Check Point Blog
J
Java Code Geeks
腾讯CDC
Apple Machine Learning Research
Apple Machine Learning Research
宝玉的分享
宝玉的分享
Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
量子位
Google DeepMind News
Google DeepMind News
I
InfoQ
The GitHub Blog
The GitHub Blog
aimingoo的专栏
aimingoo的专栏
N
Netflix TechBlog - Medium
Hugging Face - Blog
Hugging Face - Blog
博客园 - Franky
V
V2EX
Blog — PlanetScale
Blog — PlanetScale
T
The Blog of Author Tim Ferriss
小众软件
小众软件
博客园_首页
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
IT之家
IT之家

Cyber Daily News

Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Attackers increasingly turning to trusted security tools to compromise Aussie victims Exclusive: Champion Homes confirms customer data compromised in “cyber event” Australia, Japan commit to partnership to meet cyber security challenges & strengthen cyber defences NSW Treasury cyber incident contained, impact no longer ‘significant’ Report: AI-based data incidents on the rise in Australia WA rental scam surge: Tenants targeted with fake $500 discount trap Aussie Information Commissioner launches Privacy Awareness Week 2026 Unregistered branded text messages to be labelled ‘Unverified’ from 1 July US Federal Reserve outlines AI's influence on the finance sector Exclusive: Major Australian jewellery brand confirms cyber incident Australian government establishes new Cyber Incident Review Board Watch this! Komari server monitor tool abused by hackers Act Now! ACSC warns of active exploitation of cPanel & WHM critical vulnerability Exclusive: Kiwi electrical contractor confirms cyber attack Over 1 in 2 firms have AI privacy concerns: Intuit Exclusive: Prime Properties listed as breach victim by M3rx ransomware Anthropic launches dedicated Claude Security platform to public beta DigiCert launches AI Trust architecture to secure agents, models, and content ‘Rebuilding the enterprise’: How CEOs are preparing for automation Op-Ed: Redefining performance in the AI-powered SOC Ukrainian official advocates for artificial intelligence, autonomous drones for battlefield deployment NZ council cyber attack leads to ID and financial data being exposed ‘Building confidence’: The key to effective AI implementation Vect unveiled: Inside an emerging ransomware group’s affiliate network Exclusive: Gelatissimo confirms unauthorised access, investigates DragonForce hack claims US Department of War launches cyber-focused apprenticeship program CrowdStrike launches Project QuiltWorks to tackle skyrocketing AI-discovered vulnerabilities Australian government stands up new ‘tripartite forum’ to tackle AI challenges in the workforce
Exclusive: 2019 claims alleged cyber incident on Melbourn...
Daniel Croft · 2026-06-19 · via Cyber Daily News

An infamous threat actor has claimed a cyber attack on an Australian weight-loss clinic, claiming to have stolen the data of tens of thousands of patients.

Exclusive: 2019 claims alleged cyber incident on Melbourne weight loss clinic

Based in Victoria, Elina Medical Weight Loss Clinic is a leading weight-loss centre that has worked with over 1,000 patients with weight-loss programs. The clinic forms part of Waverly GP in Glen Waverly, Victoria.

Notorious threat actor 2019 listed the clinic on an infamous hacking forum, claiming to have stolen the data of over 28,000 patients across over 300,000 records.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

According to the listing, allegedly stolen data includes names, addresses, dates of birth, email addresses, gender, home and mobile numbers, Medicare card details, postcodes, appointment records, including doctors, booking times, reminder status and payment status fields.

In the past, 2019 has both sold data and released it for free, with the latest listing being a one-time sale in exchange for cryptocurrency.

Sample data was also included in the 2019 listing; however, the legitimacy of the data has not been verified.

Responding to Cyber Daily’s request for comment, Elina Medical Weight Loss Clinic said it could confirm an unauthorised user gained access but the incident had been contained and an investigation is underway.

While the investigation is still in its early stages, we can confirm two Elina HotDoc user accounts were logged into by an unknown third party. The incident was quickly contained, with activity limited to these Elina accounts,” the clinic said.

The unknown third party no longer has access and Elina’s broader IT environment remains secure and unaffected.

Our clinic is operating as normal with zero disruption to patient care. Elina is working to verify what specific information within HotDoc has been accessed, so it can inform potentially impacted patients.”

The clinic also addressed the online claims and said that while they may prove concerning for customers, it is making security and its investigation its top priority.

We recommend that our patients remain vigilant against the risk of potential phishing emails or scam calls, which are often the most likely risk associated with unauthorised access to contact information,” the statement said.

We take cyber security seriously and are committed to keeping all our patients updated as we work to respond to this incident.

We are also liaising with the relevant authorities in response to this incident alongside various experts across the cyber security industry.

We would like to assure our patients that we are taking all appropriate steps to remediate this situation as swiftly as possible and have also implemented sophisticated monitoring systems to ensure we are aware of any further developments.

We understand this news may cause concern to our patients and would like to thank them for their ongoing support as we work to resolve this as swiftly as possible.”

Elina Medical Weight Loss Clinic then provided advice for consumers on how to protect themselves from any potential fallout, which includes not sharing personal information unless the recipient is confirmed and trustworthy, remaining vigilant against suspicious activity, keeping passwords up to date and using a password manager, using multi-factor authentication, not responding to suspicious links and phone calls and monitoring bank accounts.

Who is 2019?

Threat actor 2019 has been active on underground hacking forums since early 2026 and has made more than 30 leak posts in that time, with the majority referencing Australian victims such as the Australian Centre for the Moving Image and Services Australia.

While Australian organisations appear to be 2019’s preferred target, they have also listed entities from the United States, the United Arab Emirates, France, and Italy.

Generally, 2019 offers stolen data for free, but in some cases, it is sold online in a one-time sale in return for bitcoin, Ethereum or Monero cryptocurrencies.

Most recently, 2019 reached out to media and other individuals using what appeared to be the noreply email for the Australian Privacy Commission.

The emails, two of which were received by the Cyber Daily team, contained abnormal content with the email sent to this writer having the subject line “:(“ and simply reading “cybercriminals are not terrorists”, as well as a table that featured the words “f--- you”.

2019 was attributed to the incident as the emails also contained a link to what appears to be their user page on a threat forum.

A day later, on 10 June, the Productivity Commission (PC) confirmed the incident, stating it was aware of the issue and had launched an investigation into the matter.

“On 9 June 2026, some members of the public received unsolicited emails from a Productivity Commission email address. Some of these emails contained identifying information that the sender implied had been taken from PC records,” the Productivity Commission said.

“As a result of our initial investigation into this issue, we have determined that an external third party is the source of these emails. During our review, we found no evidence that any of the identifying information used in the emails has come from the PC. The PC website does not store personal data in a way that would expose user emails, and many of the affected individuals have had no prior engagement with the PC.”

The Productivity Commission added that a vulnerability was identified and had now been patched.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

Daniel Croft

Born in the heart of Western Sydney, Daniel Croft is a passionate journalist with an understanding for and experience writing in the technology space. Having studied at Macquarie University, he joined Momentum Media in 2022, writing across a number of publications including Australian Aviation, Cyber Security Connect and Defence Connect. Outside of writing, Daniel has a keen interest in music, and spends his time playing in bands around Sydney.