![]()
Welcome to this month’s edition of Cyber Insights, covering a fake investment platform scam doing the rounds, plus a look at several recent Australian data breaches and why that browser extension you installed years ago might not be as harmless as it seems. Everything you need to stay a step ahead.
![]()
In this scam, you come across a polished-looking advertisement or social media post promoting an exciting opportunity to invest in shares, cryptocurrency or foreign exchange trading. The website or app looks professional and legitimate, and sometimes even copies the branding of a well-known financial company. After you make contact, whether through the ad itself, a social media message or a direct message, you’re encouraged to set up an account and make a small initial payment to get started.
Once you’re in, the platform shows you a dashboard with growing “returns” on your investment. It looks real, so you’re encouraged to invest more money to take advantage of your apparent success. This is the trap. When you try to withdraw your money, you run into problems, excuses, delays, or a demand that you pay extra “fees” before your funds can be released. In many cases, the platform simply disappears, taking your money with it.
These scams are dangerous because they often run for weeks or months, slowly building your trust before asking for larger amounts. By the time you realise something is wrong, you may have handed over thousands of dollars, money that is almost never recoverable once it reaches a scammer. Investment scams were the most costly type of scam reported to Scamwatch in early 2026, with Australians losing $45.5 million in just three months. Around half of that came through fake websites, ads, social media and apps like these, and the National Anti-Scam Centre took down 5,834 scam websites in that same period.
Follow these tips to avoid falling victim to this scam:
- Be cautious of any investment opportunity that comes through a social media ad, unsolicited message or online post, especially if it promises high, guaranteed returns.
- Before investing any money, check whether the company holds an Australian Financial Services Licence by searching the ASIC website.
- If a platform asks you to pay extra “fees” to withdraw your own money, stop immediately and send no further money. This is a clear sign of a scam.
![]()
Origin Energy
Origin Energy has revealed that an attacker gained access to a shared customer database called Kraken. This system is used by around a third of Australian energy retailers, and Origin holds a stake in the company that runs it. An attacker first contacted the company on 2 July 2026 claiming to have broken in, but Origin initially judged the report not credible. New information on 22 July confirmed a genuine breach had occurred, and Origin told the Australian Securities Exchange (ASX) and its customers on 28 July. Origin believes the attacker may have used the login details of a former employee that had never been switched off. This gave roughly three weeks of undetected access before its security team stepped in, though the company says the exact method is still being investigated.
Around 900,000 current and former customers had personal information accessed, including names, addresses, dates of birth, phone numbers and account details. A small amount of partial financial information was also taken, such as the last four digits of a credit card or part of a bank account number. Origin says this information on its own cannot be used to commit fraud. A person claiming responsibility told a journalist that 2 million customer records had been stolen, a figure Origin has not confirmed. Origin has brought in outside security experts, reported the incident to the relevant authorities, and extended its customer support hours. It is contacting affected customers directly, and is urging them to watch for follow-up scam emails or calls. Read more here
GO2 Health
GO2 Health is a Brisbane medical clinic offering general practice and veteran care services. Its main email inbox was broken into around 24 April 2026, after a staff member was tricked by a fake email designed to look genuine. The clinic noticed the same day and told the Office of the Australian Information Commissioner (OAIC) on 18 May. It took until 16 July, almost three months after the breach, to work out exactly which patients were affected and tell them.
The information taken was limited to whatever had been sent to that one email inbox over the previous 12 months. This included some patients’ Department of Veterans’ Affairs ID numbers and other personal details shared by email. GO2 Health says its main patient record systems were not affected, and it has found no evidence the stolen information has been published or misused. The clinic has brought in outside cyber security experts and notified affected patients. It has also reported the incident to the Australian Cyber Security Centre and the OAIC, and is inviting affected patients to contact it directly with any questions. The exact number of patients affected has not been made public. Read more here
Key lessons for organisations
- Switch off user accounts the moment someone leaves your organisation. Origin’s breach shows how a single forgotten account can go unnoticed for weeks.
- Train staff to spot fake emails designed to trick them. Encourage a habit of double-checking requests before clicking links or replying with sensitive information, as seen in the GO2 Health breach.
- Keep a close eye on your domain and website settings. CubePilot’s attacker was able to redirect visitors to a fake site while browsers still showed a secure padlock, so familiar security signals are not always enough on their own.
![]()
Not All Browser Extensions Are Your Friend
You installed that handy little extension months, maybe years ago, to check your grammar, block ads, or save coupons at checkout. It has sat quietly in your browser toolbar ever since, and you’ve probably not thought about it since the day you added it. That’s exactly the problem.
Security researchers have found that extensions which behaved perfectly normally for years can suddenly turn harmful after a hidden update. This often happens because the developer sold it to someone else, or the developer’s own account was hacked. Once that happens, the extension can read everything you type and capture your passwords and login details. It can also quietly send your browsing activity to a cybercriminal, all without any obvious warning sign on your screen. Because extensions run inside your browser with broad permissions, they can be one of the easiest ways for an attacker to get into your accounts and your organisation’s systems.
Follow the tips below to keep your browser extensions from becoming a security risk:
- Open your browser’s extensions menu (in Chrome, Edge or Firefox this is usually under Settings, then Extensions) and review every extension installed. If you don’t recognise it or no longer use it, remove it.
- Only install extensions from official browser stores, and check the publisher name, review score and number of users before adding anything new.
- Avoid granting an extension permission to “read and change all your data on websites you visit” unless you genuinely need that level of access for the tool to work.
- Turn on automatic updates for your browser itself, and periodically recheck your extension list, since a trusted extension can turn harmful after an update you never noticed.
- If you use work accounts, such as email, HR systems or business banking, in the same browser as your personal browsing, consider keeping a separate browser profile. Use this extension-free profile just for sensitive logins.
- If you notice unexpected pop-ups, your homepage or search engine changing on its own, or unfamiliar login alerts, remove suspicious extensions immediately and change your passwords.
If you would like to discuss your cybersecurity needs, book a complimentary consultation here
Frequently Asked Questions
Scammers post polished ads or messages promoting shares, crypto or forex trading. Once you sign up and make a small payment, a dashboard shows fake returns to encourage you to invest more. When you try to withdraw, you hit delays, extra "fees" or the platform disappears altogether with your money.
Search the ASIC website to see whether the company holds an Australian Financial Services Licence. Be wary of unsolicited offers through social media or online ads, especially ones promising high, guaranteed returns. If you're ever asked to pay a fee to withdraw your own money, that's a clear sign of a scam.
An attacker is believed to have used login details belonging to a former employee that were never deactivated. This gave around three weeks of undetected access to a shared customer database before Origin's security team stepped in. Roughly 900,000 current and former customers had personal information accessed.
DNS hijacking is when an attacker takes control of the settings that direct visitors to a website. In CubePilot's case, this let the attacker redirect users to a fake version of its site using fraudulent security certificates, so browsers still showed the normal "secure" padlock. This made the attack hard for users to spot.
An extension that's safe today can turn harmful after a hidden update, often because it's been sold to a new owner or the developer's account was hacked. Once compromised, it can read what you type and send your browsing activity to an attacker. Regularly checking your extensions and removing ones you don't use or recognise reduces this risk.