We regret to share that ACRF has experienced a cyber incident that may have affected the security of some stakeholder’s personal information held by us.
We take this matter very seriously and are publishing this notice to share what has happened, what we are doing about it, and what steps you can take to protect yourself. We encourage you to read this information carefully to understand what it may mean for you and how ACRF is supporting you.
We sincerely apologise for any upset this notice may cause you or your loved ones.
ACRF received a fraudulent email from one of our vendors that had itself also been the victim of unauthorised activity. This allowed an unauthorised third party to gain temporary access to our network, including access to the email inboxes of a few of our employees. This issue has since been rectified.
Our investigation has been unable to confirm the extent of the data in the compromised mailboxes that was actually accessed by the unauthorised third party. However, given the possibility that personal information in those mailboxes may have been accessed in an unauthorised manner, we wish to inform our stakeholders of this potential risk.
The types of personal information that may have been impacted (if any) depend on your relationship with ACRF.
We say may have been impacted because we aren’t able to conclude with certainty which data in these inboxes was actually accessed by the unauthorised third party. Nevertheless, it is important to take precautionary measures to protect yourself. We have outlined these steps in the response to Question 4.
Our Donors:
Our Members / Trustees:
Our Staff (past and present):
Individuals involved in court proceedings where ACRF was a beneficiary:
We also identified a further cohort of individuals, who were a party to, or participated in, a court matter related to the estate of a donor to ACRF. As ACRF was listed as a beneficiary in this matter, we received copies of affidavits and court documents related to the proceedings and may have corresponded about our involvement in the proceedings. These materials include:
If you have been identified as being at sufficient risk as a result of the incident and we have your (recent) contact information, ACRF will notify you directly. If you have received a notification directly from us, please refer to that notification which contains information specific to you as to what personal information may have been impacted.
We have been unable to directly notify some individuals as we do not have their recent contact details. If you have not received a notice, but are concerned you may be impacted, please let us know.
Please always check the sender of any communications purporting to be from ACRF. We will never demand money from you. If you receive any communications or other activity purporting to be from ACRF which causes you concern, please let us know immediately by contacting us at info@acrf.com.au or 1300 884 988.
Immediate steps to take
We encourage you to always remain vigilant to scams by taking the following steps:
Additional precautionary measures
We also encourage you to consider the following additional precautionary measures:
Please note that if you receive a notification from ACRF, your notification will include additional information about what to do in relation to the specific types of personal information that may have been impacted.
Our investigations to date do not indicate that any information has been published on the dark or deep web as a result of this incident.
Following detection of unusual activities, we engaged cyber incident response experts to help us respond to this incident. We also reported the incident to the Office of the Australian Information Commissioner (OAIC), the New South Wales Police and the Australian Cyber Security Centre (ACSC).
ACRF has also:
We needed to investigate the issue and understand what happened and who it impacted. That takes time. It was also important for us to be as clear as possible with our donors, members, staff and other stakeholders about how they may have been impacted so that they could take meaningful action to protect themselves.
We apologise for any upset this may cause you or your loved ones.
If you have any questions or would like to speak to an ACRF representative about this matter, please get in touch with us via email at info@acrf.com.au or call us directly at 1300 884 988.
For media enquiries contact info@acrf.com.au