Cyber Crime Update

Two Major July 2026 Breaches: What Partnered Health and Accenture Tell Us About Sector-Wide Cyber Risk
Attackers are no longer skimming the surface. Two incidents in a single month show them reaching core systems — transaction records, source code, and the keys to the cloud.
Australia’s healthcare sector and the global professional-services industry have each been rocked by a significant cyber incident in the space of a few weeks: the Partnered Health medical-records breach and the Accenture source-code and cloud-credentials breach. The two events occurred in very different industries, yet they share a common and troubling theme — attackers are no longer content with defacing websites or skimming front-end systems. They are going after core systems: transaction data stores, development infrastructure, and the credentials that hold modern cloud estates together.
This post summarises only the evidenced facts from authoritative reporting, then sets out a practical cyber health check and penetration-testing plan that any organisation — in healthcare, financial services, or beyond — can act on now. At the end, we explain how Moroku can help you conduct some or all of it.
The Partnered Health Breach — Evidenced Facts
Malicious access occurred on 23 June 2026
Partnered Health became aware of the cyber attack on 23 June and began working with the Australian Cyber Security Centre and police.
Sensitive medical and personal data was stolen
Reporting from the ABC, SBS, and The Sydney Morning Herald confirms the stolen data included:
- Names, dates of birth, addresses, and contact details
- Medicare and private health insurance details
- Consultation notes, referral letters, pathology and diagnostic results
21 clinics affected nationally, including Sydney sites
The Sydney Morning Herald reports that 21 clinics were impacted, including Ultimo, Castle Hill, Sans Souci, and Dural.
Partnered Health obtained a Supreme Court injunction
The company secured an interim injunction in the NSW Supreme Court to prevent misuse or publication of the stolen data.
Does a Supreme Court Injunction Help Against an International Crime Syndicate?
The injunction is the most legally interesting element of the Partnered Health response, and it deserves an honest appraisal. Court orders of this kind have become a standard move in Australian breach response — a comparable injunction was obtained by law firm HWL Ebsworth against the ALPHV/BlackCat ransomware group in 2023. But what does an order from the NSW Supreme Court actually achieve when the adversary is an anonymous, offshore criminal syndicate?
Where it genuinely helps
- It binds everyone within reach of the court. The order restrains not just the attackers but anyone with notice of it — Australian media outlets, data traders, researchers, and curious insiders — from accessing, publishing, or misusing the stolen data.
- It powers takedowns. An injunction gives lawyers a legal instrument to demand that platforms, forums, hosting providers, and search engines operating in or serving Australia remove the data when it surfaces.
- It suppresses secondary harm. Much of the damage from a health-data breach comes from re-publication and opportunistic misuse after the initial leak. Raising the legal risk of touching the data shrinks its domestic market and slows its spread.
- It demonstrates diligence. Acting swiftly to contain misuse supports the organisation’s position with the OAIC, insurers, and any future civil claims by affected patients.
Where it falls short
- Criminals don’t read court orders. A syndicate operating anonymously from a non-cooperative jurisdiction has no assets, presence, or reputation within reach of the NSW Supreme Court. An order against “persons unknown” is, to them, unenforceable paper.
- The dark web is beyond the writ. Leak sites, Tor-hosted forums, and encrypted channels where stolen health data is actually traded sit outside any practical takedown regime.
- It cannot un-steal the data. The injunction does nothing to reverse the exfiltration, revoke what the attackers hold, or reduce the ransom leverage they enjoy.
- It risks false reassurance. Boards and patients may read “injunction obtained” as “problem contained.” It is not — it is harm mitigation at the edges of the problem, not at its centre.
The honest verdict: an injunction is a legitimate and worthwhile harm-containment tool — against the domestic ecosystem that would otherwise amplify a breach. Against the syndicate itself, it is largely symbolic. The only defences that work against an offshore attacker operate before the breach: hardened credentials, segmented networks, tested detection and response. That is why the health check below matters more than any court order.
The Accenture Breach — Evidenced Facts
Accenture confirmed a breach on 7–8 July 2026
Accenture stated: “We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery.” This statement appears consistently across BleepingComputer, SecurityWeek, CRN, News18, and TechRadar.
A threat actor (“888”) claims to have stolen ~35GB of internal data
Across all major outlets, the attacker claims the dataset includes:
- Source code
- RSA private keys
- SSH private keys
- Azure Personal Access Tokens (PATs)
- Azure Storage access keys
- Configuration files
These claims are consistently reported but have not been independently verified.
Screenshot evidence shows cloning of an Azure DevOps repository
The attacker shared a screenshot of a repository named “121123_AtriasTalentAcademy” hosted under an accenture.com domain.
Accenture has not disclosed the attack vector or whether client data was affected
All outlets confirm Accenture has provided no details on how access was gained, whether the exfiltrated credentials were active, whether client environments were exposed, or whether regulators were notified.
What These Two Breaches Reveal
Across both incidents, attackers reached deep operational systems:
- Partnered Health: clinical systems, EMR data stores, and pathology interfaces
- Accenture: development infrastructure, cloud access tokens, and private keys
This is not superficial compromise — it is core-system exposure. When an attacker walks away with consultation notes or the private keys to a cloud estate, the blast radius extends far beyond the initial victim: to patients, to clients, and to every downstream system those credentials could unlock.
If a national healthcare group and one of the world’s largest technology consultancies can be breached at this depth, the honest question for every board and executive team is not “could this happen to us?” but “how would we know if it already has?”
A 10-Point Cyber Health Check (Sector-Wide)
| Check | What good looks like | |
|---|---|---|
| 1 | Credential & Access Audit | MFA enforced everywhere; privileged credentials, tokens, and keys rotated on a defined schedule. |
| 2 | Network Segmentation | Clinical and production systems isolated from administrative and general-purpose networks. |
| 3 | Patch Management | Coverage of EMR platforms, HL7/FHIR engines, PACS/DICOM systems, and cloud services — not just desktops. |
| 4 | Cloud Configuration Review | IAM policies, storage access, and logging audited across Azure, AWS, and GCP. |
| 5 | Third-Party Integration Audit | Pathology, imaging, billing, and DevOps pipeline connections reviewed for excessive access. |
| 6 | Backup & Recovery Validation | Offline or immutable backups maintained — and the restore actually tested. |
| 7 | Endpoint Security | EDR/XDR deployed across all endpoints, including clinical workstations and developer machines. |
| 8 | Logging & Monitoring | Outbound exfiltration detection in place — a 35GB transfer should never go unnoticed. |
| 9 | Staff Awareness | Training against medical-themed phishing; developer credential hygiene (no keys in repos, short-lived tokens). |
| 10 | Incident Response Readiness | Tested IR plan, OAIC notification templates, and pre-engaged forensics partners. |
Recommended Pentest Actions
- External penetration test — patient portals, telehealth platforms, and public-facing cloud applications
- Internal network test — simulate lateral movement toward EMR or DevOps systems
- Cloud security assessment — Azure/AWS/GCP IAM, tokens, and storage configuration
- Application security testing — EMR platforms, HL7/FHIR interfaces, and DevOps pipelines
- Social engineering testing — phishing and pretexting against staff and administrators
- Red-team simulation — a full exercise targeting data exfiltration, testing detection and response end to end
Conduct some — or all — of it with Moroku
Working through a list like this takes time, focus, and specialist experience — three things most in-house teams are short on while also running the day-to-day. Moroku can support your organisation to conduct some or all of the work above:
- Rapid cyber health check — a structured assessment against the 10 points above, delivering a prioritised, board-ready findings report
- Pentest scoping and coordination — defining the right mix of external, internal, cloud, and application testing for your environment, and managing trusted testing partners through to remediation
- Cloud and credential hygiene review — hands-on review of IAM, token, and key management practices, informed by exactly the failure modes on display in July’s breaches
- Incident response readiness — IR plan development and tabletop exercises so the first time you rehearse a breach isn’t the day one happens
Whether you need an independent set of eyes on one item or an end-to-end programme, we’d welcome a conversation.