My News Feed Saturday 1 August 2026

Meriton cyber attack exposes nearly 2000 guests and staff

• By Editorial Team •
cyber attackdata breachmeritonprivacycybersecurityaustralia

Apartment servicing giant Meriton has acknowledged a cyber attack from January that infiltrated its systems and potentially exposed personal information of nearly 2000 guests and staff members across its Australian network.

The breach, which came to light over the past few days, targeted operational data stored within Meriton's network spanning Sydney, Brisbane, the Gold Coast, Melbourne and Canberra. Once the incident came to light, the company notified 1889 individuals whose information may have been affected.

According to Meriton's disclosure, the attackers accessed approximately 35.6 gigabytes of data, primarily consisting of "incident reports" — internal records documenting injuries and accidents that occurred at the company's serviced apartments. Despite the large volume of information accessed, Meriton maintains that most of the compromised data was not particularly sensitive in nature.

Most significantly for affected guests and employees, no credit card details or other financial information were stolen in the breach. Meriton stated there is currently no evidence that the personal information has been misused or released publicly, offering some reassurance to those whose data may have been compromised.

The company reported the incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. Meriton has engaged leading cybersecurity and forensic IT professionals to investigate the breach and prevent future incidents. In response, the company has implemented enhanced security measures across its network and deployed extensive monitoring systems to quickly identify and respond to any future threats.

The Meriton attack is the latest in a concerning string of cyber breaches affecting Australian consumers. Earlier this month, finance company Latitude Group disclosed that a hack had compromised the records of 14 million Australian and New Zealand customers, including driver's licences, passport numbers and personal details. This incident reflects a troubling pattern that has included major breaches at Medibank and Optus, which collectively exposed millions of Australians' sensitive information.

Regulators and consumer advocates have expressed growing concern about the scale and frequency of such attacks. The Australian consumer watchdog has called on business leaders to strengthen their defences as identity theft and financial fraud reach unprecedented levels. While more than $569 million was reported lost to scams in 2022, that figure is understood to represent only a small portion of actual fraud losses across the country.

Reporting compiled from queanbeyanage.com.au, 9news.com.au.

Frequently Asked Questions

When did the Meriton cyber attack occur?

The attack occurred in January 2023, but was not publicly disclosed until late March. The company reported the breach to relevant authorities and notified affected individuals once the incident was confirmed.

What information was exposed in the Meriton breach?

Hackers accessed approximately 35.6 gigabytes of data, primarily consisting of incident reports documenting injuries and accidents at Meriton properties. No credit card details or financial information were compromised.

How many people were affected by the Meriton cyber attack?

Approximately 2000 people were potentially affected, including Meriton guests and past and present employees. The company notified 1889 individuals whose data may have been compromised.

More news