Political parties run by Australian mining magnate Clive Palmer have suffered a ransomware attack, potentially compromising banking records, employment history, and other personal information. The Trumpet of Patriots, which contested May's federal election without securing any seats, announced the breach to supporters on Thursday.
The breach occurred on 23 June and involved unauthorised access to servers, resulting in possible copying of data records. This may include all emails, documents, and records from both the Trumpet of Patriots and its predecessor, the United Australia party. Affected data could encompass email addresses, phone numbers, identity records, banking details, and employment history, though the party said it is unsure of the full extent.
In a notice posted on its website, the party stated: 'We do not know comprehensively what information of yours was on the server but you should assume that any information you have provided would have been stored on the server.' It added that it was 'impracticable to notify individuals' and has since secured systems and restored them from backups.
The breach has been reported to the Office of the Australian Information Commissioner (OAIC) and the Australian Signals Directorate (ASD). Supporters are advised to review what information they provided and remain vigilant for potential scams. Under Australia's mandatory data breach notification scheme, organisations must assess and report serious breaches within 30 days.
Palmer's parties failed to win any seats in the federal election despite an estimated $60m advertising spend and millions of unsolicited text messages. The ASD responded to 121 ransomware incidents in 2023-2024, comprising 11% of all incidents, while the OAIC reported that 26% of 413 cybersecurity breaches in the same period involved ransomware.



