
Episode notes
In July 2026, someone accessed the system Victorian courts use to link participants to online hearings. Not the case management system - the joining list. Four years of it, across ten regional court locations, for the Magistrates' Court and the Children's Court.
This episode walks through what was confirmed, what was only claimed, and why a scheduling layer turned out to be more sensitive than the case files it pointed at.
What Court Services Victoria confirmed: the incident occurred in July 2026; the data spans 2022 to 2026; ten named regional locations including Bendigo, Castlemaine, Echuca, Kerang, Kyneton, Maryborough, Mildura, Ouyen, Robinvale and Swan Hill. Exposed fields include participant names, case titles and numbers, hearing dates, times and courtrooms, plus two things not on the public record - email addresses and a description of the person's role in the matter. The Case Management System, employee data and financial data were not accessed.
What was only claimed: the "more than 28,600 lines" figure comes from the threat actor, not from the organisation. CSV states it "is unable to verify the number of people and matters impacted". Lines are not people, and no affected-person count has been published.
The most sensitive claim, carefully sourced: the ABC reports it understands the leaked data includes the names of parties in family violence intervention order hearings and children's court cases. CSV has not confirmed this. CSV's own support page links to The Orange Door, Safe Steps and the Victims of Crime Helpline.
Also covered: why nobody has been individually notified, what CSV is offering instead (a public FAQ and a hotline on 03 9087 6116), and why your ability to notify people is a design decision you make years before a breach.
Four takeaways: find your scheduling layers; treat metadata and context as data; use retention as a blast-radius control; and know whether your clients sit under the OAIC or a state regulator - CSV is a Victorian public sector body, so this one sits with OVIC under the Privacy and Data Protection Act 2014 (Vic), not the OAIC.
And the uncomfortable closing question: CSV confirms this is a completely different system to its 2024 breach. What else in your organisation looks like the system you have not hardened yet?
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: Court Services Victoria, "Data Security Notification" and "CSV data security incident FAQs" (courts.vic.gov.au, 30 July 2026); Magistrates' Court of Victoria notification (mcv.vic.gov.au, 5 August 2026); Cyber Daily exclusive (30 July 2026); Lawyers Weekly (30 July 2026); ABC News (7 August 2026), summarised by DataBreaches.Net; Law360 Australia; Privacy and Data Protection Act 2014 (Vic); Office of the Victorian Information Commissioner.
