LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ozsoft.com.au Listed by lynx Ransomware Group

HIGH severityUnverified claimHow we verify

ozsoft.com.au Listed by lynx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 22, 2025
ozsoft.com.au Listed by lynx Ransomware Group

Reported October 22, 2025.

HIGH
Severity
October 22, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

ozsoft.com.au has been listed by the Lynx ransomware group following the exfiltration of internal files in an attack, with the listing disclosed on 22 October 2025. Individuals and organisations should check whether their data was exposed and take appropriate security steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target mid-sized technology and services firms, listing them on leak sites after claiming to have stolen data and encrypted systems. In this environment, even smaller Australian IT providers can appear as victims when groups seek leverage through public pressure. On 22 October 2025, ozsoft.com.au was reported as listed by the lynx ransomware group, which claimed to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the precise scope is limited. The listing itself is a claim by the group rather than independent confirmation of every detail.

For customers, partners and staff of a custom software and IT services company, any such claim raises practical questions about what information may have left the organisation’s control and what steps follow. This account stays within the reported facts and established public knowledge of the actor and sector.

Inside the incident

According to the available record, ozsoft.com.au was listed by the lynx ransomware group on or around 22 October 2025. The group’s claim centres on a ransomware attack in which internal files were exfiltrated. No public confirmation of the exact date of intrusion, the initial access method, the volume of data taken, or the number of individuals affected has been provided in the facts. People affected are listed as unknown. The organisation is identified as OzSoft Solutions Pty Ltd. Beyond the assertion that internal files were removed as part of the attack, further technical or operational specifics remain undisclosed.

Ransomware incidents of this type typically involve encryption of systems combined with data theft for double-extortion pressure. In this case, only the leak-site listing and the description of internal-file exfiltration are stated. No ransom demand amount, negotiation details, or confirmation of data publication have been supplied in the record, so those elements cannot be treated as established.

The group behind it: lynx

Lynx is a ransomware operation that has appeared in public reporting as a group that encrypts victim systems and threatens to release stolen data if payment is not made. Like other contemporary ransomware actors, it commonly uses a double-extortion model: systems are locked and copies of files are removed for leverage. The group has been observed listing organisations on dedicated leak sites to increase pressure. These tactics are well-documented across multiple public analyses of the actor’s activity.

In the present matter, the facts record only that lynx listed ozsoft.com.au and claimed internal files were exfiltrated in a ransomware attack. No additional statements attributed to the group about this specific victim—such as sample file counts, screenshots of particular documents, or deadlines—are included in the provided record. Therefore any further claims remain unverified beyond the listing itself. Readers should treat the leak-site entry as an assertion by the threat actor pending independent corroboration.

Who is ozsoft.com.au?

OzSoft Solutions Pty Ltd operates in the custom software and IT services industry. Public summary information places the company in the 20-to-49 employee range with revenue between 1 million and 5 million, headquartered in Launceston, Tasmania, Australia. Organisations of this type typically design, develop, maintain or support software systems for clients, and may also provide related IT consulting, infrastructure or managed services.

A firm in this sector commonly holds source code, project documentation, client contracts, internal administrative records, employee information and technical credentials or configuration data needed to deliver services. Because such companies sit between their own operations and those of their customers, a compromise can affect both the provider and the organisations that rely on its software or support. The consequential nature of a breach here stems from that intermediary role rather than from any judgment about the company’s security posture, which is not established in the facts.

What was likely exposed

The facts state that internal files were exfiltrated in the ransomware attack. No further breakdown of file categories, exact data types, or volume is disclosed. People affected remain unknown. Exact contents are therefore unconfirmed.

Companies in custom software and IT services ordinarily maintain a range of internal material: project files, source-code repositories or backups, client correspondence, invoices, employee records, and system documentation. Whether any of those categories were among the files taken cannot be asserted from the available record. The only confirmed description is the group’s claim of internal-file exfiltration. Readers should not assume specific personal or commercial data sets were involved until more detail is verified.

Why it matters

For individuals whose information may have been held by the company—employees, contractors or clients—the practical risks include potential misuse of contact details, credentials or project-related personal data if those items were present among the stolen files. Even when the precise contents are unknown, the mere possibility of exposure can lead to phishing attempts that reference the organisation or its projects. For the organisation itself, the incident creates operational disruption, potential contractual obligations to notify clients, and reputational pressure arising from the public listing.

Because the number of people affected is unknown and the data types beyond “internal files” are not itemised, the scale of downstream impact cannot be quantified from the facts. The risk remains real but bounded by what is actually known: a ransomware claim involving data theft against a mid-sized Australian software and IT services provider. Calm verification and monitoring are more useful than speculation about worst-case scenarios that the record does not support.

If your data was in this claimed breach

If you have a relationship with OzSoft Solutions Pty Ltd—as a current or former employee, contractor or client—treat the possibility of exposure seriously but proportionately. Change passwords for any accounts that may have been linked to the company, enable multi-factor authentication where available, and watch for unexpected emails or messages that reference the firm or its projects. Monitor financial and identity accounts for unusual activity. Because the exact data taken is unconfirmed, these steps remain precautionary rather than responses to proven compromise of specific records.

You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. That check will not confirm or rule out involvement in this particular incident, but it provides a practical baseline for further monitoring. Official notifications, if any are issued by the company or Australian authorities, should be followed when they become available. Public detail on this event remains limited to the lynx listing and the description of internal-file exfiltration reported on 22 October 2025.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyozsoft.com.au security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See ozsoft.com.au’s full breach history →

More recent breaches

ciscientific.com.au Listed by lynx Ransomware GroupJanuary 4, 2025www.ktlgroup.com Listed by lynx Ransomware GroupDecember 16, 2025CSA Tax & Advisory Listed by lynx Ransomware GroupDecember 2, 2025sspinnovations.com Listed by lynx Ransomware GroupNovember 27, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the ozsoft.com.au Listed by lynx Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lynx — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram