ozsoft.com.au Listed by lynx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ozsoft.com.au has been listed by the Lynx ransomware group following the exfiltration of internal files in an attack, with the listing disclosed on 22 October 2025. Individuals and organisations should check whether their data was exposed and take appropriate security steps.
Ransomware groups continue to target mid-sized technology and services firms, listing them on leak sites after claiming to have stolen data and encrypted systems. In this environment, even smaller Australian IT providers can appear as victims when groups seek leverage through public pressure. On 22 October 2025, ozsoft.com.au was reported as listed by the lynx ransomware group, which claimed to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the precise scope is limited. The listing itself is a claim by the group rather than independent confirmation of every detail.
For customers, partners and staff of a custom software and IT services company, any such claim raises practical questions about what information may have left the organisation’s control and what steps follow. This account stays within the reported facts and established public knowledge of the actor and sector.
Inside the incident
According to the available record, ozsoft.com.au was listed by the lynx ransomware group on or around 22 October 2025. The group’s claim centres on a ransomware attack in which internal files were exfiltrated. No public confirmation of the exact date of intrusion, the initial access method, the volume of data taken, or the number of individuals affected has been provided in the facts. People affected are listed as unknown. The organisation is identified as OzSoft Solutions Pty Ltd. Beyond the assertion that internal files were removed as part of the attack, further technical or operational specifics remain undisclosed.
Ransomware incidents of this type typically involve encryption of systems combined with data theft for double-extortion pressure. In this case, only the leak-site listing and the description of internal-file exfiltration are stated. No ransom demand amount, negotiation details, or confirmation of data publication have been supplied in the record, so those elements cannot be treated as established.
The group behind it: lynx
Lynx is a ransomware operation that has appeared in public reporting as a group that encrypts victim systems and threatens to release stolen data if payment is not made. Like other contemporary ransomware actors, it commonly uses a double-extortion model: systems are locked and copies of files are removed for leverage. The group has been observed listing organisations on dedicated leak sites to increase pressure. These tactics are well-documented across multiple public analyses of the actor’s activity.
In the present matter, the facts record only that lynx listed ozsoft.com.au and claimed internal files were exfiltrated in a ransomware attack. No additional statements attributed to the group about this specific victim—such as sample file counts, screenshots of particular documents, or deadlines—are included in the provided record. Therefore any further claims remain unverified beyond the listing itself. Readers should treat the leak-site entry as an assertion by the threat actor pending independent corroboration.
Who is ozsoft.com.au?
OzSoft Solutions Pty Ltd operates in the custom software and IT services industry. Public summary information places the company in the 20-to-49 employee range with revenue between 1 million and 5 million, headquartered in Launceston, Tasmania, Australia. Organisations of this type typically design, develop, maintain or support software systems for clients, and may also provide related IT consulting, infrastructure or managed services.
A firm in this sector commonly holds source code, project documentation, client contracts, internal administrative records, employee information and technical credentials or configuration data needed to deliver services. Because such companies sit between their own operations and those of their customers, a compromise can affect both the provider and the organisations that rely on its software or support. The consequential nature of a breach here stems from that intermediary role rather than from any judgment about the company’s security posture, which is not established in the facts.
What was likely exposed
The facts state that internal files were exfiltrated in the ransomware attack. No further breakdown of file categories, exact data types, or volume is disclosed. People affected remain unknown. Exact contents are therefore unconfirmed.
Companies in custom software and IT services ordinarily maintain a range of internal material: project files, source-code repositories or backups, client correspondence, invoices, employee records, and system documentation. Whether any of those categories were among the files taken cannot be asserted from the available record. The only confirmed description is the group’s claim of internal-file exfiltration. Readers should not assume specific personal or commercial data sets were involved until more detail is verified.
Why it matters
For individuals whose information may have been held by the company—employees, contractors or clients—the practical risks include potential misuse of contact details, credentials or project-related personal data if those items were present among the stolen files. Even when the precise contents are unknown, the mere possibility of exposure can lead to phishing attempts that reference the organisation or its projects. For the organisation itself, the incident creates operational disruption, potential contractual obligations to notify clients, and reputational pressure arising from the public listing.
Because the number of people affected is unknown and the data types beyond “internal files” are not itemised, the scale of downstream impact cannot be quantified from the facts. The risk remains real but bounded by what is actually known: a ransomware claim involving data theft against a mid-sized Australian software and IT services provider. Calm verification and monitoring are more useful than speculation about worst-case scenarios that the record does not support.
If your data was in this claimed breach
If you have a relationship with OzSoft Solutions Pty Ltd—as a current or former employee, contractor or client—treat the possibility of exposure seriously but proportionately. Change passwords for any accounts that may have been linked to the company, enable multi-factor authentication where available, and watch for unexpected emails or messages that reference the firm or its projects. Monitor financial and identity accounts for unusual activity. Because the exact data taken is unconfirmed, these steps remain precautionary rather than responses to proven compromise of specific records.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. That check will not confirm or rule out involvement in this particular incident, but it provides a practical baseline for further monitoring. Official notifications, if any are issued by the company or Australian authorities, should be followed when they become available. Public detail on this event remains limited to the lynx listing and the description of internal-file exfiltration reported on 22 October 2025.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ciscientific.com.au Listed by lynx Ransomware Groupwww.ktlgroup.com Listed by lynx Ransomware GroupCSA Tax & Advisory Listed by lynx Ransomware Groupsspinnovations.com Listed by lynx Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ozsoft.com.au Listed by lynx Ransomware Group →
Publicly posted by lynx — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.