Qilin ransomware gang claims 215 GB theft from Australian charity Meli
- Organization
- Meli
- Exploit
- Ransomware
- Industry
- Nonprofit
Meli, a not-for-profit community services organisation headquartered in North Geelong, Victoria, confirmed in late August 2024 that it had been targeted in a cyber attack. The organisation runs family and community support programs, more than 30 kindergartens across the Geelong, Bellarine and Colac regions, and a foster care service.
The Qilin ransomware operation, also tracked as Agenda, listed Meli on its darknet leak site on 25 August 2024 and claimed to have taken 419,617 files totalling roughly 215 GB. To support the claim the group published 14 screenshots of stolen documents, among them financial statements, confidentiality agreements, scans of current and expired passports, and a Medicare card. Qilin did not publish a ransom amount or a deadline.
Meli said it detected the incident, moved to secure its systems and engaged forensic specialists and cyber security advisers. A later statement acknowledged that a subset of files had been taken from the affected system. The organisation notified Victoria Police, Victoria Health, the Australian Cyber Security Centre and other government agencies.
Meli said client services continued as normal, though some internal processes were affected and staff fell back on paper based and manual systems for parts of the operation. Qilin claimed on its leak site that the attack took place on 21 August 2024, as relayed by Cyber Daily, while the Institute of Community Directors Australia placed the initial breach in late July. As of the end of August the investigation was continuing and no ransom demand had been made public.