Sydney Tools data breach: Hackers could access over 34 million orders

25 March 2025 2 minutes Author: Newsman

A database breach at Australian retailer Sydney Tools has exposed more than 34 million online order records and employee data. This includes addresses, salary amounts and details of products ordered.

The company left its Clickhouse database open, allowing anyone to view sensitive information without needing to log in. The stolen data included names, addresses, phone numbers, emails, details of tools purchased, and personal details of around 5,000 employees, including salaries and sales plans. Most worryingly, the database remains accessible despite repeated attempts by cybersecurity researchers to contact the company. They also contacted the Australian Signals Directorate after the information was released, but have yet to receive a response.

Sydney Tools is one of the largest professional tools retailers in Australia, similar to the American Home Depot. Although the company officially reports 1,000 employees, the database contained information on a much larger number of people, indicating that the data of former employees may have been leaked. According to researchers, this amount of information opens up a wide range of opportunities for targeted attacks, especially through phishing, fraud and social engineering methods aimed at high-value customers and employees with high salaries.

The Sydney Tools incident demonstrates the disastrous consequences of a negligent attitude to cybersecurity in the retail industry. The data leak not only puts thousands of customers and employees at risk, but also creates a space for physical theft and fraud. The company urgently needs to not only close the vulnerable database, but also publicly report the incident, provide instructions to its customers and conduct a comprehensive audit of its cyber infrastructure.

Other related articles
News
Read more
Cloudflare blocking in Russia caused disruption to banks and government services
The large-scale blockade of Cloudflare in Russia caused serious disruptions in the work of TikTok, banking services, state-owned online platforms and messengers, which led to a digital collapse in some regions. Roskomnadzor is commenting on the situation as "problems with foreign infrastructure," but experts clearly point to the deliberate blocking of the American CDN provider.
205
News
Read more
Attack on Ukrzaliznytsia: infrastructure destroyed, services unavailable, security questions unanswered
The large-scale cyberattack on Ukrzaliznytsia 2025 has become a wake-up call for the entire critical infrastructure sector of Ukraine. The complete destruction of IT systems, the paralysis of online services, and deep suspicions of leaks of sensitive information indicate a catastrophic state of national cybersecurity. Experts are calling for a radical overhaul of approaches, funding, and transparency to prevent similar crises in the future.
171
News
Read more
Ukrainian hackers disrupted the supply of military equipment to the Russian Federation via India
Ukrainian hackers, InformNapalm, sanctions circumvention scheme, military equipment for the Russian Federation, India, Park Controls, HGH Infrared Systems, Sberbank India, Russian EMT, supplies to the Russian Federation, French equipment, international investigation, sanctions against the Russian Federation, hackers disrupted supplies, defense technologies, Israeli analogues, METS-S, CI Systems.
156
Found an error?
If you find an error, take a screenshot and send it to the bot.