Public incident case studies

Cyber incidents, traced to the consequence.

Public-source analysis focused on what happened, what it cost, which readiness gaps mattered, and what changed afterwards.

The organisations profiled are not and have not been Lykos Defence clients. These case studies are based solely on public-source information and examine publicly documented incident impacts, outcomes, and preparedness considerations.

Resolved enforcement outcome

FIIG Securities

2023 cyber-attack · Federal Court outcome 2026

A$3.0Mcourt-ordered financial outcomeA$2.5M penalty + A$500k ASIC costs
385GB
confidential information stolen
18,000
clients notified
4+ years
cybersecurity failures cited
  • Governance
  • Monitoring and detection
  • Asset and vulnerability management
  • Secure configuration and development
  • Security awareness
Read the case study

Material impact documented

Latitude Financial

2023 cyber incident · Remediation and investigations ongoing

A$68.3M2023 cyber-related costs and provisionsPre-tax, reported in Latitude’s 2023 Annual Report
7.9M
drivers' licence numbers stolen
6.1M
additional partial records
5–6 weeks
platform restoration
  • Third-party risk
  • Identity and access
  • Privacy and data lifecycle
  • Operational resilience and business continuity
Read the case study

Impact known; proceedings ongoing

Medibank

2022 cybercrime event · Regulatory proceedings ongoing

A$160.8Mcumulative disclosed non-recurring cybercrime costsMedibank disclosed A$160.8 million in non-recurring cybercrime costs through FY26.
9.7M
Australians in OAIC allegations
~520GB
data allegedly extracted
No MFA
on VPN, OAIC alleges
  • Identity and access
  • Monitoring and detection
  • Third-party risk
  • Privacy and data lifecycle
  • Evidence preservation and forensic readiness
Read the case study