Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Exclusive: Harcourts investigates cyber attack claims, no evidence of impact so far

Major Australasian real estate firm Harcourts has said it is aware of claims of cyber attack following the listing made by the SafePay ransomware gang yesterday.

Fri, 19 Jun 2026
Exclusive: Harcourts investigate cyber attack claims, no evidence of impact so far

Overnight, between Wednesday and Thursday this week, the SafePay ransomware gang listed Harcourts on its dark web leak site, threatening to leak allegedly stolen data. According to the countdown timer, the alleged data will be leaked in one day and 15 hours at the time of writing.

Speaking with Cyber Daily, Harcourts has confirmed it is aware of the claim and has launched an investigation.

“We are aware that an external party has made a claim about our company online,” said a Harcourts spokesperson.

 
 

“As soon as we became aware of this claim, we took immediate steps to engage specialist cyber security experts to commence an urgent investigation. We have also introduced containment measures to reduce risk and strengthen the security of our environment while we continue our investigation.”

The firm added that while it is in the early stages of its investigation, it has yet to note any evidence of impact.

“We are liaising with our network offices and will continue to update our staff, clients and key partners if we identify any relevant and accurate evidence of impact to personal information.

“We also have ongoing monitoring in place, with the support of our cyber security experts.”

Harcourts also reiterated that the allegedly stolen data would not be accessible through clear web means; however, this does not rule out access by criminals who already use those tools and are within the cyber crime ecosystem.

“We will update the relevant authorities as appropriate, in line with our obligations.”

At this stage, the threat actor has not disclosed any details of the incident nor shared any sample data to verify exfiltration. However, the listing has already had 2,142 views at the time of writing.

Who is SafePay?

SafePay was first observed in October 2024 and has since claimed more than 500 victims.

The group has been observed targeting businesses in Australia, the United Kingdom, the United States, Italy, New Zealand, Canada, Belgium, Brazil, Germany, Barbados and Argentina.

According to the group, it is not a ransomware-as-a-service (RaaS) operation.

“SafePay ransomware has never provided and does not provide the RaaS,” SafePay said on its leak site.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags:

Daniel Croft

Born in the heart of Western Sydney, Daniel Croft is a passionate journalist with an understanding for and experience writing in the technology space. Having studied at Macquarie University, he joined Momentum Media in 2022, writing across a number of publications including Australian Aviation, Cyber Security Connect and Defence Connect. Outside of writing, Daniel has a keen interest in music, and spends his time playing in bands around Sydney.