Pennant Hills Golf Club, founded in 1923, is the Hills District’s leading private golf club, with a 5,925-metre par-71 eighteen-hole championship course. The club is known for hosting amateur events and competitions.
The golf club was listed on the dark web by the infamous Qilin ransomware gang overnight; however, very few details are known about the alleged cyber attack.
Qilin’s listing does not outline details of the incident, what kind of data was allegedly stolen, if any, or what kind of ransom or deadline has been set.
Responding to Cyber Daily's request for comment, a spokesperson for Pennant Hills Golf CLub said that it was investigating the claims, but that there had been no disruption to its operations.
"We are responding to a cyber incident after detecting unauthorised access to our systems. We took immediate steps to secure our systems and have engaged external cyber experts to provide advice," the spokesperson wrote.
"Recently we were made aware of claims made by an unauthorised third party in relation to information alleged to be from our systems. We are working urgently with our experts to verify and investigate these claims.
"There has been no disruption to our operations, and we will keep our members and staff informed with any relevant updates as we continue our investigation.
"Protecting the information entrusted to us is a responsibility we take very seriously, and we apologise for any concern this incident may cause."
Who is Qilin?
Qilin has claimed 1,968 victims since it was first observed in 2022, spread across 99 countries. It is currently the most active ransomware operation in existence, averaging about 100 victim listings per month so far in 2026.
The group operates under a ransomware-as-a-service model, with affiliates gaining access to its ransomware infrastructure in return for a cut of any ransom payments.
While some affiliates will publish complete details of their activities, including the volume of data stolen and screenshots of evidence, others post minimal information, often not going into detail about the data or its contents.
Qilin’s most recent Aussie victim was K-12 tutoring provider Kinetic Education, which was listed on the dark web on 8 June.
Like with Pennant Hills Golf Club, the leak post does not include the volume of data involved, nor any details of the data potentially compromised. All that’s included is Kinetic Education’s company logo, the date of the leak post, and the number of views it has clocked up.
Updated - 06/07/26: Updated to include Pennant Hills Golf Club's statement.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.