Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

GO2 Health confirms limited data breach, patient data remains largely secure

Brisbane medical centre GO2 Health says one internal inbox was compromised, with “Department of Veterans’ Affairs ID numbers and other information” accessed.

Wed, 22 Jul 2026
GO2 Health confirms limited data breach; patient data remains largely secure

Everton Park-based GO2 Health has confirmed it was the victim of what appears to be a business email compromise phishing attack, which has led to some patient data being accessed without authorisation.

“We understand the importance people place on the security of their personal information, and we take this very seriously. We sincerely apologise for any concern that this incident has caused our patients,” a GO2 Health spokesperson told Cyber Daily after the ABC initially broke the news of the incident on 21 July.

“When we became aware of unauthorised access to one of our email mailboxes via a phishing email, we took immediate steps to engage external experts to investigate and contain the incident. We also issued an immediate alert on 24 April to mailbox users who received the phishing email to warn them to remain vigilant.”

 
 

GO2 Health’s investigation revealed that limited data within the compromised mailbox had been accessed, including some patients’ Department of Veterans Affairs ID numbers. Other data provided to that inbox may also have been accessed; however, only that specific inbox was impacted.

“Importantly, there was no access to the system where we primarily store patient information, and the mailbox uses an auto-archive, so the data accessed only pertains to emails sent during the previous 12 months leading up to the incident,” the spokesperson said.

“We have also identified no evidence that any personal information has been published or used without permission.”

GO2 Health said it had identified the individuals impacted by the incident and notified them of what had occurred and what type of data had been exposed.

“We also notified the Australian Cyber Security Centre and Office of the Australian Information Commissioner (OAIC), and have continued to update the OAIC throughout this process,” GO2 Health said.

GO2 Health also addressed some concerns regarding how long its investigation took.

“These sorts of investigations are extremely complex, and identifying exactly which individuals may have been affected takes time to complete with accuracy via a review of the contents of the mailbox,” the spokesperson said.

“We wanted to avoid causing undue concern and confusion by notifying the wrong people, or communicating inaccurate information.

“We understand our patients will have questions. We ask anyone who may have specific questions about their specific information to contact us directly, and we will try to provide them with as much detail as possible.”

No threat actor has yet been identified as the perpetrator.

Who is GO2 Health?

GO2 Health is based in the Brisbane suburb of Everton Park and offers general practice and specialist medical and nursing services.

GO2 Health also operates REFORGE, which it describes as “one of Australia’s leading veteran care clinics”.

According to its website, GO2 Health has supported more than 14,000 patients, including more than 7,000 veterans.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags:

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.