Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Exclusive: Downies Collectables continues to respond to ransomware incident

Investigations by Aussie rare coin supplier remain ongoing, as cyber extortionists continue to apply pressure on the dark web.

Tue, 04 Aug 2026
Exclusive: Downies Collectables continues to respond to ransomware incident

One of Australia’s leading numismatics and model specialist sellers is continuing to respond to a ransomware attack and extortion attempt by a cyber criminal group calling itself Settra.

The hackers listed Downies as a victim in a July leak post and are continuing to selectively disclose data stolen in the incident in an attempt to ramp up pressure on their victim.

Downies confirmed it was investigating the incident at the time and is now responding to malicious claims made by the ransomware group.

 
 

“On Monday, 6 July 2026, we identified suspicious activity within our IT network and immediately commenced an investigation, which remains on foot,” Downies told Cyber Daily following the latest update made by the hackers.

“Based on investigations to date, we understand that data stored within our IT system was accessed and removed without authorisation by a malicious cyber criminal.

“We recently became aware that certain information is referred to within a breach listing on a dark web leak site of a cyber criminal organisation, which is part of the continuing investigation efforts.

“We implore people not to look for data illegally leaked, as doing so only encourages further such criminal activity and may further the potential harm to Australians possibly impacted.”

Luke Templeton, Downies’ CEO, said responding to the incident has been challenging, particularly in relation to Settra’s “reprehensible conduct”.

Settra originally claimed to have found several irregularities in Downies’ business operations; however, it appeared that the summary of the group’s findings is AI-generated, likely with an eye to cast the company in a poor light and apply pressure, a tactic the group continues to use.

“We are urgently working with our forensics experts and cyber security advisors to undertake a comprehensive investigation of the incident and any data stolen by the criminal organisation,” Downies said.

“We are also working with relevant Australian government agencies in response to this incident, including the Australian Signals Directorate, the Australian Federal Police, and Victoria Police.

“This incident has also been reported to the Office of the Australian Information Commissioner, and we will be directly notifying individuals impacted by this incident.”

Despite being a relatively new group first observed at the end of June, Settra has already listed 36 victims on its darknet leak site. Downies is its only Australian victim to date.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: