Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

ASX-listed fintech firm discloses cyber incident impacting client data

An Australian ASX-listed fintech has disclosed a cyber incident which it says has impacted both client and other data.

• Wed, 07 Oct 2026 •
ASX-listed fintech firm discloses cyber incident impacting client data

OFX Group Limited is an international money transfer and currency exchange business based in Sydney, Australia. It was founded in 1988 as OzForex, and now has offices across 8 global financial hubs including Sydney, London, Dublin, Auckland, Hong Kong, Singapore, Toronto and San Francisco. The company went public in 2013.

In a statement published through the ASX, OFX Group disclosed the incident saying that it was currently investigating to understand the depth of the incident.

“At this stage of its investigation, OFX has not identified any unauthorised access to client accounts or funds and, based on the information available to date, there has been no financial loss to clients,” the company noted.

 
 

“OFX’s services and systems continue to operate normally and remain fully available. OFX’s IT and Security teams responded immediately when they became aware of the incident and have implemented containment actions “

The company also said it was working to determine how many clients were impacted, as well as their identities.

It also said data belonging to non-clients, including job applicants, was accessed by the cyber criminal.

“At this stage, it does not appear that any copies of identity documents have been accessed. It also appears that none of the data accessed can be used to make a payment in the OFX platform,” OFX Group added.

Once OFX Group can confirm that their data was accessed, impacted individuals will be notified of the breach.

“OFX’s investigations into this incident are continuing as a matter of urgency and OFX will provide further updates as appropriate.”

The company said it had notified the Office of the Australian Information Commissioner (OAIC), the Australian Signals Directorate’s (ASD’s) Australian Cyber Security Centre (ACSC) and other relevant global authorities.

Cyber Daily and its sister publication Banking Daily reached out to OFX Group for more details, but the firm declined to comment beyond existing statements.

The threat actor behind the incident has not yet been identified, nor has any hacker or hacking group claimed responsibility publicly. Cyber Daily and Banking Daily will continue to investigate.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: