A hacker known as 2019, who has claimed responsibility for a string of data breaches affecting Australian organisations, has turned their attention to a New Zealand real estate company.
On 18 August 2026, 2019 published details of an alleged breach involving New Zealand Sotheby’s International Realty, claiming to have obtained data from the organisation. The incident appears to involve a third-party customer relationship management (CRM) system used for marketing and operational purposes.
The scale of the alleged compromise is notable. The hacker claims access to approximately 1.6 million records, a figure that appears unusually large for a niche New Zealand real estate business and raises questions about the scope of the affected third-party system.
The data reportedly includes customer contact information such as names, email addresses and physical addresses. The information is currently being offered for sale on an underground hacking forum.
Who is 2019?
The threat actor known as 2019 became active in January 2026 and has made approximately 40 posts, most of which relate to alleged data breaches and other leaks.
Very little is publicly known about the individual or group behind the activity. Unlike some established threat actors, 2019 does not appear to be consistently targeting organisations using a particular software platform or technology.
Based on the organisations claimed as victims, the likely scenario is that 2019 is focusing on bespoke or publicly facing applications (Mitre ATT&CK Technique T1190) with weak security controls rather than exploiting a single common technology or vendor.
The threat actor is generally considered a credible source of stolen data when making breach claims. The main disputed claim to date relates to an alleged compromise involving Services Australia’s Centrelink agency in June 2026.
Recent claimed victims include a number of prominent Australian organisations, including BestPriceTravel Australia, Court Services Victoria, the Melbourne International Film Festival and Lifeline Australia.
Organisations reportedly targeted by 2019
The following table summarises the organisations and data associated with 2019’s reported breach claims based on information published by the threat actor.
| Date | Company name | Records exfiltrated | Fields exfiltrated |
|---|---|---|---|
| 24/08/26 | New Zealand Sotheby’s International Realty | 1.6 million | Names, email addresses, physical addresses and other contact information; data reportedly sourced from a third-party CRM |
| 14/07/26 | Lifeline Australia | 10,600 | AD Distinguished Name, client name, date of birth, email address, login and phone number |
| 04/08/26 | BestPriceTravel Australia | Not specified | Not specified |
| 30/07/26 | Court Services Victoria | 28,600 | Booking ID, hearing type, date of birth, custody location and Webex credentials |
| 23/06/26 | National Portrait Gallery (npg.gov.au) | 2,600 | Mobile number, name, payroll identifier and email address |
| 01/06/26 | Melbourne International Film Festival | 6,782 | Addresses, customer IDs, email addresses, names and membership information |
| 12/06/26 | Ochre Health | 25,000 | Names, dates of birth, addresses, email addresses, phone numbers, Medicare numbers, Department of Veterans’ Affairs numbers, appointment details and billing information |
| 03/06/26 | Australian Centre for the Moving Image (ACMI) | 25,000 | Full names, email addresses, IP addresses and order details, including rented item, rental date and payment method |
Record counts and data fields in the table are based on claims attributed to 2019 and have not necessarily been independently verified.
Data is often offered for sale
2019 generally makes stolen data available for free, although there have been instances where the threat actor has attempted to sell datasets through underground forums.
Where data is sold, 2019 has reportedly sought cryptocurrency payments, including Bitcoin, Ethereum or Monero, with some datasets offered as one-time sales.
The latest New Zealand Sotheby’s International Realty claim is particularly noteworthy because of the reported volume of records and the apparent involvement of a third-party CRM platform.
If the 1.6 million-record figure is accurate, the incident may extend beyond the direct customer database of the real estate business and could potentially reflect a broader compromise of the underlying CRM provider or a dataset shared across multiple customers.
What organisations should take away
The activity attributed to 2019 highlights the risks posed by externally facing applications and third-party services. Organisations may have strong internal security controls while still being exposed through applications, integrations or service providers that sit outside their traditional security perimeter.
Just because you have been using a public facing application for an extended period of time without issue does not mean that it has strong security controls and if it holds PI or PII data then you should periodically test its security maturity.
The New Zealand Sotheby’s International Realty claim also demonstrates why unusually large breach claims should be treated carefully until the source and scope of the data can be independently established.