The Qilin ransomware group has named two more Australian organisations on its dark-web ransom blog, adding Redrop Group and Thorndale Foundation to its list of claimed victims.
The latest listings highlight the continued targeting of Australian organisations by major ransomware operations and the potential exposure of sensitive information when threat actors move from an initial victim claim to publishing stolen data.
Thorndale Foundation

The Qilin listing for Thorndale Foundation currently includes material that the ransomware group claims was obtained during the alleged compromise.
Evidence published on the group’s leak site includes passport photographs and invoices.
The presence of these documents is potentially significant because passport information represents highly sensitive personal data. If your organisation is storing passport images or passport ID’s then please ask yourself, is it absolutely necessary to do so. If it is not then cease doing so.
However, material published by a ransomware group should be treated as threat-actor-provided evidence rather than independent confirmation of an incident. The authenticity, completeness and circumstances surrounding the material would require verification by the affected organisation or other trusted sources.
Redrop Group

Qilin has also listed Redrop Group as an Australian victim.
At the time of writing, the Redrop Group listing does not appear to contain publicly available evidence or data samples comparable to those currently displayed for Thorndale Foundation.
The absence of published evidence does not necessarily indicate that no data was obtained. Ransomware groups can progressively update leak-site listings, particularly as negotiations with an alleged victim develop.
Additional information could therefore appear on the listing at a later stage.
Why the Listings Matter
Qilin is one of the ransomware operations using a double-extortion model. Under this approach, attackers seek to gain leverage not only through encryption or disruption of systems, but also through the threat of releasing data allegedly stolen from the victim.
For Australian organisations, the latest listings demonstrate the importance of considering both operational disruption and data exposure when assessing ransomware risk.
Where sensitive documents such as passports, invoices or other business records are involved, the potential consequences can extend beyond the immediate availability of IT systems.
Threat Actor Claims vs Confirmed Incidents
It is important to distinguish between an organisation being named on a ransomware leak site and an independently confirmed cyber security incident.
A threat actor may claim to have compromised an organisation without providing evidence, while published material may subsequently provide indications that data was obtained. Even then, the material requires validation before conclusions can be drawn about the full scope of an incident.
For Redrop Group, no publicly displayed evidence has currently been identified alongside the Qilin claim. For Thorndale Foundation, Qilin has published samples including passport photographs and invoices.
| Organisation | Country | Qilin Listing | Publicly Displayed Evidence |
|---|---|---|---|
| Thorndale Foundation | Australia | Listed | Passport photographs, invoices and other material |
| Redrop Group | Australia | Listed | No evidence currently observed |
More Information to Come
The two Australian listings remain active developments.
More information is expected to come later, particularly if Qilin publishes additional data relating to Redrop Group or releases further material associated with the Thorndale Foundation claim.
Organisations monitoring ransomware activity should continue to treat leak-site listings as threat intelligence and potential indicators of compromise, while avoiding assumptions about an incident until information can be independently verified.
This article is based on monitoring of ransomware threat-actor activity. The claims made by Qilin have not been independently verified. The article will be updated if additional information or evidence becomes available.