Two more Australian organisations have appeared on ransomware and extortion group leak sites, with Qilin listing Zig Inge Group and Krybit listing Jones the Grocer.
The two listings were observed on 24 September 2026, according to ransomware tracking sources monitoring the groups’ leak-site activity.
Qilin – Zig Inge Group
The Qilin ransomware group added Zig Inge Group a retirement living operator to its victim listings on 24 September.
The listing identifies the organisation as Zig Inge Group, with the associated website being:
www.prospecthillcamberwell.com.au
Ransomware tracking data recorded the Qilin listing at approximately 16:37 UTC on 24 September 2026. Qilin’s recent listings have included organisations across a wide range of industries and countries.
A separate ransomware tracker currently categorises Zig Inge Group as being in the real estate sector and records the listing date as 24 September 2026.
At this stage, the appearance on the leak site should be treated as a claim by Qilin. The listing itself does not independently establish what systems may have been accessed, whether data was stolen, or whether encryption occurred.
Krybit – Jones the Grocer
The Krybit extortion group has also added an Australian organisation to its leak site.
The victim is listed as Jones the Grocer, with the website:
RansomLook recorded the listing at approximately 13:45 UTC on 24 September 2026, alongside another Krybit listing for Air Tanzania.
Jones the Grocer is an Australian retail and grocery business, making this another example of the continuing exposure of Australian organisations across different ransomware and data-extortion operations.
Again, the leak-site entry represents an unverified claim by Krybit. Further information would be required to establish whether data was actually obtained, what information may have been accessed, and whether the incident involved ransomware encryption or was primarily a data-extortion operation.
Two More Australian Listings
| Organisation | Ransomware / Extortion Group | Website | Listed |
|---|---|---|---|
| Zig Inge Group | Qilin | prospecthillcamberwell.com.au | 24 September 2026 |
| Jones the Grocer | Krybit | jonesthegrocer.com | 24 September 2026 |
The simultaneous appearance of two Australian organisations on different ransomware leak sites highlights the continued targeting of Australian businesses by multiple extortion operations.
For organisations monitoring Australian cyber threats, ransomware leak-site activity can provide an early indication of an alleged incident, but a listing should not automatically be treated as confirmation of a successful compromise or data breach. Organisations should look for independent confirmation, including statements from the affected company, regulatory notifications, or technical evidence.
More information may become available if either group publishes samples of allegedly stolen data or the affected organisations issue statements.