Update — 3 August 2026: More detail has emerged since this piece was first published. The listing indexed by Daily Dark Web on 8 April put the dataset at 900,002 customer records, and threat intelligence accounts attributed it to an actor operating under the handle “hackboy.” Reported fields include names, dates of birth, contact details, addresses, account IDs, outstanding balances and billing references — the combination that makes convincing phone scams possible. The Epoch Times covered the claim on 9 April. We have found no public statement from Synergy confirming or denying the breach, and no regulator has published a finding. The claim remains unverified.
In what appears to be the latest addition to a long line of critical infrastructure operators attacked by dark-web hackers, reports emerged last night that Western Australia’s biggest electricity provider, Synergy, had been hit by a major hack. According to a listing posted tonight on the dark-web hacker watch website Daily Dark Web, samples of the breach and claims related to it appear to have been leaked to a well-known leak forum. As we go to press, Synergy has made no public announcement about whether it confirms or denies the breach; nor has the extent or type of the breach been disclosed, nor has the identity of the hacking party. If confirmed, the breach would represent one of the most damaging cyber-attacks to occur within Australia’s energy industry in recent history – and further highlights that Australia’s critical infrastructure remains firmly in the cross-hairs of both financially-motivated cyber-criminals and Ransomware groups.
About Synergy
Synergy is fully owned by the Government of Western Australia and represents the largest electricity generator and distributor in Western Australia. Over 1 million residential, commercial, and industrial customers receive their electricity supply through Synergy across the SWIS network (the same grid system that powers Perth and much of Western Australia). While Synergy generates electricity using conventional means, it is also at the forefront of Western Australia’s renewable energy transformation. It owns a number of wind farms, solar farms, and large-scale battery installations throughout Western Australia as part of the state government’s push towards meeting its 2030 emissions reduction target.
It is Synergy’s massive size that makes the alleged breach potentially devastating. Utility providers like Synergy hold vast amounts of highly sensitive information regarding their customers – such as customer billing records, bank details, smart meter readings, identity documentation, employee personnel files, contractor agreements, and OT configurations. Leaks from any of these areas may lead to a range of problems, including identity theft and targeted phishing attacks against WA households; however, leaks from operational systems may pose significantly greater threats.
What do we know — and what do we don’t?
At present, little detail is known. A dark-web posting indexed by Daily Dark Web tonight states that Synergy has suffered a significant data breach. It does not disclose the volume of data breached, the types of information breached, or when the alleged breach occurred. To date, no Ransomware group has claimed responsibility for a major leak site, and therefore, there is no independent confirmation that the data being offered for sale is genuine and/or current.
Postings like this one surface on invite-only forums that sit on the dark web rather than the open internet, which is part of why they are so hard to verify quickly — our guide to the difference between the deep web and the dark web explains how these spaces work.
An important caveat
While true breaches do occur frequently on the dark web, many postings labeled “breaches” are in reality recycled datasets, repackaged “leaks,” or complete fabrications created to coerce money from companies or enhance a threat actor’s credibility among other users on underground forums. In recent months, multiple high-profile “breach” announcements against major Australian organizations have ultimately resulted in nothing more than old datasets (which had previously been released into the wild), compromises involving Third-party vendors, or simply scraped public data being repackaged and presented as new stolen data. Therefore, until Synergy or relevant Western Australian authorities make an official response to this posting, readers should treat this posting as merely an unsubstantiated claim rather than a proven fact.
The reverse also happens. Smaller incidents get dismissed and then turn out to be real and unusually damaging, as with the MyLovelyAI leak, where roughly 106,000 accounts caused harm out of all proportion to the record count because of what the records contained.
A trend – not a fluke
Regardless of whether this specific posting is legitimate, there is clearly a trend. Australia has experienced an unprecedented run of high-profile cyberattacks over the past 18 months. Energy companies, telcos, health care providers, educational institutions, and government agencies have all appeared on dark web leak sites — our dark web statistics for 2026 track how quickly stolen records reach these forums. Multiple Ransomware crews have repeatedly included Australian organizations on their lists of victims (including LockBit, Medusa, Qilin, Akira & SafePay), and each month the Australian Cyber Security Centre (ACSC) publishes advisories identifying critical infrastructure operators as prime targets for both financially motivated cybercriminals and nation-state-sponsored actors.
Why energy utilities are so appealing
As stated earlier, energy utilities offer cyber attackers a unique combination of factors that provide maximum leverage to extract money from them. Each energy utility maintains extensive databases of personal information about millions of individuals, operates in a relatively straightforward-to-disrupt IT/OT environment, is under constant regulatory scrutiny to ensure continuous availability, and has sufficient visibility in the public eye to maximize the potential for embarrassment or disruption. Any attacker capable of plausibly threatening to either disrupt or embarrass a state-owned electricity provider will undoubtedly get Synergy’s undivided attention.
Is this new for Synergy?
Not at all. Since the passage of Australia’s Security of Critical Infrastructure Act 2018 (the SOCI Act) and the designation of electricity assets as critical infrastructure, Synergy has operated under an expanded set of reporting requirements, mandated risk management frameworks, and ongoing oversight by government regulators aimed at making essential services less vulnerable to exactly this type of cyber event.
What Synergy customers should do now
Nothing here is confirmed, but the sensible precautions cost nothing and are worth taking regardless. Treat any unexpected call, text or email referencing your Synergy account balance with suspicion — billing data is precisely what makes impersonation scams convincing, and the pattern is the same one we broke down in the Coinbase text scam. Never act on a payment request that arrives unprompted; call the retailer on a number you looked up yourself. If you want ongoing warning when your details surface somewhere they shouldn’t, our reviews of Aura and Norton cover what each service actually detects.
Where does this go from here?
There are three primary factors that will determine where this story goes from here: whether Synergy officially releases a public statement (silence extending beyond 24-48 hours usually indicates an internal investigation is underway). When/if any named threat actor posts proof-of-breach samples. How quickly government agencies like the Australian Signals Directorate (ASD) or the OAIC publicly acknowledge that mandatory notification thresholds have been exceeded.
For a sense of what the aftermath looks like when a claim of this size is confirmed, the T-Mobile breach and its $350 million settlement shows how long the tail runs — that one took four years to reach the payout stage.