Aussie Farmers Direct
We've seen a surge in older data breaches resurfacing on Telegram channels lately, often repackaged as "new" leaks to generate views and illicit sales. What really struck us wasn't the volume of records in this particular case – it was the clear evidence of data decay and the potential for outdated information to still be weaponized in targeted phishing campaigns. The breach we're examining involves data from Aussie Farmers Direct, an Australian online grocery delivery service that went into administration in 2018. While the breach itself isn't new, its reappearance highlights the persistent risk posed by legacy data and the ongoing value it holds for malicious actors.
Aussie Farmers Direct breach: 35,000 customer records resurface
The Aussie Farmers Direct breach involves approximately 35,000 customer records. This data was discovered circulating on a Telegram channel known for aggregating and selling leaked databases on October 26, 2024. While the breach itself likely occurred years ago, its reappearance on this platform suggests a renewed interest in the data, possibly for use in targeted scams or identity theft. The data had been circulating quietly, but we noticed it as part of a larger sweep identifying re-surfaced breaches.
The breach caught our attention due to the nature of the data included, despite its age. The exposed records contain a mix of Personally Identifiable Information (PII), including customer names, email addresses, phone numbers, delivery addresses, and order histories. While payment card details are not believed to be included in this leak, the available information is sufficient for crafting highly convincing phishing emails or SMS messages. It matters to enterprises now, because even defunct companies have a responsibility to ensure secure data disposal. This incident also highlights the long tail of data breaches and the need for continuous monitoring of online marketplaces for compromised information.
- Total records exposed: Approximately 35,000
- Types of data included: Names, email addresses, phone numbers, delivery addresses, order histories
- Sensitive content types: PII
- Source structure: Appears to be a database export (format not specified in the Telegram post)
- Leak location(s): Telegram channel (name withheld to avoid amplification)
- Date of first appearance: October 26, 2024 (on Telegram)
External Context & Supporting Evidence
While initial reporting on the original Aussie Farmers Direct breach is scarce, the company's collapse in 2018 was widely covered by Australian news outlets. A report by ABC News Australia detailed the company's financial struggles and eventual closure. This context is important because it suggests that data security may not have been a top priority during the company's final months. The lack of transparency surrounding the original breach, coupled with the company's demise, likely contributed to its reappearance on Telegram.
On a related note, the resurgence of older breaches aligns with a broader trend observed by cybersecurity researchers. As noted in a recent Security Intelligence article, credential stuffing attacks, which rely on reused or outdated credentials, are on the rise. The Aussie Farmers Direct data, while old, could still be valuable for individuals who have reused their email addresses and passwords across multiple platforms.
Breach Breakdown
4,326 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds