Sydney-headquartered retail investment and brokerage firm fell victim to an external network intrusion. Threat actors hosted an exfiltrated SQL trading directory for sale on the dark web, containing the transaction histories and usernames of over 400,000 clients.