Home/Incidents/KPMG Australia

KPMG Australia

29 May 2026 · National · Legal & Professional Services
Data Breach CRITICAL ✓ Verified

What happened

Big Four accounting firm KPMG Australia became engulfed in a major systemic data breach scandal after a whistleblower revealed partners routinely misused highly confidential client intelligence for commercial gain. Senior audit partners covertly accessed and shared sensitive board papers, insider documentation, and financial profiles belonging to long-term clients—including Lendlease, Macquarie Group, Westpac, Dexus, Telstra, and Optus—to pitch for and secure lucrative rival corporate audit contracts. Following a two-year internal mishandling of the disclosures, a cascading crisis on May 29 forced the immediate resignations of CEO Andrew Yates, Head of Audit Julian McPherson, and COO Eileen Hoggett. The fallout triggered formal investigations by ASIC, CA ANZ, and the Tax Practitioners Board, alongside a multi-state review of government contracts and a federal parliamentary inquiry into large partnership governance.

Incident details

Organisation
KPMG Australia
Date
29 May 2026
Attack type
Data Breach
Severity
CRITICAL
Sector
Legal & Professional Services
State
National
Records affected
Multiple Corporate Clients
Threat actor
Inside Threat

Source

kpmg.com ↗
← Back to all incidents