The Nova ransomware syndicate successfully infiltrated the NSW RFS IT infrastructure via a compromised third-party remote access credential (Citrix gateway). While the actors failed to execute their encryption payloads, they successfully exfiltrated 200 gigabytes of data archives and dumped them on the dark web. Internal communications verified the exposure of operational files, topographic maps, and emergency response project files, alongside triggering widespread operational password resets.