Tasmanian not-for-profit provider Community Based Support (CBS) issued a formal public apology and breach disclosure following the fallout of a September/October 2025 cyber attack claimed by the Lynx ransomware group. The threat actors exfiltrated internal networks containing client medical/care management profiles, employee payroll records, personal contact details, and corporate financial data, followed by extortion demands. CBS activated incident response frameworks alongside external technical specialists, notified privacy regulators, and implemented revised security and identity monitoring protocols for affected community care recipients and staff.