Clive Palmer’s United Australia Party and Trumpets of Patriots have suffered a ransomware attack that could include all of the emails and documents held by the party.
An email was sent by the United Australia Party to its mailing list on Thursday afternoon saying it had suffered a data breach last month.
“On 23 June, 2025, we identified unauthorised access to our servers resulting in access to, and the possible exfiltration of, certain data records. We were the subject of a ransomware cyberattack,” it said.
A near-identical statement was posted on the Trumpet of Patriots website.
The messages said that the records accessed could include “all emails to and from the [party] (including their attachments) and documents and records created and or held electronically by the [party] at any time in the past”.
Both said this could include all information provided to the party, such as email addresses, phone numbers, banking records and other confidential documents.
The messages also said the parties do “not know comprehensively what information of yours was on the server” and that they will not notify all the individuals because it is “impractical”.
The parties say the breach has been reported to the Office of the Information Commissioner and the Australian Signals Directorate.
When contacted by Crikey, a spokesperson for Palmer sent a text saying: “This is the first I have heard anything about this.”
An individual who answered a phone number listed by the UAP for anyone who has questions about the breach said that they did not think that the party had been contacted by the attacker.
“We don’t know the extent of the information that they have. At the moment, we’re working on finding out what’s been divulged and what’s not,” they said.
The individual said that the party would update its notice of the breach “if anything else comes to light”.
While the parties’ breach may be extensive, there is reason to believe the data exposed may not include the phone numbers of people who received text messages from Palmer’s parties during election campaigns.
During the 2025 federal election, a Trumpets of Patriots source told Crikey that this mass messaging was carried out by an external firm and that the party did not have access to the list of recipients.
Australian digital privacy lawyer James Patto told Crikey that the Privacy Act‘s carve-out for political parties meant that Palmer’s parties would not be subject to any penalties for the breach.
However, he noted that the recently introduced statutory tort for serious invasions of privacy, as well as contractual obligations arising from any confidential documents that were breached, meant that the parties were not free from any consequences.
“This could be a test case to hit political parties. And it might be nice if they [those affected] win something because it might bring in some rigour to the political parties in their data management,” he said.