On October 29, 2025, Malibu Boats Australia appeared on the leak site operated by the qilin ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the company, which sells boats and marine equipment across Australia. Anyone whose personal information appears in those stolen files—including customers, employees, suppliers, or their family members—now faces the risk that their data could be published or sold.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Malibu Boats Australia
Get alerted the next time Malibu Boats Australia files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Malibu Boats Australia’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that qilin posted Malibu Boats Australia to its data-leak portal on 29 October 2025. The group claims to have stolen internal company files but has not yet published samples. No confirmed total of affected individuals has been released, and the precise volume or type of records remains unclear. Available reporting describes the incident as a classic ransomware operation in which data is taken before encryption demands are made.
Why This Matters for You and Your Family
When a company that holds customer orders, payment details, addresses, or employee records is breached, that information can quickly reach identity thieves, fraudsters, or harassers. Internal files often contain names, phone numbers, email addresses, dates of birth, and sometimes driver’s licence or passport copies. For families this can mean children’s details surface alongside parents’, creating long-term exposure. A single leak like this one can feed years of phishing, account takeovers, and unwanted contact if the data spreads.
The Doxxing and Identity-Chain Risk
Ransomware leaks rarely stay isolated. Criminals frequently link an email from one breach to usernames on social media, gaming platforms, or shopping sites. That process, known as identity-chain mapping, turns one company breach into a map of your entire digital life. A leaked boat-order address can be matched to a child’s Roblox or Fortnite account that uses the same email, exposing the family to doxxing, swatting, or targeted scams. Gaming accounts are especially vulnerable because kids often reuse passwords or email addresses that appear in adult-oriented business records.