Data Breach Public Notification Register
The Environment Protection Authority (EPA) maintains this register in accordance with section 59P(2) of the Privacy and Personal Information Protection Act 1998 (PPIP Act).
This register contains details of public notifications issued by the EPA in relation to eligible data breaches involving personal information.
Notifications remain available on this register for at least 12 months from the date of publication.
Data breach policy
The EPA's Data Breach Policy outlines our approach to complying with the Mandatory Notification of Data Breach Scheme, including role and responsibilities for:
- containing, assessing and managing data breaches
- notifying and reporting on 'eligible data breaches'.
Public notification register of data breaches
Date of data breach
Unknown – EPA became aware of the breach on 6 August 2026
Type of breach
Unauthorised disclosure
Description of the breach
An issue with guest user accounts in Salesforce may have made litter reports and user contact details available.
How the breach occurred
There was an issue with guest user access to the EPA’s Report Litter and Local Litter Check within Salesforce.
Other affected agencies (if applicable)
N/A
Personal information subject of the breach
The personal information included litter reports made by individuals using Report Litter and the contact details of users of the Local Litter Check.
The EPA can confirm sensitive documents such as drivers’ licences and financial information is not captured by the portal.
Time the information was available as a consequence of disclosure, access, or loss
The EPA is unable to determine how long the personal information may have been available prior to its temporary closure on 6 August 2026. The Local Litter Check has been active since 2018 while the Report Litter web app was launched in 2015 and upgraded to its current form in 2021.
Risk mitigation activities and or planned action to control harm
As soon as we became aware of the incident, the EPA took immediate steps to secure the information and investigate the matter. This included closure of the portals until the security issues had been resolved (between 6 August and 20 August) as well as the implementation of enhanced security testing and improved controls.
Recommended action(s) for affected individuals
Individuals should:
- Be cautious of unexpected emails, phone calls or text messages seeking personal information
- Avoid opening links or attachments from unknown or unexpected senders
- Use strong and unique passwords for online services
- Enable multi-factor authentication where available
- Monitor for signs of identity misuse, scams or fraudulent activity
- Contact ID Support NSW for assistance
Date notification published
28 September 2026
Date of data breach
29 June 2026
Type and description of the breach
CLM and UPSS spatial datasets were assigned public access permissions.
How the breach occurred
A subfolder containing CLM and UPSS spatial datasets had inadvertently been assigned public access permissions.
Other affected agencies (if applicable)
N/A
Personal information subject of the breach
The personal information involved may have included full names and contact addresses.
Importantly the EPA can confirm that no financial or primary proof-of-identity documents were exposed.
Time the information was available as a consequence of disclosure, access, or loss
April 2021 to 13 July 2026.
Risk mitigation activities and or planned action to control harm
The EPA secured the data on discovery by revoking unauthorised access, strengthened access controls by updating relevant permissions and user privileges, and is contacting affected individuals where possible.
Recommended action(s) for affected individuals
Individuals should:
- Be cautious of unexpected emails, phone calls or text messages seeking personal information
- Avoid opening links or attachments from unknown or unexpected senders
- Use strong and unique passwords for online services
- Enable multi-factor authentication where available
- Monitor for signs of identity misuse, scams or fraudulent activity
- Contact ID Support NSW for assistance
Date notification published
28 August 2026
Date of data breach
28 June 2025
Type and description of the breach
Unauthorised third-party access to the EPA’s POEO public register, which includes non-public documents relating to Dangerous Goods, Radiation and Pesticides licences.
How the breach occurred
Unauthorised third-party access.
Other affected agencies (if applicable)
N/A
Personal information subject of the breach
- Full name
- Postal address
- Contact email address.
We confirm that no financial or primary proof-of-identity documents, such as driver’s licence numbers were exposed.
Time the information was available as a consequence of disclosure, access, or loss
Between 2015 and February 2026.
Risk mitigation activities and or planned action to control harm
Took the POEO Register offline to undertake a comprehensive security check.
Notified Cyber Security NSW and the NSW Privacy Commissioner that we believe Dangerous Goods, Radiation and Pesticides licence documents, dated between 1 January 2011 and 13 November 2024, have been accessed without permission.
Recommended action(s) for affected individuals
Individuals should:
- Be cautious of unexpected emails, phone calls or text messages seeking personal information
- Avoid opening links or attachments from unknown or unexpected senders
- Use strong and unique passwords for online services
- Enable multi-factor authentication where available
- Monitor for signs of identity misuse, scams or fraudulent activity
- Contact ID Support NSW for assistance.
Date notification published
13 May 2026
Get help or make a complaint
ID Support
ID Support NSW offers assistance for individuals dealing with data breaches and information compromise.
To contact ID Support NSW:
- visit ID Support NSW
- phone 1800 001 040, Monday to Friday 9 am to 5 pm, excluding public holidays. Interpreter services are available.
NSW Environment Protection Authority
To contact us:
- visit Environment Line
- email [email protected]
Submit a privacy complaint
If you were impacted by a breach, you can submit a privacy complaint to the EPA regarding this incident to [email protected]