Incident

NSW Reconstruction Authority reports data leak, up to 3,000 flood victims' data exposed in ChatGPT upload


Learn More

The NSW Reconstruction Authority is reporting a data breach affecting applicants to the Northern Rivers Resilient Homes Program, a government initiative established after the devastating 2022 floods in northern NSW. The Northern Rivers Resilient Homes Program assists residents affected by flooding through various measures, including buying back homes in high-risk flood areas, contributing to rebuilding costs, or funding resilience improvements such as home elevation.

A former contractor uploaded sensitive applicant information to the artificial intelligence platform ChatGPT without authorization, potentially exposing the personal details of up to 3,000 individuals.

The incident took place between March 12 and 15, 2025, but was not reported for more than six months. The unauthorized upload involved a Microsoft Excel spreadsheet containing 10 columns and over 12,000 rows of information related to program applicants. The Authority engaged forensic analysts and worked with Cyber Security NSW. Exposed data includes:

  • Names
  • Addresses
  • Email addresses
  • Phone numbers
  • Personal information
  • Health information

The number of affected individuals is estimated at up to 3,000 people, all of whom are applicants to the Northern Rivers Resilient Homes Program. 

According to the NSW Reconstruction Authority, there is currently no evidence that any of the uploaded data has been accessed by a third party or made publicly available.Officials acknowledge this possibility cannot be completely ruled out, given that public AI tools like ChatGPT operate in uncontrolled environments.

The Reconstruction Authority has established support channels for affected individuals, including a dedicated call center at 1800 844 085 (operating Monday to Friday, 9am to 5pm) and access to ID Support NSW at 1800 001 040. The Authority has also pledged to provide compensation for any reasonable out-of-pocket expenses if compromised identity documents need replacement.

NSW Reconstruction Authority reports data leak, up to 3,000 flood victims' data exposed in ChatGPT upload