

In late 2018, Vinomofo began a project to migrate data in stages, from its legacy environment to a new platform. To support this, it copied its customer database into an AWS-hosted temporary migration database.
Unfortunately this database was sitting on an old AWS account that predated Amazon’s default use of virtual private clouds, meaning it was never properly walled off from the wider internet.
The first data tranche was transferred in April 2022, followed by customer lists in August 2022.
On 25 September 2022, a threat actor accessed and exfiltrated data from this database, comprising around 17GB relating to roughly 928,760 individuals, including identity, contact and financial information. The hacker sought a ransomware payment from Vinomofo. The stolen data was listed for sale on the dark web on 16 October, with a sample sold on 20 October 2022.
Vinomofo notified the OAIC on 17 October 2022 (some 22 days after the ransomware incident occurred).
That notification kicked off a formal investigation by the OAIC, eventually resulting in the Determination being handed down in October 2025.
Privacy Commissioner Carly Kind concluded that the “totality of steps” Vinomofo had taken simply didn’t amount to “reasonable steps” to protect the personal information they held, given what was at stake: the sensitivity and volume of the information, the resources a business like Vinomofo had available, and the very real risk of exactly this kind of breach occurring.
In other words, having some security measures isn’t the test. The test is whether what you did was proportionate to what you were protecting.
In determining what would have been reasonable, the OAIC had regard to:
In considering the controls that should have been in place, reference was made to industry Standards – specifically the NIST CSF, ISO 27000 series, the Essential 8 and the Information Security Manual.
The decision provides some clear direction on the sort of controls the Commissioner might expect an organisation like Vinomofo to have in place, covering technical controls, policies and procedures, internal cyber skills and a culture of security awareness. These expectations are clear from the orders that required Vinomofo to take a number of steps including:
On the people and culture side, the Commissioner found that Vinomofo’s business posture simply didn’t value or nurture attention to customer privacy.
A 2021 audit had found no formal security policies existed at all, no documentation on things as basic as acceptable use of laptops or passwords. The team responsible for cyber security at the time of the breach was just three people, and none held formal cyber security qualifications.
Vinomofo pointed to some mitigating factors, including staff privacy training through a program called Safetrac, and the disruption COVID had caused to its operations.
The Commissioner accepted those points, but didn’t accept they excused the delay in getting the fundamentals sorted before customer data was moved into a new, more exposed environment.
In this Determination the Commissioner therefore ordered an independent review of whether the security team is adequately resourced and qualified, and a refreshed staff training program. Vinomofo also was ordered to bring in an independent reviewer within six months to check all of this has actually been done properly.
The bigger lesson for anyone reading this outside the wine industry is that APP 11.1 isn’t a box you tick once. It’s a standard that gets reassessed every time your data footprint changes. A cloud migration project is exactly the kind of moment regulators will now expect you to have handled with diligence that is proportionate to the risk.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.