Funlab, the Australian entertainment company behind Holey Moley, said a cyber-security incident affected some of its IT systems from 20 to 22 September 2024. The company said venues and operations returned to normal within 48 hours. In October, the Lynx ransomware group listed Funlab on its leak site and posted material it claimed came from the company.
Funlab said it did not believe guest data had been accessed, but acknowledged that limited information relating to a low-double-digit number of current and former employees may have been accessed. Public reporting has not established that customer data was stolen, how attackers first got in, whether systems were encrypted, the amount of data exfiltrated or any ransom demand.
What is Funlab, and why is Holey Moley mentioned?
Holey Moley is a Funlab brand, not a separately named victim in the company’s public statements. Funlab also operates Strike Bowling, Archie Brothers, B. Lucky & Sons, La Di Darts, Juke’s Karaoke, Red Herring Escape Rooms and Hijinx Hotel. Its current company profile says the group has more than 80 locations across Australia, New Zealand and the United States and more than 2,500 employees. Reports published in 2024 used lower figures, including about 40 locations and more than 2,000 employees.
The reported incident concerned Funlab’s wider IT environment. It does not establish that a particular Holey Moley venue, booking system or payment terminal was independently compromised.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Individual A-Z Tabs for Quick Access: No need for annoying searches! With individual alphabetical tabs, this password keeper book makes it easier to find your passwords in no time. It also features an extra tab for your most used websites. All the tabs are laminated to resist tears.
- Medium Size & Ample Space: Measuring 5.3"x7.6", this password book fits easily into purses, handy for accessibility. Stores up to 560 entries and offers spacious writing space, perfect for seniors. It also provides extra pages to record additional information, such as email settings, card information, and more.
- Spiral Bound & Quality Paper: With sturdy spiral binding, this logbook can 180° lay flat for ease of use. Thick, no-bleed paper for smooth writing and preventing ink leakage. Back pocket to store your loose notes.
- Never Forget Another Password: Bored of hunting for passwords or constantly resetting them? Then this password book is absolutely a lifesaver! Provides a dedicated place to store all of your important website addresses, emails, usernames, and passwords. Saves you from password forgetting or hackers stealing.
- Discreet Design for Secure Password Organization: With no title on the front to keep your passwords safe, it also has space to write password hints instead of the password itself! Finished with an elastic band for safe closure.
What happened and when?
| Date | What is established |
|---|---|
| 20–22 September 2024 | Funlab said some IT systems were affected. It described the event as a cyber-security incident. |
| Within 48 hours | Funlab said operations returned to business as usual. |
| 14 October 2024 | Cyber Daily reported that Lynx had listed Funlab on its leak site. |
| 15 October 2024 | 9News and other outlets reported Funlab’s confirmation of the incident. |
| 16 October 2024 | PerthNow and The West Australian placed the Funlab event alongside attacks reported at two other local businesses. |
Contemporaneous media called the event a ransomware attack because Lynx is a ransomware and extortion group and published a claim against Funlab. Funlab’s own wording was more cautious. Available reports support claims of unauthorised access and alleged data theft, but do not confirm that Funlab files were encrypted.
What did Funlab say about customer and employee data?
Funlab said it did not believe guest data had been accessed. That is not the same as a forensic guarantee that no customer information was exposed, and no later public source in the available reporting confirms customer-data theft.
The company separately said limited information relating to a small number of current and former employees—described as “low double digits”—may have been accessed. Funlab said it contacted affected or potentially affected employees, offered assistance, and reported the matter to the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) and the Office of the Australian Information Commissioner (OAIC).
Rank #2
- Never Forget a Password Again: Tired of forgetting your passwords? Say goodbye to the frustration of constantly juggling and resetting passwords. Our Password Book with Colorful Alphabetical Tabs helps you easily store and keep all your passwords in one secure place, saving you from the hassle of managing multiple passwords, with no visible labels or titles, protecting your sensitive information.
- Find Your Passwords Quickly & Easily: Need to find a password in seconds? This password keeper with alphabetical tabs makes it simple. With vibrant colors and clear A-Z prints, you can quickly locate what you need, making it a breeze to access your accounts.
- Easily Store Up to 900 Passwords: This password notebook features 240 pages of 120gsm thick paper, offering the capacity to store up to 900 passwords. Additionally, it provides ample space for internet service providers, wireless router settings, software licenses, email settings, frequently visited websites, and extra notes.
- Intimate Add-Ons for Enhanced Functionality: Measuring 8.4" x 5.8", this password keeper includes 2 ribbon bookmarks for easy navigation, a fine inner pocket at the back for additional storage, an elastic pen holder for convenience, and 120gsm paper to prevent ink bleeding. It's perfect for managing your passwords and more.
- A Thoughtful Gift for Any Occasion: Looking for a practical gift for your loved ones or colleagues? This Password Book is an ideal choice to alleviate the stress of password memorization. Suitable for both men and women, it's a considerate gift for family, friends, and colleagues on birthdays, holidays, or any special occasion.
- Guest data: Funlab’s position was that it did not believe this category had been accessed.
- Employee data: Funlab acknowledged possible limited access involving a low-double-digit number of people.
- Confirmed exfiltration: Public reporting does not establish that particular guest or employee files were copied out, or that the published material represents the full scope of the incident.
What did the Lynx group claim?
Lynx listed Funlab on its leak site and posted screenshots and documents as purported evidence. Cyber Daily reported apparent folders labelled “Payroll”, “Finance” and “Gsuite Backup”, along with budget spreadsheets and internal communications (Cyber Daily’s report).
Those details are observations of material published by a threat actor, not independent confirmation that every file was genuine, complete or obtained during this incident. The available coverage does not establish the initial access method, the quantity of data taken, whether encryption occurred, or the ransom amount.
Which other local businesses were reported as affected?
A PerthNow report grouped the Funlab story with incidents involving two Western Australian businesses. The cases should not be treated as a confirmed single campaign: the available evidence does not show that the same attacker or intrusion method was used against all three organisations.
Rank #3
- 【Tired of constantly searching for or resetting your passwords?】 MOSA BEAR password keeper book is the perfect solution for you! This password book provides a dedicated place to securely store all your important website addresses, emails, usernames and passwords, ensuring your information is protected and easy to find. The well-designed log pages help you manage multiple accounts in a systematic way, saying goodbye to password confusion.
- 【Premium Design & Password Security】 The password book with alphabetical tabs features an anonymous cover design with no title on the cover, effectively avoiding information exposure. The password keeper design is specifically designed with password security in mind, providing space to record password hints instead of writing directly on the password itself, further protecting your important information.
- 【Simple Layout and Plenty of Space】The 160-page password logbook is designed to provide ample space to record passwords and other important information. It can store up to 414 passwords. In addition, it provides extra pages to record other information, such as email setup, card information, computer operating system information, software licenses, and more. The journal also includes 3 blank pages at the end for you to add additional notes.
- 【Palm-sized Size & Premium Quality】 This password notebook has an ideal size, 4.3" x 5.7", for carrying around, whether in a purse or pocket. Its sturdy glue binding allows the notebook to unfold smoothly and is more comfortable to use. The inner pages are made of high-quality 100GSM thick paper, which can effectively reduce ink penetration and ensure a cleaner and neater writing effect. The overall design takes into account both portability and durability, making it an ideal choice for recording important passwords.
- 【A-Z Tabs for Quick Search 】Our password book comes with alphabetical tabs to help you find the password you need quickly and easily. Alphabetically organized tabs ensure that you can quickly flip to the right section, saving you the time and hassle of searching for your password.
TPG Aged Care
TPG Aged Care, a Kingsley provider, said an attacker gained unauthorised access to servers and obtained approximately 65GB of data. It reported the incident to the ACSC and OAIC.
Road Distribution Services
Welshpool trucking business Road Distribution Services was also reported as caught up in a similar cyber attack. The available coverage does not state which systems were affected, how much data was involved, whether a ransom was demanded or what notifications were made.
Why ransomware reaches smaller and mid-sized businesses
Ransomware is not limited to major corporations. Smaller operators can hold valuable payroll, finance, customer, supplier and operational information while having fewer dedicated security staff. Their venues may also depend on connected booking, point-of-sale, identity and cloud systems, making downtime immediately costly.
Rank #4
- No more Password Aggravation:This book will simplify your electronic life and free you from the constant frustration of trying to remember and reset your passwords. You can record longer and more complex passwords and never forget them again.
- Alphabetical Tabs (A-Z): We upgraded to one letter one tab(A-Z),others are two letters share 5 pages(AB-YZ). Our password journal has 6 pages per alphabetical tab. Makes your password easy to find and keeps organized.
- Plenty of Space for Information: Each tab has 6 pages with 3 entries per page, it can contain over 414 passwords. There're additional pages, PC info, email settings and 8 pages of notes. We have reserved a place to write a password hint instead of the password itself to ensure password security.
- 100GSM No-Bleed Paper: This password notebooks are made of very thick 100gsm paper, no bleed through. Size 4.3in x 5.7in, suitable size for carry-on. 180°lay flat so it’s easy to write in.
- Excellent Gift to All Ages:Easy to use, keeps passwords organized. With an elastic band, pen holder, bookmarker and inner pocket. A great present for friends and family.
The ACSC says ransomware can cause operational disruption, lost revenue, reputational damage and customer loss for small and medium-sized businesses. Its guidance highlights poor cyber hygiene, exposed internet services, weak authentication and inadequate backups as common contributors. Those are risk patterns, not a confirmed explanation for how attackers entered Funlab’s environment; no public report identifies Funlab’s initial access vector.
What an Australian business should do after an attack
- Record and preserve evidence. Keep ransom notes, suspicious emails, timestamps, affected-device details and known actions. Preserve logs and avoid deleting files that may help investigators.
- Isolate affected systems. Disconnect compromised devices and limit network access to contain spread, while taking care not to destroy volatile evidence.
- Get specialist help. Contact an incident-response or digital-forensics provider and the ACSC hotline, 1300 CYBER1 (1300 292 371).
- Secure identities from a clean device. Change privileged, email, VPN, cloud and other important credentials. Revoke active sessions and review administrator and former-employee accounts. Enable multi-factor authentication.
- Check backups before restoring. Determine whether backups are intact, isolated or immutable. Restore only after compromised credentials, persistence and vulnerable systems are understood.
- Assess personal information. Determine what data was accessible, whether it was copied and which people may face harm.
- Notify the right parties. Consider OAIC, ACSC, affected individuals, insurers, law enforcement, customers and suppliers according to the facts and applicable obligations.
- Keep investigating after service resumes. Restoring venue operations does not prove that attacker access, stolen credentials or data-exfiltration paths have been removed.
- Do not assume payment solves the problem. The ACSC warns that paying a ransom does not guarantee decryption or prevent publication and can encourage further attacks.
Australian reporting and privacy obligations
Ransomware reporting, privacy notification and operational incident reporting are separate issues.
Ransom-payment reporting
Under Australia’s ransomware-payment reporting regime, a reporting business entity generally includes an entity carrying on business in Australia with annual turnover of at least AUD3 million. If a covered entity makes, or becomes aware of, a ransomware or cyber-extortion payment, it must submit the government report within 72 hours. The ACSC explains the process in its payment-reporting guidance.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsBest Value
- NEVER FORGET A PASSWORD AGAIN: Almost every App. has a password, it is almost impossible to remember all the password log in details. This password book is specifically designed to help you create secure passwords and store all your passwords safely in one place. You will never forget your password log-in details again with this password keeper.
- ALPHABETICAL A-Z TABS FOR QUICK ACCESS: Alphabetical tabs design allows you to store your passwords alphabetically so you can find what you want faster, no more annoying searches!
- ANONYMOUS WITHOUT ANY TITLE: On the outside, this password notebook organizer looks just like those writing journals, there is no title listed on the cover, so no one would know it's a password book. But we still recommend keeping the internet password logbook in a safe place such as a locked drawer or a shelf full of books.
- THICK NO-BLEED PAPER: This 5.2" x 7.6" password book contains 74 sheets of thick 120gsm paper that resists ink smearing, say goodbye to those cheap password books that bleed ink!
- PREMIUM QUALITY & PERFECT MEDIUM SIZE: This password journal comes with a high-quality leatherette hardcover, an elastic band, pen holder, ribbon bookmarker, and inner accordion pocket. It measures 5.2 inches wide and 7.6 inches long, which is the perfect size for your needs.
Notifiable Data Breaches
The Notifiable Data Breaches scheme may require notification to affected people and the OAIC when a breach is likely to result in serious harm. Reporting an event to the ACSC does not automatically satisfy every privacy, contractual or sector-specific requirement. Businesses should obtain legal and privacy advice during a live incident.
Controls that reduce ransomware risk
No single safeguard guarantees protection. The ACSC’s recommendations include:
- Enforce multi-factor authentication for email, VPN, administrator and critical-system accounts.
- Patch operating systems, applications, appliances and internet-facing services promptly.
- Maintain offline or otherwise protected backups and test restoration regularly.
- Remove unnecessary exposure of remote desktop, file shares, NAS devices and remote-administration interfaces to the internet.
- Deploy centrally managed endpoint protection and ensure someone responds to its alerts.
- Use unique, strong passphrases with a business password manager.
- Apply least-privilege access and review dormant and former-worker accounts.
- Train staff to recognise phishing, malicious attachments and unusual login prompts.
- Maintain an incident-response plan with out-of-band communication methods.
- Review the security and access practices of suppliers and managed-service providers.
Further practical controls are set out in the ACSC’s ransomware protection guidance.
What remains unknown about Funlab
- How attackers initially entered Funlab’s systems.
- Whether files or systems were encrypted.
- The precise volume of data copied or accessed.
- Whether Lynx’s published material was complete and authentic in every respect.
- Whether a ransom was demanded or paid.
- Whether guest data was later confirmed as compromised.
- Whether Funlab, TPG Aged Care and Road Distribution Services were connected by one campaign or actor.
The clearest public account is therefore limited but useful: Funlab experienced a September 2024 IT incident, recovered operations quickly, and later faced a Lynx extortion claim. Its statement did not establish customer-data theft, while possible limited employee-data access remained the material privacy concern described in contemporaneous reporting.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




