What July Ransomware Attacks Reveal About SME Security Gaps

Between 11 and 23 July 2026, ransomware groups listed three separate Australian organisations on their dark web leak sites. None share an industry. None have made headlines before. And as of this writing, none of the three has confirmed a breach, these are claims made by the threat actors themselves, not verified incidents. That distinction matters, and so does the pattern underneath it.

Three Targets, No Common Thread Except Size

The National Picture

Ransomware groups like SafePay and DragonForce run affiliate-based, high-volume extortion operations built to find the easiest path in, not the biggest name to extort. For an IT and risk team at a mid-market organisation, “we’re too small to be worth it” was never a sound assumption. ASD’s Annual Cyber Threat Report 2024-25 puts numbers behind that. ASD’s ACSC responded to more than 1,200 cyber security incidents in FY2024-25, an 11 per cent increase on the year before. The average self-reported cost of cybercrime climbed across every size of business: up 14 per cent to $56,600 for small business, and up 55 per cent to $97,200 for medium business, a steeper rise than large organisations recorded.

Where the Gaps Actually Sit

What gets exploited in incidents like these is rarely sophisticated. It’s the fundamentals: unpatched applications and operating systems, missing multi-factor authentication on remote access, unrestricted administrative privileges, and application control gaps that let unapproved software run unchecked. These are the exact technical controls the Essential Eight was built to address, and they are exactly where mid-market environments tend to quietly lose visibility over time. A patch that fails silently on one machine. An MFA policy that never made it to a legacy account. An endpoint added six months ago that was never brought into scope.

Closing the Visibility Gap

Most organisations find out about gaps like these the way the three above may be finding out now, after the fact, when a leak site countdown starts. A point-in-time audit or an annual self-assessment tells you what your controls looked like on the day someone checked, not what they look like today, a limitation we’ve covered in more detail here.

What actually closes that gap is continuous, evidence-based verification: an ongoing check across every endpoint in your environment confirming whether your Essential Eight technical controls are genuinely in place and functioning, not an assumption carried over from last year’s review. It’s the difference between security coverage and security confidence, and it’s usually the gap that costs the most when it goes unaddressed.

The Gap These Three Have in Common

Twelve days and three unrelated sectors is a narrow window, but it’s a live one. Ransomware groups don’t choose targets for size or profile, they choose whichever control gap gives them a way in first.

If you want an honest, current read on where that gap might sit in your own environment, our team can walk you through it.

Let's see how we can personalise your cloud computing needs

Evolution Systems is ISO 27001 Certified