Between 11 and 23 July 2026, ransomware groups listed three separate Australian organisations on their dark web leak sites. None share an industry. None have made headlines before. And as of this writing, none of the three has confirmed a breach, these are claims made by the threat actors themselves, not verified incidents. That distinction matters, and so does the pattern underneath it.
Three Targets, No Common Thread Except Size
- A Western Australian equipment hire firm appeared on the DragonForce leak site on 11 July, with screenshots of credit applications, tax invoices and hire records published as alleged proof of the intrusion.
- A Grafton, NSW accounting and advisory firm that has been operating since 1916 turned up on the SafePay group’s leak site on 20 July, with financial and client records allegedly at risk of release.
- A Melbourne heritage restoration and construction firm was among more than a dozen victims The Gentlemen group posted to its leak site within a single 24-hour period on 23 July.
The National Picture
Ransomware groups like SafePay and DragonForce run affiliate-based, high-volume extortion operations built to find the easiest path in, not the biggest name to extort. For an IT and risk team at a mid-market organisation, “we’re too small to be worth it” was never a sound assumption. ASD’s Annual Cyber Threat Report 2024-25 puts numbers behind that. ASD’s ACSC responded to more than 1,200 cyber security incidents in FY2024-25, an 11 per cent increase on the year before. The average self-reported cost of cybercrime climbed across every size of business: up 14 per cent to $56,600 for small business, and up 55 per cent to $97,200 for medium business, a steeper rise than large organisations recorded.
Where the Gaps Actually Sit
What gets exploited in incidents like these is rarely sophisticated. It’s the fundamentals: unpatched applications and operating systems, missing multi-factor authentication on remote access, unrestricted administrative privileges, and application control gaps that let unapproved software run unchecked. These are the exact technical controls the Essential Eight was built to address, and they are exactly where mid-market environments tend to quietly lose visibility over time. A patch that fails silently on one machine. An MFA policy that never made it to a legacy account. An endpoint added six months ago that was never brought into scope.
Closing the Visibility Gap
Most organisations find out about gaps like these the way the three above may be finding out now, after the fact, when a leak site countdown starts. A point-in-time audit or an annual self-assessment tells you what your controls looked like on the day someone checked, not what they look like today, a limitation we’ve covered in more detail here.
What actually closes that gap is continuous, evidence-based verification: an ongoing check across every endpoint in your environment confirming whether your Essential Eight technical controls are genuinely in place and functioning, not an assumption carried over from last year’s review. It’s the difference between security coverage and security confidence, and it’s usually the gap that costs the most when it goes unaddressed.
The Gap These Three Have in Common
Twelve days and three unrelated sectors is a narrow window, but it’s a live one. Ransomware groups don’t choose targets for size or profile, they choose whichever control gap gives them a way in first.
If you want an honest, current read on where that gap might sit in your own environment, our team can walk you through it.