What reportedly happened
AC Small Maxwell & Co, a boutique accounting and advisory firm based in Grafton, NSW, and operating since 1916, was named by the SafePay ransomware group in late July. According to reporting from Cyber Daily, the threat actors claimed to have stolen data from the firm and threatened to publish it within days if a payment wasn't made. The firm offers accounting, taxation, financial planning, payroll administration, estate planning and SMSF services to a regional client base.
As of the most recent reporting, the threat actor hadn't provided any sample data or other evidence to support the claim, and the firm hadn't publicly confirmed a breach. Ransomware groups regularly list businesses on leak sites before any data is verified, partly as pressure tactics. Whether or not this particular claim holds up, the targeting pattern behind it is well established and worth paying attention to.
Why accounting firms keep showing up on these lists
This isn't an isolated case. Other Australian accounting firms have been named by ransomware groups over the past year, including a Victorian firm where internal documents were published after a Qilin ransomware attack, and a Queensland firm where client financial and banking data was posted online following a similar incident. Industry reporting citing the Office of the Australian Information Commissioner places legal, accounting and management services among the five most-affected sectors for data breach notifications.
The reason is straightforward. Accounting practices hold exactly the kind of data that's valuable to steal and easy to monetise: tax file numbers, bank account details, identity documents, superannuation records. Many of these firms are small, with IT budgets to match, which makes them a comparatively easy target next to a big four firm with a dedicated security team.
What this means for a firm like yours
The lesson here isn't "get a bigger budget," it's making sure the basics are actually in place: multi-factor authentication on every account that can reach client data, regular and tested backups that aren't reachable from a compromised computer, staff who know how to recognise a phishing attempt, and a plan for what happens in the first hour if something does go wrong.
None of this requires enterprise-level spending. It requires treating client tax and financial data with the same seriousness a bank would, because to the people targeting these firms, it's worth exactly the same amount either way.
