02 8987 4501  ·  0406 340 856
Google Reviews
Accounting

A small NSW accounting firm has been targeted by ransomware.

Published 2 August 2026

A ransomware group has claimed an attack on a century-old accounting and advisory firm in regional NSW, threatening to leak client data within days. The firm hasn't confirmed the claim. What's worth noting either way is who's being targeted, and why.

Why IT Service Centre
Since 2004Two decades supporting Sydney businesses
2-hour responseDuring business hours, sooner for urgent issues
One partnerSupport, security, networks and cloud, together

What reportedly happened

AC Small Maxwell & Co, a boutique accounting and advisory firm based in Grafton, NSW, and operating since 1916, was named by the SafePay ransomware group in late July. According to reporting from Cyber Daily, the threat actors claimed to have stolen data from the firm and threatened to publish it within days if a payment wasn't made. The firm offers accounting, taxation, financial planning, payroll administration, estate planning and SMSF services to a regional client base.

As of the most recent reporting, the threat actor hadn't provided any sample data or other evidence to support the claim, and the firm hadn't publicly confirmed a breach. Ransomware groups regularly list businesses on leak sites before any data is verified, partly as pressure tactics. Whether or not this particular claim holds up, the targeting pattern behind it is well established and worth paying attention to.

Why accounting firms keep showing up on these lists

This isn't an isolated case. Other Australian accounting firms have been named by ransomware groups over the past year, including a Victorian firm where internal documents were published after a Qilin ransomware attack, and a Queensland firm where client financial and banking data was posted online following a similar incident. Industry reporting citing the Office of the Australian Information Commissioner places legal, accounting and management services among the five most-affected sectors for data breach notifications.

The reason is straightforward. Accounting practices hold exactly the kind of data that's valuable to steal and easy to monetise: tax file numbers, bank account details, identity documents, superannuation records. Many of these firms are small, with IT budgets to match, which makes them a comparatively easy target next to a big four firm with a dedicated security team.

What this means for a firm like yours

The lesson here isn't "get a bigger budget," it's making sure the basics are actually in place: multi-factor authentication on every account that can reach client data, regular and tested backups that aren't reachable from a compromised computer, staff who know how to recognise a phishing attempt, and a plan for what happens in the first hour if something does go wrong.

None of this requires enterprise-level spending. It requires treating client tax and financial data with the same seriousness a bank would, because to the people targeting these firms, it's worth exactly the same amount either way.

Not sure where you'd stand?

Let's check your practice's setup.

A short review usually turns up the two or three things worth fixing first. Better to find them now than after a claim like this one turns real.

Start a conversation