Ransomware Gangs Are Naming Ordinary Australian Businesses: What Perth SMBs Should Do Now

Three ransomware groups have claimed attacks on ordinary Australian businesses in September 2026 — not banks or hospitals. Here's why Perth SMBs need an incident response plan before it happens, not after. From Computer Mechanics, Perth IT specialists since 1997.

Garry BloomGarry Bloom · Founder & CEO
23 September 2026
5 min read
Cybersecurity
Ransomware
Incident Response
Perth Business
An investigation board representing a ransomware incident response

In the space of three weeks this September, ransomware groups have posted extortion claims against a South Australian farm machinery supplier, a hardware conglomerate, and a commercial kitchen manufacturer in New South Wales. None of them are large enough to have made national news under normal circumstances. All of them are exactly the size and profile of a typical Perth SMB. If your business doesn't already have a written incident response plan, that's the actual takeaway: decide now, while nothing is on fire, who you call first and what happens in the first hour — because new Australian research shows most businesses haven't.

Three claims in three weeks

Ransomware groups increasingly run their own "leak sites" — pages on the dark web where they name victims and threaten to publish stolen data unless a ransom is paid. Three recent postings show how far down the size scale this now reaches:

  • 4 September — the newly emerged Storm group listed a South Australian farm machinery supplier, publishing sample documents as proof and threatening a full data release.
  • 15 September — the group calling itself The Gentlemen claimed an attack on an Australian hardware conglomerate, posting an extortion notice threatening to leak sensitive data.
  • 16 September — the Kairos group named a commercial kitchen manufacturer in New South Wales on its leak site.

None of these three claims had been publicly confirmed by the businesses involved, regulators, or mainstream media as this article was written. That unconfirmed status is worth sitting with for a moment, because it's not actually the reassurance it sounds like.

Why "unconfirmed" doesn't mean "not real"

A leak-site posting is itself the attack's second stage. The group has already been inside the network, already exfiltrated whatever it wanted, and is now using public pressure — customers, suppliers and staff seeing the company's name on a leak site — to push toward payment. Whether the business confirms it publicly changes nothing about what already happened; it only changes how the story is managed from here. For a small business without a plan, that management happens in a panic, in public, in real time.

This is also precisely why "we're too small to be a target" keeps being wrong. None of the three businesses above are household names. A farm machinery dealer and a commercial kitchen manufacturer are ordinary trading businesses, not the kind of high-profile target that makes headlines — which is exactly the profile modern ransomware crews go after, because smaller businesses are less likely to have tested backups, a written response plan, or 24/7 monitoring.

The research backs it up

New research commissioned by Optus and conducted by Ipsos in 2026 surveyed Australian sole traders and small businesses and found:

  • Only 40% of small businesses prioritise cybersecurity.
  • 35% have already experienced a cyberattack.
  • 60% have no cyber response plan at all.

Put those together and the picture is stark: more than a third of small businesses have already been hit, but nearly two-thirds still haven't decided in advance what they'll do if it happens again — or happens to them for the first time.

What an incident response plan actually contains

A response plan doesn't need to be a fifty-page document. For a business our size, it needs to answer a short list of questions clearly enough that any staff member can act on it under pressure:

Who gets called first

Your IT provider, your cyber insurer (if you have a policy), and your lawyer's contact details, written down somewhere that doesn't depend on the compromised network to access.

What NOT to do

Don't unplug, reformat, or "just delete the weird file" before anyone qualified has looked at it. Isolating a machine from the network is usually right; wiping it destroys the evidence needed to understand how the attacker got in and whether they're still inside anywhere else.

Whether your backups actually work

A backup that's never been test-restored is a hope, not a plan. If a server dies or gets encrypted, the business needs to know — in advance, not on the day — how long a restore actually takes and how much data would be lost.

Who decides on paying a ransom

This should never be improvised by whoever happens to answer the phone at 2am. Decide the process — legal advice, insurer involvement, law enforcement notification — before there's a countdown timer on screen.

How you'll talk to staff and customers

A short, pre-agreed line for "what do we tell people" removes one more decision from an already overloaded moment, and stops mixed messages going out while the situation is still being assessed.

We've written before about what we actually do in the first hour of a ransomware incident — that post covers the response itself. This one is about the part that happens before any of that: deciding the plan while you have the luxury of time to think clearly.

Perth businesses aren't exempt

Ransomware crews don't check postcodes. The businesses named on leak sites this month were spread across South Australia and New South Wales, but there's nothing about a farm machinery supplier or a kitchen manufacturer that makes them more attractive targets than a Perth accounting firm, trades business, or medical practice. The profile that matters to an attacker is opportunity, not location: outdated software, no multi-factor authentication, and no tested backup.

Getting started

If your business has been meaning to formalise an incident response plan but hasn't got around to it, this is as good a prompt as any. We can help assess where the gaps are — from backup and disaster recovery through to broader IT security — and put a written plan in place before it's needed rather than while it's being tested for real. Computer Mechanics has supported Perth businesses since 1997; see why local businesses choose us to work through cybersecurity planning properly.

Garry Bloom
Written by
Garry Bloom
Founder & CEO · 29 years in IT

Garry founded Computer Mechanics — the business behind IT Support Perth — in 1997. With 29 years in IT management and support across internal and external service environments, he leads the team's technical direction and its cybersecurity and managed-IT strategy for Perth businesses.

Meet the IT Support Perth team →
Garry Bloom
23 September 2026
5 min read
Cybersecurity
Ransomware
Incident Response
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Critical Flaw in Check Point's Small-Business Firewall: What to Patch This Week

Check Point has patched two critical, unauthenticated RCE flaws (CVSS 9.8) in its VPN gateways, including the Spark Firewall used by many small offices. Here's what Perth businesses should check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

September Patch Broke Remote Desktop on Windows Server: What Perth Businesses Must Check

September's Patch Tuesday fixed a critical, unauthenticated Remote Desktop flaw — then the same update broke RDS on Windows Server, forcing hard reboots. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Passkeys Are Now Default in Microsoft 365: What Perth Businesses Must Check

Microsoft has switched Entra ID to passkeys by default and is retiring SMS and voice sign-in codes by February 2027. Here's what Perth businesses need to check now. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Ransomware Hits a Perth Office: What We Do in the First Hour
Cybersecurity
Ransomware

Ransomware Hits a Perth Office: What We Do in the First Hour

A representative walkthrough of how we respond in the first hour of a ransomware attack on a Perth small business — contain, assess, protect the backups, and start recovery — and why that hour is really decided months earlier. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/3/2026
Critical Flaw in Check Point's Small-Business Firewall: What to Patch This Week
Cybersecurity
Firewall

Critical Flaw in Check Point's Small-Business Firewall: What to Patch This Week

Check Point has patched two critical, unauthenticated RCE flaws (CVSS 9.8) in its VPN gateways, including the Spark Firewall used by many small offices. Here's what Perth businesses should check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/21/2026
September Patch Broke Remote Desktop on Windows Server: What Perth Businesses Must Check
Cybersecurity
Patch Management

September Patch Broke Remote Desktop on Windows Server: What Perth Businesses Must Check

September's Patch Tuesday fixed a critical, unauthenticated Remote Desktop flaw — then the same update broke RDS on Windows Server, forcing hard reboots. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/18/2026