Ransomware in Australia 2026
Ransomware remains the most disruptive cybercrime threat facing Australian organizations, according to the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC). Attackers now routinely combine file encryption with data theft, threatening to publish stolen records publicly unless a ransom is paid, a tactic known as double extortion that has become the dominant attack model across the country in 2026. From small retailers to hospitals and universities, no sector has proven immune to this escalating threat.
This report breaks down the verified 2026 ransomware statistics behind that trend, covering how many Australian organizations have been targeted, what these attacks are costing businesses, and how attackers are getting in. All figures below are sourced from the ASD’s Annual Cyber Threat Report, the National Anti-Scam Centre, and independent industry surveys, giving an accurate picture of the ransomware landscape Australian businesses are navigating this year.
Interesting Facts About Ransomware in Australia 2026
| Category | Data Point |
|---|---|
| Ransomware incidents responded to by ACSC (FY2024-25) | 138 |
| Ransomware share of all cyber incidents | 11% |
| Ransomware victims with data posted online | 35% |
| Organizations targeted by ransomware in past 12 months | 35% |
| Large organizations (1,000+ employees) targeted | 49% |
| Average self-reported cybercrime cost overall | $36,633 |
| Average reported loss per business | $80,850 |
| Large organization average reported loss | $202,700 (up 219%) |
| Total cybercrime reports (FY2024-25) | 84,700 |
| Critical infrastructure notifications | 190+ (up 111%) |
| Businesses that disclosed ransom payments since June 2025 | 75+ |
Source: Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC); RSM Australia; National Anti-Scam Centre
These figures confirm that ransomware has moved from an occasional nuisance to a routine cost of doing business in Australia. The ACSC responded to 138 ransomware incidents during FY2024-25, and separate industry research from RSM Australia found that 35% of medium and large organizations had been targeted by ransomware or extortion attempts in just the past 12 months, a figure that climbed to 49% among organizations with more than 1,000 employees. The financial toll has grown just as sharply, with average reported losses for large organizations jumping 219% to $202,700 per incident.
Perhaps most telling is the 35% of ransomware victims who had their stolen data posted online after an attack, evidence that double extortion has become the industry standard rather than the exception. With 84,700 total cybercrime reports filed through ReportCyber during the year, equivalent to one report roughly every six minutes, and critical infrastructure notifications more than doubling to over 190, Australian organizations are facing a threat environment that continues to intensify even as awareness and defensive investment both increase.
Ransomware Incidents in Australia Statistics 2026
ACSC CYBER INCIDENT RESPONSE (FY2024-25)
Total Cyber Security Incidents | ███████████████ 1,200+
Ransomware Incidents | ████ 138
Malicious Activity Notifications| ████████████████████ 1,700+
| Metric (FY2024-25) | Figure |
|---|---|
| Total cyber security incidents responded to | 1,200+ (up 11%) |
| Ransomware incidents responded to | 138 |
| Ransomware share of all cyber incidents | 11% |
| Ransomware incidents discovered via ACSC proactive contact | 39% |
| Malicious activity notifications issued | 1,700+ (up 83%) |
Source: ASD’s ACSC, Annual Cyber Threat Report 2024-25
The ASD’s ACSC responded to more than 1,200 cyber security incidents during FY2024-25, an 11% increase from the previous year, with ransomware accounting for 11% of that total through 138 separate incidents. Notably, 39% of these ransomware incidents were only discovered because the ACSC proactively contacted the affected organization to warn them of suspicious activity, rather than the organization identifying the compromise on its own, a pattern that highlights persistent gaps in detection capability across much of the Australian business community.
The scale of proactive threat monitoring also grew substantially, with the ACSC issuing more than 1,700 notifications of potentially malicious cyber activity, an 83% jump from the prior year. This increase reflects both a genuinely more active threat landscape and an expansion of the ACSC’s own monitoring capacity, meaning organizations are being warned about potential compromises earlier and more frequently than in previous years, even as the underlying volume of ransomware attempts continues to climb.
Ransomware Business Impact Statistics in Australia 2026
ORGANIZATIONS TARGETED BY RANSOMWARE (PAST 12 MONTHS)
All Organizations Surveyed | ██████████████████ 35%
Organizations with 1,000+ Staff | ████████████████████████ 49%
| Organization Size | % Targeted by Ransomware/Extortion |
|---|---|
| All surveyed organizations | 35% |
| Organizations with 1,000+ employees | 49% |
| Survey base | 155 medium and large organizations |
Source: RSM Australia 2026 Cyber Security Report
The RSM Australia 2026 Cyber Security Report, based on a survey of business and IT leaders from 155 medium and large organizations, found that 35% had been targeted by ransomware or an extortion attempt within the past 12 months. That already substantial figure rose sharply for larger enterprises, with 49% of organizations employing more than 1,000 people reporting they had been targeted, confirming that scale and visibility make an organization a more attractive target rather than offering meaningful protection.
This size-based disparity carries important implications for how Australian businesses should think about ransomware risk. Larger organizations typically hold more valuable data, operate more complex and interconnected systems, and present a bigger potential payout for attackers running a ransom negotiation, all factors that likely explain why nearly half of the largest surveyed organizations had faced a targeted attempt. Smaller businesses are far from safe, but the data suggests attackers are increasingly concentrating effort on enterprises where a successful breach yields the greatest financial return.
Ransomware Financial Cost Statistics in Australia 2026
AVERAGE REPORTED CYBERCRIME LOSS BY ORGANIZATION SIZE
Small Business | ████████████████ $56,600
Medium Enterprise | ███████████████████████████ $97,200
Large Organization| ████████████████████████████████ $202,700
| Organization Size | Average Reported Loss | YoY Change |
|---|---|---|
| Overall (self-reported, all reporters) | $36,633 | — |
| All businesses (average) | $80,850 | +50% |
| Small business | $56,600 | +14% |
| Medium enterprise | $97,200 | +55% |
| Large organization | $202,700 | +219% |
Source: ASD’s ACSC, Annual Cyber Threat Report 2024-25; National Anti-Scam Centre
The financial cost of cybercrime, including ransomware, rose sharply across every category of Australian organization during FY2024-25. The average reported loss across all businesses climbed 50% to $80,850 per incident, but the increases were far steeper for larger organizations, where average losses jumped 219% to $202,700. Medium enterprises saw losses rise 55% to $97,200, while small businesses faced a comparatively smaller but still significant 14% increase to $56,600 per reported incident.
These figures represent only the self-reported direct financial losses captured through official channels, and the ACSC has repeatedly noted that the vast majority of cybercrime goes unreported entirely, meaning the true economic cost is almost certainly higher. The steep rise in losses for large organizations in particular suggests that attackers are becoming more sophisticated at extracting maximum value once they gain access to an enterprise network, whether through larger ransom demands, more extensive data theft, or prolonged operational disruption before systems can be restored.
Ransomware Data Extortion Statistics in Australia 2026
RANSOMWARE VICTIMS WITH DATA POSTED ONLINE
Data Published After Attack | ████████████████████ 35%
| Metric | Figure |
|---|---|
| Ransomware victims with stolen data posted online | 35% |
| Dominant attack model in 2026 | Double/triple extortion |
| Payment method typically demanded | Cryptocurrency |
Source: ASD’s ACSC, Annual Cyber Threat Report 2024-25
Modern ransomware attacks in Australia now routinely involve more than simple file encryption. In 35% of ransomware cases, victims had their stolen data published online, evidence of the double extortion model where attackers steal sensitive data before encrypting systems, then threaten public release of that data to pressure payment even from organizations capable of restoring their systems from backup. Some attackers have escalated further into triple extortion, adding direct threats against customers or individuals named in the stolen data as additional leverage.
Payment demands in these cases are almost universally made in cryptocurrency, which complicates both tracing the funds and prosecuting the perpetrators, many of whom operate from overseas jurisdictions with limited law enforcement cooperation. For context on how significant the cryptocurrency angle has become across Australian cybercrime broadly, the crypto fraud statistics tracked in the US market show a similar pattern of criminals favoring digital currency specifically because of the anonymity and cross-border speed it offers, dynamics that apply just as strongly to ransomware payment demands in Australia.
Ransomware Attack Vector Statistics in Australia 2026
RANSOMWARE ENTRY POINTS
Exploited Vulnerabilities | █████████████████ 28-32%
Phishing Emails | ██████████████ 24%
Compromised Credentials | █████████████ 21-23%
| Entry Point | % of Ransomware Attacks |
|---|---|
| Exploited vulnerabilities (unpatched software/devices) | 28-32% |
| Phishing emails | 24% |
| Compromised credentials | 21-23% |
Source: Industry-reported data compiled from Australian cyber security vendors
The most common way attackers gain initial access to Australian networks is through exploited vulnerabilities in unpatched software or devices, accounting for between 28% and 32% of ransomware attacks. Phishing emails that trick staff into clicking malicious links or opening infected attachments make up another 24% of attacks, while compromised credentials, often purchased from dark web markets or harvested through earlier phishing campaigns, account for a further 21% to 23%. Exposed remote desktop protocol connections and supply chain attacks through trusted vendors round out the remaining significant entry points.
This breakdown highlights why basic cyber hygiene remains so central to ransomware prevention despite attackers’ growing sophistication. Businesses carrying adequate cyber-related business insurance coverage alongside strong patching discipline and staff phishing awareness training address the three largest entry vectors simultaneously, since unpatched systems, successful phishing, and compromised credentials together account for the large majority of successful ransomware intrusions in the Australian data.
Ransomware Critical Infrastructure Statistics in Australia 2026
CRITICAL INFRASTRUCTURE NOTIFICATIONS (YoY)
Previous Year | ████████ 90
FY2024-25 | ████████████████████ 190+
| Metric | Figure |
|---|---|
| Critical infrastructure notifications issued | 190+ |
| Year-over-year increase | 111% |
| Most targeted sectors | Healthcare, Education, Logistics and Transport, Government |
Source: ASD’s ACSC, Annual Cyber Threat Report 2024-25
Critical infrastructure operators faced a dramatic escalation in targeting during FY2024-25, with the ACSC issuing more than 190 notifications of potential malicious cyber activity to critical infrastructure entities, a 111% increase from the previous year. Healthcare organizations remained heavily targeted for their sensitive patient data, with ransomware attacks causing service outages and delays in care delivery. Education institutions, including schools and universities, faced data breaches and ransomware incidents that disrupted learning and exposed student records.
Logistics and transport operators also featured prominently among targeted sectors, with attacks on supply chain systems leading to operational delays and financial losses that rippled beyond the immediately affected organization. This concentration of attacks on essential services reflects a deliberate strategy by cybercriminals, who understand that organizations providing critical services face intense pressure to restore operations quickly, making them more likely to pay a ransom rather than endure prolonged downtime that could affect public safety or essential service delivery.
Ransomware Cybercrime Reporting Statistics in Australia 2026
TOTAL CYBERCRIME REPORTS (FY2024-25)
Reports Filed | ████████████████████████████████████ 84,700
| Metric | Figure |
|---|---|
| Total cybercrime reports (ReportCyber) | 84,700 |
| Average reporting frequency | One report every 6 minutes |
| Total scam losses reported in 2025 | $2.18 billion |
| DoS/DDoS incidents responded to | 200+ (up 280%+) |
Source: ASD’s ACSC; National Anti-Scam Centre, Targeting Scams Report
Australians filed 84,700 cybercrime reports through ReportCyber during FY2024-25, equivalent to one report roughly every six minutes throughout the entire year. This sits within a broader national picture of rising cybercrime losses: the National Anti-Scam Centre’s Targeting Scams Report found Australians lost a combined $2.18 billion to scams and cybercrime in 2025, an increase of 7.8% from the previous year, drawing on data pooled from Scamwatch, ReportCyber, the Australian Financial Crimes Exchange, and other sources.
Denial-of-service attacks also surged as part of this broader trend, with the ACSC responding to more than 200 denial-of-service and distributed denial-of-service incidents, a jump of more than 280% compared with the previous reporting period. While these attacks differ from ransomware in that they aim to disrupt availability rather than extort payment directly, the sharp increase reflects the same underlying trend of Australian organizations facing a more crowded and aggressive cyber threat landscape across nearly every attack category tracked by the ACSC.
Ransomware Payment Disclosure Statistics in Australia 2026
RANSOMWARE PAYMENT DISCLOSURES SINCE JUNE 2025
Businesses That Disclosed Payments | ████████████████████ 75+
| Metric | Figure |
|---|---|
| Businesses that disclosed ransom payments since June 2025 | 75+ |
| Mandatory disclosure threshold | >$3 million annual turnover |
| Businesses required to report | Minority of all Australian businesses |
Source: ITnews; Australian ransomware payment reporting obligations
More than 75 Australian businesses have formally disclosed payments made to ransomware groups since June 2025, when mandatory reporting obligations came into effect for businesses with more than $3 million in annual turnover. Because this disclosure requirement only applies to a minority of Australian businesses by revenue threshold, the true number of organizations that have paid a ransom is almost certainly far higher than the publicly disclosed figure suggests, since smaller businesses below the turnover threshold face no legal obligation to report a payment at all.
The financial consequences of these payments compound the broader costs already documented for Australian businesses. For organizations weighing whether to pay a ransom against the cost of rebuilding systems from scratch, the business bankruptcy statistics tracked in the US market offer a useful comparison point on how financial shocks of this scale can push already-strained businesses toward insolvency, a risk that Australian small and medium enterprises face acutely given that many operate with limited cash reserves and no dedicated cyber insurance coverage to absorb the cost of a major ransomware incident.
Disclaimer: The data research report we present here is based on information found from various sources. We are not liable for any financial loss, errors, or damages of any kind that may result from the use of the information herein. We acknowledge that though we try to report accurately, we cannot verify the absolute facts of everything that has been represented.
