Call IT Assessment

Qilin Ransomware Is Hunting Australian Accounting Firms — And the Privacy Act Just Raised the Stakes

Published: 25 July 2026 | Last updated: 25 July 2026 | Reading time: 12 minutes | Author: AyeTech Cyber Security Team

⚠️ Active Threat to Australian Professional Services

Qilin — currently the most active ransomware operation in the world — has listed 17 Australian victims in 2026, and accounting firms are being named on its leak site with client financial data published. If your firm holds client tax, financial or legal records and relies on an internet-facing VPN or firewall for remote access, you are in the target profile.

Key Takeaways

  • The threat is local and current: Qilin has listed 17 Australian victims in 2026, including small accounting firms whose client financial details were published on the dark web
  • How they get in: Internet-facing firewalls and VPNs (Cisco ASA, Fortinet, SonicWall, Palo Alto CVE-2026-0257, VPN bypass CVE-2026-50751) and stolen credentials — then backups are deleted and data exfiltrated, sometimes within 48 hours
  • The stakes changed on 1 July: Accountants, lawyers, conveyancers and real estate agents are now covered by the Privacy Act — a breach at your firm is a notifiable regulatory event, not just a bad week
  • Backups alone are not enough: Qilin steals data before encrypting, so recovery does not prevent your clients’ records being published
  • Every entry vector has a defence: Rapid patching, MFA, immutable backups, EDR and 24/7 monitoring map one-to-one against Qilin’s attack chain

Qilin: The Busiest Ransomware Operation in the World

If you have only got room in your head for one ransomware name in 2026, make it Qilin. Multiple threat intelligence trackers rank Qilin as the most active ransomware-as-a-service (RaaS) operation in the world right now, with roughly 1,500 claimed victims since it launched — more than 500 of them in 2026 alone.

Part of the reason for that surge is consolidation. As law enforcement disrupted LockBit, RansomHub and ALPHV/BlackCat, their affiliates — the criminals who actually carry out the attacks — needed somewhere to go. Many of them moved to Qilin, bringing their tooling and experience with them. We covered the RaaS model in our earlier piece on ransomware targeting Australian SMEs; Qilin is that model at industrial scale.

Qilin attacks follow the double-extortion playbook: affiliates steal data first, then encrypt systems. Victims who refuse to pay are listed on Qilin’s dark web leak site and their data is published. That second lever is what makes the current campaign against professional services firms so damaging — and it is why this is not just another ransomware story.

#1 Most active ransomware operation globally entering 2026
500+ Victims claimed by Qilin in 2026 alone
17 Australian victims listed by Qilin this year
$56,600 Average self-reported cost of cybercrime per small business (ASD)

The Australian Victims: Accounting Firms on the Leak Site

This is not a threat happening to someone else, somewhere else. Cyber Daily reports Qilin has listed 17 Australian victims in 2026, at one point claiming four Australian businesses in a single month. Professional services firms — accounting, financial services and legal practices — feature consistently on the list.

Two confirmed accounting-sector cases show how this plays out:

  • A Brisbane accounting firm confirmed a cyber incident involving unauthorised third-party access to part of its IT environment after being listed on Qilin’s leak site. The published dataset reportedly included financial details belonging to several clients alongside company data. The firm notified affected individuals and reported the incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner (OAIC).
  • A Victorian accounting firm was listed as a Qilin victim with internal documents posted to the dark web.

Note what happened in the first case: it was not just the firm’s own data that ended up on the dark web — it was client financial records. When an accounting firm is breached, every client whose tax file number, bank details or financial statements sat in that practice management system becomes a victim too. That is the multiplier effect that makes professional services firms such attractive targets, and it is exactly the scenario the ACSC warns about as cybercrime reports arrive every six minutes nationally.

Why Professional Services Firms Are the Target

From an attacker’s point of view, a suburban accounting or legal practice is close to the perfect victim. Three things line up:

  • Data density. A 15-person accounting firm holds the complete financial identity of hundreds of individuals and businesses: TFNs, bank accounts, payroll records, trust account details, financial statements. A law firm holds conveyancing files, settlement details, and matters clients would pay to keep private. Per gigabyte, few businesses hold more extortion-ready data.
  • Thin defences. Most firms of this size have no dedicated IT security staff, no 24/7 monitoring, and remote access that was set up during COVID and never hardened. The partners are experts in tax or law — not in firewall firmware versions. We covered this asymmetry in why small businesses need managed IT, and it applies doubly to firms whose stock-in-trade is sensitive data.
  • Pressure to pay. A firm locked out of its practice management system during BAS season, or facing publication of client records, is under enormous pressure to make the problem go away quietly. Attackers know professional reputations are the product — and they price ransoms accordingly.

Deadline pressure makes it worse. Tax season, EOFY lodgements and settlement dates give attackers natural leverage: every day of downtime has a visible, dated cost.

How Qilin Actually Breaks In

Qilin affiliates are not wizards. Across incident reports from 2025 and 2026, the same handful of entry vectors appear again and again — and every one of them is defensible.

1. Internet-facing firewalls and VPNs

The dominant entry point is the very device meant to keep attackers out. Through 2025 and 2026, Qilin-linked intrusions have repeatedly started with abuse of Cisco ASA, Fortinet and SonicWall appliances. In 2026 the list grew: Arctic Wolf documented Qilin affiliates exploiting the PAN-OS authentication bypass CVE-2026-0257 against Palo Alto firewalls and moving rapidly from perimeter compromise to domain-wide encryption, while a separate VPN authentication bypass, CVE-2026-50751, has been actively exploited since at least early May.

The pattern should sound familiar — it is the same class of perimeter-device vulnerability behind incidents we have covered before, and the reason we patch critical network device CVEs across all managed sites within 24 hours. An unpatched firewall is not a defence; it is a door.

2. Stolen credentials and Initial Access Brokers

The second route is simpler: log in. Qilin affiliates buy working VPN and RDP credentials from Initial Access Brokers — criminals who compromised the network weeks or months earlier and sell the access on. Other credentials come from phishing. If your firm’s remote access accepts a username and password without multi-factor authentication, an attacker with a bought or phished credential walks straight in as a legitimate user, and no firewall rule stops them.

3. Then it moves fast

Once inside, Qilin affiliates follow a tight sequence: harvest more credentials, locate and delete every backup they can reach, exfiltrate the most sensitive data, then launch encryption — in some incidents within a day or two of initial access. The backup deletion step is deliberate: it removes your recovery option before you know you are under attack. And because data is stolen before encryption, restoring from backup solves only half your problem — the extortion over publication remains.

The 48-Hour Window

In fast Qilin intrusions, the gap between first access and full encryption can be under 48 hours — much of it outside business hours. A firm that checks its systems Monday to Friday, 9 to 5, can be breached Friday evening and fully encrypted before anyone opens a laptop on Monday. This is why 24/7 monitoring and EDR are not enterprise luxuries; they are the difference between an alert and an incident.

What Changed on 1 July: Your Breach Is Now a Regulatory Event

Here is the part of this story that most ransomware coverage misses. On 1 July 2026, the AML/CTF tranche 2 reforms took effect and pulled more than 100,000 Australian small businesses — accountants, lawyers, conveyancers, real estate agents and dealers in high-value goods — under the Privacy Act for the first time, regardless of turnover. We covered the details in our guide to the July 2026 privacy changes.

Read that list again, then look at Qilin’s victim list. They are the same professions.

Before 1 July, a small accounting firm hit by ransomware faced a terrible operational and reputational problem, but many were exempt from the Privacy Act under the old small business threshold. Now the obligations arrive with the breach:

  • Notifiable Data Breaches scheme. If personal information is accessed or disclosed without authorisation and serious harm is likely, the firm must assess the breach and notify both the OAIC and affected individuals. Stolen client financial records published on a leak site is close to a textbook trigger.
  • Reasonable steps to secure personal information. The Privacy Act expects covered entities to take reasonable steps to protect the data they hold. A firm breached through an unpatched, years-old VPN vulnerability will find that conversation with the regulator uncomfortable.
  • Ransom payment reporting. Separately, businesses with turnover above $3 million that pay a ransom must report the payment to the Australian Government within 72 hours, with civil penalties for failing to do so.

The Brisbane firm’s response — notifying affected individuals and reporting to the ACSC and the OAIC — is the template every newly covered firm now has to be ready to follow. The question to ask yourself is simple: if it happened to your firm this weekend, would you know what to report, to whom, and within what deadline?

Not Sure If Your Firm Could Withstand a Qilin-Style Attack?

AyeTech runs security assessments built for professional services firms — covering your remote access, patching, backups, monitoring and Privacy Act readiness in one review.

Book a Security Assessment

The Defence Checklist, Mapped to the Attack Chain

The good news buried in the threat intelligence: Qilin’s playbook is consistent, which means the defence can be too. Each stage of the attack has a specific counter:

Qilin Attack Stage The Defence What It Looks Like in Practice
Exploiting firewall / VPN vulnerabilities Rapid patch management Critical perimeter-device patches applied within days of vendor advisories — hours for actively exploited CVEs. Retire remote access you no longer use.
Logging in with stolen credentials MFA everywhere + conditional access Phishing-resistant MFA on every VPN, RDP, email and cloud login. No exceptions for partners or “temporary” accounts.
Deleting backups before encryption Immutable, offline-capable backups Backups the attacker cannot reach or alter from inside your network, with restores actually tested — a backup that has never been restored is a hope, not a backup.
Credential harvesting and lateral movement EDR + 24/7 monitoring Endpoint detection on every device, watched around the clock, so the intrusion is caught in the dwell time — before encryption, not after.
Data exfiltration and extortion Least privilege + network monitoring Staff access only the client data they need; unusual outbound transfers raise alerts. Less reachable data means less to steal.
The aftermath Incident response plan with NDB obligations built in A written, rehearsed plan that includes OAIC notification steps, ACSC reporting, and client communications — decided calmly in advance, not at 2am mid-incident.

If you want the deeper how-to on the fundamentals, our ransomware prevention guide walks through each control. And the controls themselves are not new — they are substantially the Essential Eight (soon to evolve into the Essentials series) applied with discipline.

The Honest Assessment

Almost no 5–50 person firm can run rapid perimeter patching, phishing-resistant MFA, immutable backups, EDR and 24/7 monitoring on its own — and Qilin’s affiliates are counting on exactly that. This layered defence is what a managed service provider does at scale, across hundreds of clients, for a predictable monthly fee that is a rounding error against the true cost of one successful attack.

Protect Your Firm — and Your Clients’ Data

AyeTech provides managed cyber security for Australian professional services firms: 24/7 monitoring, rapid patching, hardened remote access, immutable backups and incident response — aligned to the Essential Eight and your new Privacy Act obligations.

Get a Security Assessment Explore Our Cyber Security Services

Or call us on 02 9188 8000 to speak with a security specialist today.

Frequently Asked Questions

What is Qilin ransomware?

Qilin is a ransomware-as-a-service (RaaS) operation, currently ranked the most active ransomware group in the world. It leases its ransomware to affiliates who carry out attacks and share the proceeds. Qilin has claimed roughly 1,500 victims since launch — over 500 in 2026 alone — after absorbing affiliates from disrupted operations including LockBit, RansomHub and ALPHV/BlackCat. Attacks use double extortion: data is stolen before encryption, and non-payers have their data published on Qilin’s dark web leak site.

Which Australian businesses has Qilin ransomware attacked?

Qilin has listed 17 Australian victims in 2026, according to Cyber Daily. Confirmed accounting-sector cases include a Brisbane accounting firm — which confirmed a cyber incident after being listed, with published data reportedly including client financial details — and a Victorian accounting firm whose internal documents were posted to the dark web. Professional services firms, including accounting, financial services and legal practices, feature consistently among the targets.

How does Qilin ransomware get into a network?

Mostly through internet-facing firewalls and VPNs, and stolen credentials. Affiliates have abused Cisco ASA, Fortinet and SonicWall devices, exploited the PAN-OS authentication bypass CVE-2026-0257, and actively exploited the VPN bypass CVE-2026-50751 since at least May 2026. Access is also bought from Initial Access Brokers or gained with phished credentials against RDP and VPN endpoints. Once inside, affiliates harvest credentials, delete reachable backups, exfiltrate data and encrypt — sometimes within 48 hours.

Why are accounting firms being targeted by ransomware?

They combine maximum data value with minimum defences. A small firm holds tax file numbers, bank details, payroll and financial statements for hundreds of clients — ideal for double extortion — while typically having no security staff, no 24/7 monitoring, and remote access that was never hardened. Deadline pressure around tax season and lodgements adds leverage for attackers.

Do accountants have to report a ransomware attack under the Privacy Act?

In most cases now, yes. Since 1 July 2026, accountants, lawyers, conveyancers, real estate agents and dealers in high-value goods fall under the Privacy Act regardless of turnover. If a breach involving personal information is likely to cause serious harm, the Notifiable Data Breaches scheme requires notifying the OAIC and affected individuals. Separately, businesses with turnover above $3 million that pay a ransom must report the payment within 72 hours. See our guide to the July 2026 privacy changes for the full picture.

We have backups. Are we safe from Qilin?

Backups are necessary but not sufficient, for two reasons. First, Qilin affiliates deliberately locate and delete every backup they can reach before encrypting — so backups must be immutable or offline to survive. Second, Qilin steals data before encryption: backups restore your systems, but they do not prevent your clients’ records being published on a leak site. Early detection and hardened access matter as much as recovery.

Is it illegal to pay a ransomware ransom in Australia?

Paying is not itself illegal, but the Australian Government strongly discourages it, payment may breach sanctions law if the recipient is sanctioned, and businesses with turnover above $3 million must report any ransom payment within 72 hours or face civil penalties. Payment also guarantees nothing — stolen data may still be leaked or sold, and paying marks you as a willing payer.

What should a small firm do first, this week?

Four things, in order: confirm your firewall and VPN firmware are current (and retire remote access you no longer use); switch on MFA for every VPN, RDP, email and cloud login; verify you have at least one backup an attacker inside your network could not delete, and test-restore it; and check whether your firm came under the Privacy Act on 1 July — if so, make sure someone owns the breach notification process. If you cannot confidently do all four in-house, that is the signal to bring in a managed provider.

Are law firms being hit by Qilin too?

Legal practices appear consistently in the professional services sector trend data for Qilin targeting, alongside accounting and financial services. The named, confirmed Australian victims in 2026 reporting are accounting firms, but the target profile — sensitive client data, thin IT defences, reputational pressure to pay — applies equally to legal and conveyancing practices, which also came under the Privacy Act on 1 July 2026.

How does an MSP actually help against ransomware?

A managed service provider runs the layered defence no small firm can staff alone: perimeter patches applied within hours of critical advisories, MFA and conditional access enforced tenant-wide, immutable backups with tested restores, EDR on every endpoint watched 24/7, and a rehearsed incident response plan that includes regulator notification. AyeTech delivers this from $149 per user per month — against an average small business cybercrime cost of $56,600 per incident.

What is double extortion ransomware?

A model where attackers steal a copy of your data before encrypting your systems, giving them two pressure points: pay for a decryption key, and pay again to stop the stolen data being published or sold. Qilin runs this as standard — non-payers are listed on its dark web leak site and their data released. It defeats the assumption that good backups alone make you safe: backups restore systems, but they cannot un-steal data.

How much does a ransomware attack cost an Australian small business?

ASD puts the average self-reported cost of cybercrime for a small business at $56,600 per report — and ransomware runs far higher. With average downtime around 21 days, plus forensics, rebuilds, client notification, legal advice and potential penalties, the true cost for a 30-person firm commonly reaches $300,000 to over $1 million, before counting lost clients and reputation.

Who do I report a ransomware attack to in Australia?

The ACSC via ReportCyber at cyber.gov.au or the hotline 1300 CYBER1 (1300 292 371). If personal information was involved and serious harm is likely, notify the OAIC and affected individuals under the Notifiable Data Breaches scheme. If your turnover exceeds $3 million and you pay a ransom, report the payment to the Australian Government within 72 hours. Also notify your cyber insurer immediately and, where client funds are at risk, your bank.

What should I do in the first hour of a ransomware attack?

Isolate affected systems — disconnect them from the network and internet — but do not wipe or rebuild anything yet: logs and forensic evidence matter for recovery and regulatory reporting. Do not contact the attackers or pay anything. Call your IT provider or incident response team, verify your backups are intact and disconnected, report to the ACSC on 1300 292 371, and start a written timeline — you will need it for insurers and the OAIC.

Does cyber insurance cover ransomware in Australia?

Most policies cover ransomware response — forensics, recovery, business interruption, sometimes ransom payments — but coverage depends on the controls you declared. Insurers increasingly require MFA, EDR, tested backups and patching as policy conditions, and claims can be denied if questionnaire answers were inaccurate or controls lapsed. An incident is exactly when you discover whether the controls you attested to were actually in place.

What is an Initial Access Broker?

A criminal who specialises in breaking into networks — via VPN vulnerabilities, phished credentials or exposed RDP — and sells that access to ransomware affiliates rather than using it themselves. Many Qilin victims were compromised weeks or months before the ransomware detonated: access was harvested early, sold on, and used later. A quiet network is not evidence of a clean network — detection requires actively looking.

How would I know if my firm’s data has been leaked on the dark web?

Usually one of four ways: a ransom note tells you; a dark web monitoring service detects your domain, credentials or documents; the ACSC or a security researcher notifies you; or a journalist calls. By the time data appears on a leak site, the theft happened days or weeks earlier — monitoring buys response speed, not prevention. Managed security providers typically include dark web monitoring for client domains and staff credentials.

We use cloud accounting software like Xero or MYOB. Are we safe from ransomware?

Safer in one dimension, not safe overall. The cloud platform itself is unlikely to be encrypted, but your firm still runs workstations, email, document management and shared drives full of client records — all encryptable — and an attacker with stolen credentials can log into your cloud platforms and exfiltrate client data without touching an encryptor. Cloud accounting removes one target; it does not remove the need for MFA, endpoint protection and hardened remote access.

Does the Essential Eight protect against ransomware?

Substantially, yes — it was designed around exactly these techniques. Patching closes the firewall and VPN holes Qilin exploits; MFA blocks stolen-credential logins; restricted admin privileges limit lateral movement; application control blocks unauthorised executables; and regular backups enable recovery. No framework guarantees immunity, but a firm at Maturity Level 1 or above is a dramatically harder target than the average small professional services firm.

What is EDR and does a small accounting firm really need it?

EDR (Endpoint Detection and Response) watches the behaviour of every computer — credential harvesting, unusual admin activity, mass file changes — rather than just matching known virus signatures like traditional antivirus. Qilin intrusions can go from first access to full encryption in under 48 hours, often outside business hours; EDR paired with 24/7 monitoring is what catches the intrusion during that window instead of after it. It is also now a common cyber insurance requirement.

How long does it take to recover from a ransomware attack?

The Australian average is around 21 days of downtime, but the spread is enormous. Firms with immutable backups, tested restores and an incident response plan can be operating again in days. Firms whose backups were deleted in the attack — a deliberate Qilin step — face weeks of rebuilding, possible permanent data loss, and a ransom decision made under duress. Recovery time is mostly determined by decisions made before the attack.

Can clients take legal action against my firm after a data breach?

The exposure is real and growing. Australia introduced a statutory tort for serious invasions of privacy in June 2025, the OAIC can pursue representative complaints, and clients may claim in contract or negligence where a firm failed to take reasonable care of their information. Professional bodies add confidentiality obligations for accountants and lawyers. This is general information, not legal advice — but documented, reasonable security controls are both your best prevention and your best defence.

What happened to LockBit? Is Qilin the new LockBit?

Law enforcement disrupted LockBit, ALPHV/BlackCat and RansomHub through 2024–25, but their affiliates did not retire — many moved to Qilin, taking tools and experience with them. That migration is a large part of why Qilin became the world’s most active ransomware operation by 2026. Takedowns shuffle the brand names; the threat consolidates rather than disappears.

How can a small accounting or law firm protect itself from Qilin ransomware?

Map defences to Qilin’s actual attack chain: patch internet-facing firewalls and VPNs within days of vendor advisories (or retire remote access you no longer need); enforce phishing-resistant MFA on every VPN, RDP, email and cloud login; keep immutable, offline-capable backups and test restores; deploy EDR with 24/7 monitoring to catch the intrusion during the dwell time; and maintain an incident response plan that includes OAIC notification obligations. For most firms without in-house security staff, a managed service provider is the practical way to run all five layers.

What happens if a ransomware victim doesn’t pay Qilin?

Qilin runs double extortion: data is exfiltrated before encryption, and victims who refuse to pay are listed on its dark web leak site and their stolen data published — as happened with the Australian accounting firm victims this year, where client financial details were reportedly included in published datasets. This is why backups alone are not a complete defence: they restore your systems, but they do not un-steal your clients’ data. Preventing exfiltration through early detection matters as much as recovery.

Is my firm too small for ransomware attackers to bother with?

No — targeting is largely automated. Qilin affiliates scan the entire internet for vulnerable firewalls and VPNs and buy whatever access brokers are selling; a five-person firm with an unpatched VPN appears in the same scan results as a corporation. A large share of Australian cybercrime reports come from small businesses — and small professional services firms hold valuable client data behind the weakest defences, which is precisely the appeal.

About AyeTech

AyeTech is a Sydney-based managed IT services provider specialising in cyber security for Australian small and medium businesses, including accounting, legal and professional services firms. We run the monitoring, patching, backup and incident response that keeps client data off leak sites — and firms out of the OAIC’s inbox.

Contact Information:

  • Phone: 02 9188 8000
  • Email: [email protected]
  • Address: Suite 203, Level 8, 99 Walker St, North Sydney, NSW 2060
  • Service Areas: Sydney, Melbourne, Brisbane, Perth, Adelaide

Related Resources: