Skip to main content

Ransomware explained: What is it and why are Australian businesses a target?

What is a ransomware attack, which sectors are most affected, and what are the short and long-term impacts on businesses?

May 2, 2021
Aline Rivas, Head of Content & Social Media

Australian businesses have become a massive target for ransomware cyber attacks. In a recent report, Crowdstrike found that over 67% of Australian organisations have suffered a ransomware attack, which is 10% higher than the global average.

And attacks are increasing - in size, severity, and sheer brazenness.

In April this year, a cyber attack on UnitingCare's Queensland hospitals caused chaos across the healthcare network. According to UnitingCare, the attack blocked access to their "digital and technology systems," with local reports suggesting that email and operations booking systems had become infected. Hospital staff also reported Wi-Fi networks coming down, impeding staff from critical communications and assistance, access to patient records, and difficulty in discharging patients. Some were even concerned the attack would impact their pay.

This recent ransomware attack is not the first of this kind to hit Australia’s healthcare sector, nor will it be the last. Businesses and organisations must become ultra-vigilant to protect data assets and customer privacy, and it’s clear Australian organisations are still not up to speed on the risks. So, let’s deep dive into ransomware: what it is, who is it targeting, and what are its effects?

What is ransomware?

Ransomware attacks generally involve a hacker getting malware into a computer’s system that allows them to lock and encrypt data until the victim pays a ransom to get access back. Ransomware seizes on vulnerabilities within a system, network, software, or even human users themselves, to plant malware and infect a device.

According to Deep Instinct’s Threat Report, one hacking trend that has emerged is that of double extortion ransomware tactics. In this new trend, when companies refuse to pay the ransom, cybercriminals will next threaten to publish the stolen data.

How does ransomware enter a network?

There are many techniques that a cyber criminal can use to get this malware into a company’s network, including:

  • Phishing emails

  • Email attachments

  • Malicious links on social media

  • Malvertising, or clicking a legitimate ad that has malicious code in it

  • Installing infected programs or applications

  • Visiting an unsafe or fake website or opening/closing a malicious pop-up

  • Traffic Distribution System (TDS): clicking a link on a legitimate website that redirects to a malicious website

  • An employee inserting a USB directly into their computer


Once malware is installed within a company’s system, cyber criminals don’t necessarily act on it immediately. The average cost for a business to remediate a ransomware attack is much higher for those who pay the ransom versus those who don’t. This is partly due to the fact that the business who pays the ransom still needs to make system-wide changes to prevent subsequent attacks.

Who is being targeted?

No industry or business is safe from a ransomware attack. However, the Australian Cyber Security Centre (ACSC) found that in the 2019-20 financial year, health, state governments, and the education sector were the hardest affected industries of ransomware attacks.

The higher prevalence of ransomware attacks directed at the health and government sector may be due to the lack of appropriate defence protocols in many Australian organisations. In a recent three-year study, Macquarie University found that 16% of Australian government websites did not have the most basic security protocol installed, and over one-third of those belonged to the Department of Health.

What are the effects of a ransomware attack?

New South Wales public transport was disrupted after a 2020 ransomware attack.

In one high-profile ransomware attack in 2020, major disruption to the New South Wales public transport system occurred as a result of a cyber attack on the NSW State Transit Authority. The disruption impacted bus scheduling for several days and caused problems with computer and phone systems for up to nine days across all of the company’s bus depots.

For some sectors, like healthcare, these kinds of disruptions and delays could be life threatening. As the UnitingCare disruption plays out, the potential for serious harm is clear.

In other sectors, what was already a challenging year for Australian businesses, 2020 saw several major ransomware attacks that seriously impacted operations.

Australian logistics company, Henning Harders, took down their cargo tracking systems when they discovered unusual activity in their network; Australian law firm, Law in Order, halted business operations when their system fell victim to a ransomware attack; and NSW-based retailer, IN SPORT took their entire head office system offline when they became another victim of ransomware.

On top of the financial, time, and data losses that affect businesses following a ransomware attack, organisations must also manage the long-term effects on the company’s reputation and trustworthiness.

Reputation loss can cause share prices to drop, as was the case when Nine Entertainment’s systems were attacked earlier this year, triggering a 2.4% drop in share price.

While the impact of reputation loss can be difficult to measure, global surveys indicate that up to 70% of customers would stop doing business with a company who had experienced a data breach.

Ultimately, no one is safe from ransomware attacks. As Australia has become a major target for hackers, cyber security cannot be left to chance.

Written by

Aline Rivas
Head of Content & Social Media

I've spent the last 4 years at Superloop making complex telco topics genuinely easy to read, driven by a mission to help challenger telcos take on the big guys.

Related articles

Let's take a closer look at what makes a secure password and why.

February 6, 2019

Frequent incidents underscore the critical importance of designing devices with security in mind.

November 23, 2023

The challenges of being secure in an increasingly cloud-based reality, and the opportunities that cloud access can offer.

November 28, 2021

Refresh your internet

Type to show suggested addresses. Use the up and down arrow keys to move through the list, Enter to select an address, and Escape to close the listbox.