TL;DR:
- The most dangerous ransomware families targeting Australian SMBs operate as Ransomware-as-a-Service, making attacks accessible to low-skill criminals. A single security failure, such as lacking multi-factor authentication or unpatched systems, can enable entry and major damage. Implementing basic controls like immutable backups, MFA, and regular patching significantly reduces ransomware risks.
The ransomware families that pose the greatest risk to Australian SMBs right now are LockBit, Clop, BlackCat/ALPHV, WannaCry, Ryuk/Conti, Black Basta, DeadBolt, Vice Society, Akira, and MedusaLocker. Nearly all of them operate under the Ransomware-as-a-Service (RaaS) model, which means even low-skill attackers can deploy them. RSM’s survey found that a substantial proportion of Australian organisations reported a ransomware attack or demand, and the Australian Signals Directorate’s ACSC responded to 138 ransomware incidents in FY2024–25 alone.
Here is what each family means for your business in one line:
- LockBit — the most prolific RaaS group; targets any sector, any size, and publishes stolen data publicly if you do not pay.
- Clop — exploits file-transfer software vulnerabilities at scale; your data can be stolen before you even know you have been hit.
- BlackCat/ALPHV — cross-platform, written in Rust; attacks Windows and Linux servers including VMware ESXi.
- WannaCry — old but still active on unpatched systems; spreads automatically across networks without any user interaction.
- Ryuk/Conti — historically targeted healthcare and critical services; Conti’s leaked playbooks are still being used by successor groups.
- Black Basta — fast-moving, double-extortion group that has hit professional services and manufacturing hard.
- DeadBolt — specifically targets QNAP NAS devices; a direct threat if your backups live on a network-attached storage unit.
- Vice Society — focused on education and healthcare; known for publishing data without warning.
- Akira — rising group targeting SMBs via compromised VPN credentials; has hit Australian businesses.
- MedusaLocker — common in RaaS affiliate campaigns; spreads via phishing and RDP; demands payment in Monero.
Single most important defensive action: turn on multi-factor authentication (MFA) on every remote access point and admin account before anything else. That one change stops the most common entry vector cold.
Table of Contents
- 10+ real-world ransomware attack examples and how they happened
- How these ransomware attacks actually get in
- Why encryption is no longer the whole story
- What the Australian data actually shows
- What to do in the first 72 hours if ransomware hits you
- Practical prevention priorities for SMBs
- Key takeaways
- What most ransomware guidance gets wrong
- IT Start helps Brisbane SMBs stay ahead of ransomware
- Useful sources and further reading
- FAQ
10+ real-world ransomware attack examples and how they happened
1. LockBit — the world’s most active ransomware group
LockBit operated as a RaaS platform, recruiting affiliates who carried out attacks in exchange for a cut of the ransom. Affiliates gained initial access through phishing emails, stolen remote desktop protocol (RDP) credentials, and unpatched vulnerabilities in public-facing systems. Once inside, they moved laterally, escalated privileges, exfiltrated data, then encrypted files. The group published stolen data on a dedicated leak site to pressure victims. LockBit targeted businesses of every size across manufacturing, legal, healthcare, and logistics. Australian businesses were among confirmed victims. The group’s infrastructure was disrupted by law enforcement in 2024, but affiliates regrouped quickly under new banners. What to watch for: files renamed with a .lockbit extension and a ransom note titled Restore-My-Files.txt. The lesson for SMBs: RaaS means the attacker does not need to be sophisticated. The platform does the heavy lifting.
2. Clop and the MOVEit vulnerability campaign
Clop is one of the clearest examples of a supply-chain ransomware attack. In 2023, the group exploited a zero-day SQL injection vulnerability in MOVEit Transfer, a widely used managed file-transfer application. Hundreds of organisations globally had data stolen before a patch was even available. Clop did not always encrypt files. In many cases, the group simply threatened to publish stolen data unless a ransom was paid. That is pure extortion without encryption. Australian organisations using MOVEit or third-party vendors who did were exposed. What to watch for: unexpected outbound data transfers from file-transfer servers, unusual SQL activity in web application logs, and ransom notes referencing “cl0p^_-leaks.” The MOVEit campaign showed that your exposure is not just your own software. It includes every vendor in your supply chain.

3. BlackCat/ALPHV — cross-platform and technically advanced
BlackCat, also known as ALPHV, was written in Rust, which made it unusually portable. It ran on Windows, Linux, and VMware ESXi hypervisors, meaning a single infection could take down an entire virtualised server environment. Affiliates gained access via phishing, stolen credentials, and exploited VPN vulnerabilities. BlackCat used double extortion and, in some cases, triple extortion by threatening to notify regulators or customers directly. The group was disrupted by the FBI in late 2023, but its affiliates migrated to other platforms. What to watch for: .alphv or .noberus file extensions, and ransom notes in multiple languages. For businesses running VMware, this group demonstrated that hypervisor-level attacks can take down every virtual machine in one move.

4. WannaCry — still spreading on unpatched systems
WannaCry launched in May 2017 and infected over 200,000 systems across 150 countries within days, according to CISA advisories. It exploited EternalBlue, a vulnerability in Windows SMB (Server Message Block) that Microsoft had patched two months earlier. The attack required no user interaction. It spread automatically across networks. The UK’s National Health Service was crippled, with thousands of appointments cancelled. Honestly, WannaCry is still relevant in 2026 because we still find unpatched Windows machines in SMB environments. Any machine running Windows 7, Windows Server 2008, or an unpatched version of Windows 10 is still vulnerable. What to watch for: files with a .wcry or .wncry extension and a ransom note demanding Bitcoin. The fix is still the same: patch SMB, disable SMBv1, and segment your network.
5. Ryuk and Conti — the playbook that never went away
Ryuk emerged in 2018 and was typically deployed after a TrickBot or Emotet infection had already established a foothold. Attackers spent weeks inside a network before activating the ransomware, giving them time to map systems, steal data, and disable backups. Conti evolved from Ryuk and became one of the most damaging groups before its infrastructure was disrupted in 2022. Critically, Conti’s internal playbooks were leaked, and those tactics are still being used by successor groups including Black Basta. Healthcare was a primary target. What to watch for: TrickBot or Emotet detections in your endpoint logs are a serious warning sign that Ryuk-style ransomware may follow. If you see either of those, treat it as a full incident, not just a malware cleanup.
6. Black Basta — fast, quiet, and double extortion
Black Basta appeared in 2022 and is widely believed to include former Conti members. The group moved quickly from initial access to encryption, often within 24–48 hours. Initial access came via phishing emails, Qakbot malware, and compromised RDP. Black Basta used double extortion, exfiltrating data before encrypting it and threatening publication on their leak site. Professional services, manufacturing, and construction firms were common targets. The speed of Black Basta attacks is what makes them particularly dangerous for SMBs without 24/7 monitoring. By the time someone notices something is wrong, the data is already gone. What to watch for: unusual scheduled tasks, new admin accounts created overnight, and large volumes of data moving to external IP addresses.
7. DeadBolt — a direct attack on your backup device
DeadBolt specifically targeted QNAP NAS (network-attached storage) devices exposed to the internet. It exploited known vulnerabilities in QNAP’s firmware to encrypt the entire device and demand a small ransom, typically around 0.03 Bitcoin. The attack was particularly damaging because many businesses use NAS devices as their primary backup destination. If your backup device is the thing that gets encrypted, you have no recovery path. QNAP released patches, but many devices were never updated. What to watch for: QNAP devices accessible directly from the internet on port 8080 or 443, firmware that has not been updated in over six months, and any NAS device that is not air-gapped or write-protected. This is exactly why immutable backups with separate storage matter so much.
8. Vice Society — targeting schools and hospitals
Vice Society focused heavily on education and healthcare, sectors that tend to have limited IT budgets and high volumes of sensitive personal data. The group gained access via phishing and exploited known vulnerabilities in internet-facing systems. Unlike some groups, Vice Society sometimes published stolen data without issuing a ransom demand first, using data exposure as the primary lever. Australian schools and healthcare providers are in the crosshairs of groups like this. Healthcare recorded a higher number of ransomware incidents in FY2024–25, with MFA deployment on remote access solutions being a consistent gap. What to watch for: unusual access to student or patient records, large file transfers outside business hours, and login attempts from unexpected geographic locations.
9. Akira — targeting SMBs through VPN credentials
Akira emerged in 2023 and quickly became one of the more active groups targeting small and medium businesses. The primary entry vector was compromised VPN credentials, particularly on Cisco ASA and Fortinet VPN appliances without MFA enabled. Once inside, Akira moved laterally, targeted backups, and deployed double extortion. The group has hit Australian businesses across professional services and manufacturing. Industry reporting identified single-factor remote access as responsible for roughly 34% of entry methods in 2025. Akira is a textbook example of why MFA on VPN is not optional. What to watch for: unexpected VPN logins outside business hours, new local admin accounts, and the .akira file extension on encrypted files.
10. MedusaLocker — phishing and RDP, still working
MedusaLocker is a RaaS offering that has been active since 2019 and remains in regular use by affiliates. Initial access typically comes from phishing emails or exposed RDP ports. The ransomware deletes shadow copies, disables recovery tools, and encrypts files with AES-256. Affiliates demand payment in Monero for added anonymity. MedusaLocker is not sophisticated, but it does not need to be. It works because businesses still have RDP exposed to the internet and still click on phishing emails. What to watch for: shadow copy deletion events in Windows event logs (Event ID 524), unusual RDP login attempts, and .medusa or .readinstructions file extensions.
11. Ransomware-as-a-Service (RaaS) — the business model behind most attacks
RaaS is the reason ransomware volume keeps climbing even as individual groups get disrupted. Developers build and maintain the ransomware platform, then recruit affiliates who carry out attacks and split the ransom proceeds, typically 70–80% to the affiliate and 20–30% to the developer. This means the person attacking your business may have very limited technical skill. They bought access to a polished criminal platform. LockBit, BlackCat, Akira, and MedusaLocker all operated this way. The RaaS model has also driven fragmentation, with many smaller, less disciplined groups creating more unpredictable outcomes. For SMBs, this means the threat is not just from elite nation-state actors. It is from anyone willing to pay for access to a criminal toolkit.
12. Origin Energy alleged incident — an Australian case study
In 2025, Origin Energy investigated an alleged cyber attack after a hacker claimed to have stolen data belonging to approximately two million customers and issued a ransom demand. The incident illustrates how extortion can occur without confirmed encryption. As Professor Damien Manuel warned in reporting on the incident, paying a ransom rarely guarantees that stolen data remains private. Attackers often retain copies regardless of payment and may return for a second demand. For Australian SMBs, the lesson is that a ransom demand does not mean your data is safe even if you pay. It means you have a confirmed attacker who knows your systems and your willingness to pay.
How these ransomware attacks actually get in
The attack mechanics behind the examples above follow a short list of recurring patterns. Understanding them helps you map the risk to your own environment.
Phishing and credential theft remain the most common starting point. An employee clicks a malicious link or attachment, credentials are harvested via a fake login page, and the attacker has a valid username and password. From there, they log in quietly and start exploring. We see this constantly with Microsoft 365 accounts that have no MFA.
Remote access compromise via VPN and RDP is the second major vector. Akira, Black Basta, and MedusaLocker all used this route heavily. Single-factor remote access accounted for roughly 34% of entry methods in 2025, and public-facing infrastructure accounted for a notable share. If your RDP port is open to the internet with only a password protecting it, you are a target.
Public-facing application exploits are how Clop got in via MOVEit and how WannaCry spread via SMB. Unpatched software on internet-facing servers is a standing invitation. Attackers scan for known vulnerabilities continuously using automated tools.
Supply chain and third-party access is the harder one to control. Clop’s MOVEit campaign hit organisations that had never heard of MOVEit because their vendors used it. Your security posture is only as good as the weakest link in your vendor chain.
Misconfigured cloud or NAS devices gave DeadBolt its attack surface. QNAP devices exposed directly to the internet, cloud storage buckets with public access, and unsecured admin portals are all low-hanging fruit.
Once inside, attackers follow a consistent playbook: move laterally across the network, escalate privileges to domain admin, locate and disable or encrypt backups, exfiltrate data, then deploy the ransomware. The data theft happens first. That is what makes double extortion possible.
Pro Tip: For each of these vectors, there is one practical control that closes most of the risk. For phishing: MFA and email filtering. For RDP/VPN: MFA plus geo-blocking and conditional access. For unpatched software: a monthly patching schedule with a tested rollback plan. For NAS devices: take them off the public internet and make them write-once. None of these require enterprise budgets.
For a broader view of common cyber risks for Brisbane SMBs, the pattern is consistent: the entry point is almost always something that could have been closed with a basic control.
Why encryption is no longer the whole story
Double extortion changed the calculus for every business that thought a good backup was enough. The model works like this: attackers steal your data first, then encrypt your systems. They demand a ransom for the decryption key, and a second ransom to not publish the stolen data. Clop’s MOVEit campaign is the clearest example. In many cases, files were never encrypted at all. The threat was purely about data exposure.
The business consequences go well beyond operational downtime. A data breach involving personal information triggers mandatory reporting obligations under the Australian Privacy Act’s Notifiable Data Breaches (NDB) scheme. If the stolen data includes health records, financial information, or government identifiers, you must notify the Office of the Australian Information Commissioner (OAIC) and affected individuals. That notification process has its own costs, legal exposure, and reputational fallout.
Attackers increasingly use AI tools to triage stolen data quickly, identifying the most sensitive files to threaten publication of first. This accelerates the pressure on victims and makes the extortion more targeted. A healthcare provider’s patient records or a law firm’s client files carry far more leverage than generic business documents.
Secondary extortion cycles are also real. Paying once does not remove you from the target list. It confirms you are willing to pay. Some groups sell stolen data to other criminal actors regardless of whether the ransom was paid, leading to follow-on phishing campaigns, identity fraud, and further extortion attempts targeting individual employees whose data was in the breach.
What the Australian data actually shows
The local picture is worse than many SMBs assume. RSM’s survey found that a substantial proportion of Australian organisations reported a ransomware attack or demand, and 1 in 5 experienced a data breach in the prior 12 months. That is not a large-enterprise problem.
| Metric | Figure | Source |
|---|---|---|
| Ransomware incidents responded to by ACSC | 138 in FY2024–25 | ACSC Annual Cyber Threat Report 2024–25 |
| Organisations reporting a ransomware attack or demand | 35% | RSM 2026 Cyber Security Report |
| Organisations experiencing a data breach (prior 12 months) | 1 in 5 | RSM 2026 Cyber Security Report |
| Average ransom payment (2025) | — | S-RM/FGS data via IDM |
| Single-factor remote access as entry method | ~34% | IDM / industry reporting 2025 |
| Public-facing infrastructure as entry method | — | IDM / industry reporting 2025 |
Healthcare and professional services saw the sharpest increases in targeting. PwC’s Annual Threat Dynamics 2026 highlighted growing threat actor diversity and sector concentration in Australia, with healthcare and critical sectors notably impacted. The fragmentation of ransomware groups means more actors, more campaigns, and less predictable behaviour.
The RSM data also points to a dangerous overconfidence gap. Organisations report high confidence in their ability to protect customer data, yet a third of them experienced a ransomware attack or demand in the same period. That mismatch is where most SMBs get hurt. They believe their defences are adequate until they are not.
Under the Cyber Security (Ransomware Payment Reporting) Rules 2025, organisations with annual turnover of $3 million or more must report any ransom payment to the Australian Signals Directorate within 72 hours. That is a compliance obligation most SMBs have not built into their incident response plan yet.
What to do in the first 72 hours if ransomware hits you
Speed matters, but so does sequence. The biggest mistakes we see businesses make in the first few hours are the ones that make recovery harder or more expensive.
- Isolate affected systems immediately. Disconnect infected machines from the network, including Wi-Fi. Do not shut them down yet. Powered-off machines can lose forensic evidence stored in memory.
- Preserve logs before you do anything else. Pull firewall logs, Windows event logs, and any endpoint detection logs. These tell you how the attacker got in and what they accessed. Without them, you are guessing.
- Stop replication and sync. Pause Microsoft 365 sync, OneDrive, and any cloud backup that might be pushing encrypted files to your clean copies. Cloud sync can replicate encrypted files across your entire tenant if you do not stop it quickly.
- Rotate credentials immediately. Assume every account on the affected network is compromised. Start with domain admin and any service accounts. Change passwords from a clean, unaffected device.
- Call your MSP or incident response provider. Do not try to remediate alone. If you do not have an IR retainer, call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371).
- Notify your insurer. Most cyber insurance policies require prompt notification. Delayed notification can void your claim.
- Report to ACSC/ASD. Report the incident at cyber.gov.au. If personal data was accessed or exfiltrated, notify the OAIC under the NDB scheme.
- Do not pay the ransom without forensic verification. Paying does not guarantee decryption or data deletion. Get forensic confirmation of what was actually taken before making any payment decision.
Pro Tip: Build a one-page “Payment Decision” workflow into your incident response plan before you need it. Under the Ransomware Payment Reporting Rules 2025, firms with turnover of $3 million or more have 72 hours to report a payment to ASD. That clock starts the moment you pay, not the moment you discover the incident. Having the workflow documented means you are not making that decision under pressure.
For a practical incident response plan template tailored to SMBs, the key is having it written down before something goes wrong.
Practical prevention priorities for SMBs
Honestly, most of the businesses we work with are not missing exotic security tools. They are missing the basics. Here is what actually moves the needle, in order of impact.
Immutable, separate backups are the single most important control. Not Microsoft 365 sync. Not a NAS device on your local network. A separate, write-protected backup that cannot be reached from your production environment. Government guidance is explicit: Microsoft 365 sync is not an adequate backup. Encrypted files replicate across your tenant just like normal files do.
MFA on every remote access point and admin account. This is non-negotiable. VPN, RDP, Microsoft 365 admin portal, email. All of it. Akira, Black Basta, and MedusaLocker all relied on single-factor remote access as their primary entry point.
Endpoint Detection and Response (EDR). Traditional antivirus does not catch modern ransomware behaviour. EDR tools like Microsoft Defender for Business, CrowdStrike Falcon Go, or SentinelOne monitor for behavioural indicators, such as mass file renaming or shadow copy deletion, and can stop an attack mid-execution.
Patching of public-facing services on a defined schedule. WannaCry, Clop, and DeadBolt all exploited known, patched vulnerabilities. The patch existed. It just had not been applied. Monthly patching with a tested rollback plan is the standard. Delaying because of “breakage fears” is a real risk, but it is a smaller risk than leaving a known exploit open.
Least privilege and credential hygiene. Every user account should have only the access it needs. Admin accounts should not be used for day-to-day tasks. Service accounts should have unique, complex passwords rotated regularly. We see this ignored constantly, and it is what allows lateral movement to happen so quickly once an attacker is inside.
Five-item quick audit checklist:
- Can your backups be accessed and modified from your main network? If yes, they are not immutable.
- Do all remote access accounts (VPN, RDP, Microsoft 365) require MFA? Test it, do not assume.
- When was the last time public-facing services (firewall firmware, VPN appliance, web applications) were patched? If it was more than 30 days ago, you have a gap.
- Are there any local admin accounts on workstations that are not actively managed? List them and remove or restrict them.
- Do you have an EDR tool deployed on every endpoint, including servers? Antivirus alone is not enough.
For a structured approach to cyber hygiene for Brisbane SMBs, these five checks are a solid starting point.
Key takeaways
Ransomware is not a large-enterprise problem. With 35% of Australian organisations reporting an attack or demand in RSM’s 2026 survey, SMBs are firmly in scope, and the most common entry points are still basic gaps that can be closed without enterprise budgets.
| Point | Details |
|---|---|
| Immutable backups are the foundation | Microsoft 365 sync is not a backup; use separate, write-protected storage that cannot be reached from your network. |
| MFA stops the most common entry vector | Single-factor remote access accounted for a significant share of entry methods in 2025; MFA on VPN and admin accounts closes this gap. |
| Double extortion changes who you notify | Data theft before encryption triggers NDB scheme obligations; notify OAIC if personal data was accessed. |
| Patch public-facing services monthly | WannaCry, Clop, and DeadBolt all exploited known, patched vulnerabilities that had not been applied. |
| IT Start covers the full prevention stack | IT Start provides managed security, immutable backups, MFA deployment, and incident response support for Brisbane SMBs. |
What most ransomware guidance gets wrong
Most articles about ransomware read like a vendor brochure. They list the threat families, recommend a stack of tools, and move on. What they skip is the gap between what businesses think they have and what they actually have.
We see this every week. A business owner tells us they are backed up. We check, and their “backup” is a Microsoft 365 sync to OneDrive, which replicates encrypted files in real time. Or they have a NAS device on the local network that the ransomware encrypted along with everything else. Or they have MFA turned on for regular users but not for the three admin accounts that actually matter.
Two scenarios we see often: A professional services firm with 20 staff had Akira ransomware deployed through a Fortinet VPN with no MFA. The attacker was inside for four days before encryption. By the time we were called in, the backups on the local NAS were gone. Recovery took three weeks from an offsite tape backup that had not been tested in eight months. Half the data was unrecoverable. The second scenario: a healthcare practice with 15 staff had Vice Society-style data exfiltration through a phishing email that harvested a staff member’s Microsoft 365 credentials. No MFA, no EDR, no conditional access. Patient records were accessed. The NDB notification process cost more in legal fees than the ransom demand would have.
The honest advice for SMB owners talking to their MSP: ask specifically whether your backups are immutable and stored separately from your network. Ask whether MFA is enabled on every admin account, not just user accounts. Ask when public-facing services were last patched. If your MSP cannot answer those three questions clearly, that is a problem.
IT Start helps Brisbane SMBs stay ahead of ransomware
Most Brisbane SMBs do not need a bigger security budget. They need the basics done properly. IT Start’s managed cybersecurity services cover the controls that matter most: MFA deployment across Microsoft 365 and remote access, immutable backup configuration with separate cloud storage, EDR on every endpoint, monthly patching, and a documented incident response workflow. For businesses that have never had a proper security review, IT Start offers a free risk assessment that checks MFA coverage, backup immutability, patching gaps, and admin account hygiene. It takes about an hour and gives you a clear picture of where you actually stand. If you are a Brisbane business with 10 to 50 staff and you are not confident your current setup would survive a ransomware attack, get in touch with IT Start to book your free assessment.
Useful sources and further reading
- ACSC Annual Cyber Threat Report 2024–25 — the primary Australian government source for local incident data, sector breakdowns, and defensive guidance. Published October 2025.
- Ransomware guidance — Cyber.gov.au — practical guidance on recognising, reporting, and recovering from ransomware. Includes the ACSC hotline number and response steps.
- RSM 2026 Cyber Security Report Australia — annual survey of Australian organisations covering attack rates, breach incidence, and the confidence gap. Key source for local statistics.
- PwC Annual Threat Dynamics 2026 — sector-level threat analysis for Australia, covering healthcare, critical infrastructure, and threat actor diversity.
- IDM: Ransom payments surge as ransomware groups multiply — covers average ransom payment figures, entry vector breakdowns, and the impact of group fragmentation. Useful for cost and vector data.
- 7NEWS: Origin Energy alleged cyber attack reporting — contemporary Australian case with expert commentary from Professor Damien Manuel on ransom payment risks.
- CISA Advisory AA23-039A — US Cybersecurity and Infrastructure Security Agency advisory on WannaCry and related SMB exploits; technically authoritative.
- No More Ransom — decryption tools — free decryption tools for known ransomware families; worth checking before considering payment.
- Total Cyber Academy: RaaS and how to counter it — practical training resource on the RaaS model and mitigation strategies.
- Total Cyber Academy: Backup best practices — guidance on backup immutability and the 3-2-1 backup strategy.
FAQ
What are the most common types of ransomware attacks?
The most common types are encryption ransomware (files locked and a decryption key demanded), double extortion (data stolen before encryption, with a second threat to publish it), and RaaS campaigns where affiliates deploy pre-built ransomware platforms. Phishing, compromised VPN credentials, and unpatched public-facing software are the primary entry vectors.
What is a real-life example of a ransomware attack in Australia?
In 2025, Origin Energy investigated an alleged attack after a hacker claimed to have stolen data belonging to approximately two million customers and issued a ransom demand. The ACSC also responded to 138 ransomware incidents in FY2024–25, with healthcare and professional services among the most targeted sectors.
What are the main threats that make ransomware attacks succeed?
The main enablers are single-factor remote access (no MFA on VPN or RDP), unpatched public-facing software, backups stored on the same network as production systems, and overprivileged user accounts that allow rapid lateral movement once an attacker is inside.
What should a business do immediately after discovering ransomware?
Isolate affected systems from the network, preserve logs before shutting anything down, stop cloud sync to prevent encrypted files replicating, rotate credentials from a clean device, and call your MSP or the ACSC hotline on 1300 CYBER1. Do not pay without forensic verification of what was actually taken.
Does paying the ransom guarantee you get your data back?
No. As Professor Damien Manuel noted in commentary on the Origin Energy incident, paying a ransom rarely guarantees that stolen data remains private. Attackers often retain copies regardless of payment and may return with further demands or sell the data to other criminal actors.

