Frontrow Technology
← All insights & guides
Guide

Statistics

Australian ransomware statistics: 138 incidents, 64% pay

138 ransomware incidents, 64% of attacked businesses paying, a $711,000 average ransom, and the mandatory payment-reporting numbers. Checked July 2026.

Sam Williams · 12 August 2026 · 10 min read

Australia's ransomware numbers: the Australian Signals Directorate responded to 138 ransomware incidents in FY2024-25, 64% of attacked businesses paid the ransom, the average payment fell to $711,000, and since 30 May 2025 businesses turning over $3 million or more must report every ransomware payment to the government within 72 hours.

This page covers ransomware and cyber extortion only: attack counts, who pays, how much, and what Australia's mandatory payment-reporting regime requires. Frontrow keeps separate pages for Australia's overall cyber security statistics and for OAIC data breach statistics, so nothing here rehashes those. Every figure below was checked against its primary source, the ASD Annual Cyber Threat Report 2024-25, the McGrathNicol and YouGov ransomware survey, and Department of Home Affairs materials on the Cyber Security Act 2024, in July 2026. Anything that could not be traced to a primary source has been left out.

Key facts

  • ASD's ACSC responded to 138 ransomware incidents in FY2024-25 (ASD Annual Cyber Threat Report, October 2025).
  • 39% of the ransomware incidents ASD responded to in FY2024-25 began with ASD warning the victim of a possible compromise, not with the victim detecting the attack (ASD Annual Cyber Threat Report, October 2025).
  • Ransomware featured in 11% of all cyber security incidents ASD responded to in FY2024-25, consistent with the previous year (ASD Annual Cyber Threat Report, October 2025).
  • Ransomware incidents against the Australian healthcare sector doubled in FY2024-25 compared with FY2023-24 (ASD Annual Cyber Threat Report, October 2025).
  • 64% of surveyed Australian businesses with 50 or more employees that suffered a ransomware attack chose to pay the ransom, down from 84% a year earlier (McGrathNicol and YouGov ransomware survey, November 2025).
  • The estimated average cyber ransom paid by Australian businesses fell to $711,000 in 2025, down from $1.35 million in 2024 (McGrathNicol and YouGov ransomware survey, November 2025).
  • 89% of surveyed organisations that experienced a ransomware attack in the past 12 months were businesses with 50 to 249 employees (McGrathNicol and YouGov ransomware survey, November 2025).
  • Businesses with annual turnover of $3 million or more, plus critical infrastructure entities, must report any ransomware or cyber extortion payment within 72 hours under the Cyber Security Act 2024, in force since 30 May 2025 (Department of Home Affairs factsheet).
  • At least 94 ransomware or cyber extortion payments were reported to the Australian government in the regime's first eight months to January 2026 (Home Affairs figures obtained under freedom of information by Secolve, reported by iTnews, February 2026).

How many ransomware attacks hit Australia each year?

The most reliable count comes from the Australian Signals Directorate. In FY2024-25, ASD's Australian Cyber Security Centre responded to over 1,200 cyber security incidents, and 138 of them were ransomware incidents. Ransomware featured in 11% of all incidents ASD responded to, a share consistent with the previous year (ASD Annual Cyber Threat Report 2024-25, published October 2025). These figures only count incidents where ASD was involved; there is no obligation to tell ASD about a ransomware attack you handle privately, so the true national count is higher.

One detail in the ASD data deserves more attention than the headline count: 39% of those 138 ransomware incidents started with ASD contacting the victim to warn of a possible compromise. In roughly four out of ten cases the attacker's presence was visible to an outside agency before the victim's own monitoring picked it up. ASD also singled out healthcare, where ransomware incidents doubled in FY2024-25 compared with FY2023-24, a trend it links to the sector's sensitivity to disruption and the resale value of health data (ASD Annual Cyber Threat Report 2024-25).

"Ransomware continues to be the most disruptive cybercrime threat in FY2024–25."
ASD Annual Cyber Threat Report 2024-25

How many Australian businesses pay the ransom?

The best Australian data on payment behaviour is the annual McGrathNicol ransomware survey, run with YouGov. The 2025 edition, published in November 2025, surveyed 805 owners, partners, board members and C-suite leaders at Australian businesses with 50 or more employees between 25 August and 3 September 2025, weighted to ABS population estimates. It is a survey of executives at mid-sized and larger businesses, not a census, and McGrathNicol itself notes the findings should be read as indicative. Within that population, the direction of travel is unambiguous.

  • 64% of surveyed businesses that suffered a ransomware attack in the past five years chose to pay, a significant fall from 84% in the 2024 survey.
  • The estimated average ransom paid dropped to $711,000, from $1.35 million in 2024.
  • 81% of surveyed executives said they would be willing to pay a ransom, but 20% would only do so as a last resort, up from 14% in 2024.
  • Only 18% of surveyed businesses would be willing to pay $1 million or more, down from 34% in 2024.
  • Cyber insurance factored into just 31% of decisions to pay, down from 52% in 2024, with 54% of surveyed organisations now carrying coverage below $1 million.

McGrathNicol attributes the decline to three pressures: shrinking insurance coverage, rising regulatory and reputational scrutiny following the mandatory reporting rules that commenced in May 2025, and growing scepticism that paying actually restores data or prevents a repeat attack. The survey also shows where the burden sits: 89% of surveyed organisations that experienced an attack in the past 12 months had 50 to 249 employees. And because the survey only covers businesses with 50 or more staff, the many smaller Australian businesses hit by ransomware are not captured in these figures at all.

What does the mandatory payment reporting regime require?

Australia is one of the first countries in the world to require businesses across the whole economy to report ransomware payments. Under Part 3 of the Cyber Security Act 2024, in force since 30 May 2025, a report must be lodged through ASD's online reporting form within 72 hours of making a ransomware or cyber extortion payment, or of becoming aware that one was made on your behalf (Department of Home Affairs factsheet).

  • Who is captured: businesses carrying on business in Australia with annual turnover of $3 million or more in the previous financial year, plus responsible entities for critical infrastructure assets under the Security of Critical Infrastructure Act 2018. Not-for-profits are not exempt.
  • What triggers a report: only an actual payment, monetary or non-monetary. Receiving a ransom demand and refusing to pay triggers no obligation, though voluntary reporting to ASD is encouraged.
  • What goes in the report: details of the incident, the malware variant and vulnerabilities exploited, the demand, the amount paid and how, and any communications or negotiations with the extorting entity.
  • The penalty: failing to report is a civil penalty of 60 penalty units, currently $19,800 per contravention.
  • Enforcement posture: Home Affairs ran an education-first Phase 1 from 30 May to 31 December 2025, and moved to Phase 2, an active compliance and education approach, from 1 January 2026.

Two points are widely misunderstood. First, paying a ransom is not generally illegal in Australia, although the government strongly discourages it, and a payment to a sanctioned entity or one that breaches anti-money-laundering law can be a criminal matter. Second, the report is shielded: information in a ransomware payment report is protected under the Act, may only be used for permitted purposes, and is generally not admissible in proceedings against the reporting business (Department of Home Affairs factsheet).

What has mandatory reporting revealed so far?

Home Affairs had not published aggregate statistics from the regime as at July 2026. The first public numbers came out sideways: cyber security firm Secolve obtained figures under freedom of information in November 2025, and iTnews reported the combined picture in February 2026. At least 75 businesses with turnover of $3 million or more reported paying a ransom in the regime's first eight months, between seven and 13 every month, and critical infrastructure entities lodged a further 19 payment reports in the eight months to January 2026, bringing known reported payments to 94. Because businesses under the $3 million threshold are not tracked at all, the real payment count is higher. Individual payment amounts remain protected under the Act, so no official average ransom figure exists yet.

What does a ransomware incident cost an Australian business?

ASD does not publish a ransomware-specific cost figure, but its self-reported cybercrime cost averages set the floor. In FY2024-25 the average self-reported cost of cybercrime per report was $56,600 for a small business (up 14%), $97,200 for a medium business (up 55%) and $202,700 for a large business (up 219%), with the overall business average up 50% to $80,850 (ASD Annual Cyber Threat Report 2024-25). A paid ransom sits far above those averages: the McGrathNicol survey's $711,000 estimated average payment is before counting downtime, recovery, legal advice and customer notification. At the extreme end, ASD's report cites a UK retailer whose 2025 ransomware attack cost an estimated 300 million pounds, around $618 million.

What the reporting regime means for a 50-500 seat business

Almost any business running 50 to 500 staff clears the $3 million turnover threshold, so the practical assumption is simple: the regime applies to you. That changes incident response in concrete ways. The 72-hour clock starts at payment, not at business hours, so the reporting step needs a named owner inside the incident response plan, with the required details, incident timeline, variant, demand, amount and negotiation record, captured as the incident unfolds rather than reconstructed afterwards. The payment decision itself should be settled at board level before an incident, including sanctions and AML checks, because the data shows insurers are stepping back from funding payments and 20% of executives now treat paying as strictly a last resort.

Try it

Score your tenant against the Essential Eight

A short self-assessment that benchmarks your Microsoft 365 tenant against the eight ASD controls that blunt ransomware.

Score each of the 8 strategies

Where are you on the Essential Eight — honestly?

Eight strategies. Four levels each. Pick the statement closest to your reality today. We'll map it to the Microsoft 365 tooling that closes the gap.

What's your target Maturity Level?

Maturity Level 2 — most orgs' pragmatic target

  • 01

    Application control

    Only approved applications can execute on workstations and servers.

  • 02

    Patch applications

    Internet-facing apps, browsers, Office, PDF readers patched promptly.

  • 03

    Microsoft Office macros

    Macros disabled unless from trusted locations and signed by a trusted publisher.

  • 04

    User application hardening

    Web browsers and productivity apps hardened against the most common attacks.

  • 05

    Restrict administrative privileges

    Admin accounts limited, separated and reviewed — the crown jewels of the tenant.

  • 06

    Patch operating systems

    Operating system patches applied on a schedule that matches the risk.

  • 07

    Multi-factor authentication

    MFA everywhere that matters — privileged accounts, remote access, important data.

  • 08

    Regular backups

    Backups of important data, configuration and software — and restores you have actually tested.

Figures on this page were checked against their primary sources in July 2026, and the page describes the periods each source covers, not calendar 2026. The next editions of the underlying data are ASD's Annual Cyber Threat Report 2025-26, expected around October to November 2026, and the sixth McGrathNicol ransomware survey, expected around November 2026; Frontrow will refresh this page as each is published, along with any aggregate reporting-regime data Home Affairs releases.

Common questions

Frequently asked

How many ransomware attacks happen in Australia each year?
ASD's ACSC responded to 138 ransomware incidents in FY2024-25, and ransomware featured in 11% of all incidents it responded to (ASD Annual Cyber Threat Report, October 2025). The true national count is higher, because businesses that handle an attack privately have no obligation to tell ASD about it.
Is it illegal to pay a ransomware demand in Australia?
No, paying is not generally prohibited, but the Australian Government strongly discourages it, and payments to sanctioned entities or in breach of anti-money-laundering law can attract criminal penalties. If your business turns over $3 million or more, or runs critical infrastructure, any payment must be reported to the government within 72 hours.
Who has to report a ransomware payment, and when?
Under the Cyber Security Act 2024, businesses carrying on business in Australia with annual turnover of $3 million or more, and responsible entities for critical infrastructure assets, must report within 72 hours of making a ransomware or cyber extortion payment or becoming aware one was made on their behalf. A demand alone, with no payment, triggers no mandatory report.
What is the penalty for not reporting a ransomware payment?
Failing to report is a civil penalty of 60 penalty units, currently $19,800 per contravention. Home Affairs applied an education-first approach until 31 December 2025 and has run an active compliance and enforcement posture, Phase 2, since 1 January 2026.
What is the average ransom paid by Australian businesses?
The estimated average cyber ransom paid was $711,000 in 2025, down from $1.35 million in 2024, according to the McGrathNicol and YouGov survey of 805 decision makers at Australian businesses with 50 or more employees (November 2025). No official government average exists yet, because amounts in mandatory payment reports are protected under the Cyber Security Act.

The matched next step

Find out where your own tenant would have failed

Most incidents start with a control Frontrow checks in week one: MFA coverage, legacy authentication, admin sprawl, unpatched servers. A security baseline review scores your Microsoft 365 tenant against the Essential Eight and hands you a prioritised fix list — whether or not Frontrow does the fixing.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.