The Breach Ledger is a Coastal Cyber research series examining cyber incident trends across Australian industries. Each edition draws on three primary sources: the Webber Insurance named breach register [1] (678 Australian incidents, 2018–2026), OAIC Notifiable Data Breach reports published since the scheme commenced in February 2018 [2], and threat intelligence from the ASD Annual Cyber Threat Report [3]. Together, they map what is happening in a given sector, what the consequences look like in practice, and what organisations are risking by treating security as next year’s budget problem.
This is the Legal, Accounting & Management Services Edition.
The Qilin ransomware group published client financial and banking data belonging to Kennedy McLaughlin, a Queensland-based accounting firm. The firm confirmed the incident and notified impacted individuals — but the data was already online. [4]
Accounting firms hold exactly this kind of information: bank account details, financial records, transaction histories. The data that, in the wrong hands, enables fraud. Not theoretical fraud — real, executable fraud, against real clients who trusted a firm with some of their most sensitive financial information.
Kennedy McLaughlin is not a large firm. It is the kind of practice that serves individuals, families, and small businesses who have no way to assess what controls their accountant maintains. The clients affected had no say in whether their data was secured. They found out when it appeared online.
This is not an isolated case. And the legal and accounting sector is not dealing with the same cyber risk as everyone else.
- The legal and accounting sector has the highest malicious attack rate of any top-five sector in Australia. Of 37 OAIC breach notifications in the first half of 2025, 32 — 86 per cent — were caused by malicious or criminal attack. This sector is not dealing primarily with human error.
- The target profile is deliberate. Law firms hold matter files, trust account records, and privileged communications. Accounting firms hold tax returns, banking data, and client financial statements. The data is actionable, coercive, and valuable on its own.
- A breach here is not just a regulatory event. It is a professional conduct matter. Lawyers operate under a duty of confidentiality. Accountants operate under APES 110. A breach may trigger complaints to the Law Society, CPA Australia, or the Tax Practitioners Board — not just the OAIC.
- Nine named incidents in two years. The Webber register records nine named incidents from 2024 to mid-2026. The OAIC data suggests the actual volume is considerably higher. Most incidents never make the public record at all.
Nine named incidents in the Australian breach record from 2024 to June 2026.
| Year | Organisation | State | What happened |
|---|---|---|---|
| 2026 | Kennedy McLaughlin [4] | QLD | Qilin ransomware; client financial and banking data published online |
| 2026 | LexisNexis [5] | — | Cloud breach exposing legal and government client data; critical supplier to Australian law firms, courts, and federal agencies |
| 2025 | Kelly Legal [6] | QLD | INC Ransom; 400GB+ stolen including HR files from a Queensland law firm |
| 2025 | Legal Practice Board of WA [7] | WA | Dire Wolf ransomware; online services taken offline during active investigation |
| 2025 | MKA Accountants [8] | VIC | Qilin ransomware; internal documents posted to the dark web |
| 2025 | Brydens Lawyers [9] | NSW | Alleged 600GB breach disclosed in March following a February ransomware intrusion |
| 2024 | Nicholsons Solicitors [10] | QLD | Client documents left unprotected after firm closure; ransomware group claimed to have stolen them |
| 2024 | Deloitte [11] | — | Internal communications allegedly leaked; firm stated client data was not affected |
| 2024 | Herron Todd White [12] | — | Data breach; major banks suspended the property valuation firm pending investigation |
Three separate ransomware groups — Qilin, INC Ransom, and Dire Wolf — claimed victims in this sector in 2025 alone. The Nicholsons Solicitors entry carries a specific note: the firm was already closed when the breach was claimed. Client documents were still on systems. The obligation to protect client data does not expire when the practice does.
Legal, Accounting & Management Services NDB notifications in the first half of 2025 — placing this sector fifth among all sectors, behind Health, Finance, Government, and Education. For a sector that most practitioners do not think of as a high-value target, that ranking represents significant exposure. [2]
The Webber Insurance breach register captures 678 named Australian cyber incidents from 2018 to June 2026. Nine involve legal, accounting, or management services firms. That count understates the real picture — it reflects only events that generated media coverage, not the larger volume of incidents that were managed without public disclosure, notified to the OAIC but not reported in the press, or not reported at all.
The trajectory in named incidents is unambiguous: two in 2024, five in 2025, two more in the first six months of 2026.
The structural explanation is not complicated. Professional services firms are attractive for three reasons. First, the data they hold is actionable: bank account details, tax file numbers, financial records, trust account information, and client communications can be used directly for fraud or sold on. Second, many practices operate with limited IT resources and infrastructure that receives less attention than the client work it supports. Third, the confidentiality obligations that make this sector valuable to clients also make a ransomware event more coercive: paying removes the publication threat; not paying risks exactly the kind of disclosure that destroys the client relationship and triggers a professional conduct process.
A mid-size legal or accounting practice holds a data inventory that is more sensitive, and larger in scope, than most principals recognise.
- Client matter files: property, wills, family law, litigation, privileged communications
- Trust account records: client funds, transaction histories, banking details
- Tax returns, BAS records, payroll data, tax file numbers
- Business financial statements and shareholder structures
- Identity documents: passports, bank records, Medicare cards
- Superannuation information and banking credentials
- Strategic documents, board papers, HR data (management consultancies)
- Physical files: years of client records, often with no retention schedule
The common thread is that all three categories hold data that belongs to other people — information the client handed over in confidence, under an implied or explicit professional obligation that it would be protected. When that protection fails, the consequences fall on the client.
Physical records compound the problem. Small practices commonly hold years of client files in paper form with no documented retention schedule and no destruction policy. The Privacy Act applies equally to physical records. A firm that has never asked what happens to the 2012 client file in the storage room is carrying a risk it has not accounted for.
Of Legal, Accounting & Management Services NDB notifications in the first half of 2025 were caused by malicious or criminal attack — the highest ratio of any top-five sector. Only five of 37 notifications were human error. Zero were system faults. [2]
That ratio is the inverse of what OAIC data shows in Education, where 74 per cent of breach notifications are human error. It tells a specific story about this sector: the primary recorded threat is not a staff member sending an email to the wrong address. It is a threat actor who has targeted a professional services firm and has the capability to execute.
The 86 per cent malicious attack rate is not coincidence. Whether it reflects deliberate targeting, chronically low controls, or — most likely — both, the outcome is the same: this sector absorbs a disproportionate share of criminal attack, and most of it lands. A sector where principals treat IT as a necessary evil, and where the IT manager is scraping for budget to put in the most basic technical controls, is not only a deliberate target — it is an easy one. The two dynamics reinforce each other.
This does not mean human factors are irrelevant. The 2026 Verizon Data Breach Investigations Report found that 62 per cent of all breaches still involve a non-intentional human element, and the most common initial access vectors remain compromised credentials and phishing. [13] An employee who reuses a password, responds to a phishing email, or accesses a client system without MFA is still the most likely first step in what eventually becomes a ransomware event. The 86 per cent figure measures how incidents are classified at the outcome level, not how they start.
The implication is that this sector needs to address both layers. Staff training reduces the initial access opportunity. Technical controls — MFA, privileged access management, endpoint protection, isolated backups — determine what happens after initial access occurs. A firm that has trained its staff but left its practice management platform without MFA, or that backs up to a location the attacker can also reach, has addressed the surface but not the depth.
For a small or mid-size legal or accounting firm, the starting point is not a complex framework or a significant capital investment. It is these six controls, applied specifically to where this sector fails.
-
1Implement MFA on everything with a loginPractice management software (LEAP, Clio, MYOB, Xero), email, document management systems, accounting portals, and any client-facing platforms. Compromised credentials are the dominant initial access vector in Australian breach data. MFA does not prevent credentials being stolen; it prevents them being used.
-
2Audit access and remove what is no longer neededFormer staff who retain access to matter management systems. Shared login accounts where individual accountability cannot be established. Service accounts with elevated privileges that have never been reviewed. These configurations are present in every small practice this firm has assessed. They cost nothing to remove and eliminate entire categories of risk.
-
3Test your backupsA backup that has never been restored is an assumption, not a control. Run a restore test on your practice management system and document the result. Ransomware operators routinely target and delete accessible backups before encrypting; a backup that is not isolated from the primary environment is not a recovery option.
-
4Write a one-page ransomware response planThe decision about whether to engage your insurer, notify the OAIC, contact your professional body, and communicate with affected clients cannot be made for the first time at 11pm on a Sunday when systems are down. The plan does not need to be long. It needs to name who calls whom and in what order, before the incident, not during it.
-
5Know your supply chainThe LexisNexis breach in March 2026 compromised data held by a platform that many Australian law firms treat as an essential service. [5] Firms that had given LexisNexis access to their systems or data were affected without being directly breached. Understanding what your practice management platform, legal research tool, or cloud provider can access — and what they do if they are compromised — is a question worth answering now.
-
6Understand your professional obligations before a breach, not afterA breach may trigger notification obligations under the Privacy Act, but also potential obligations to the Law Society, the Tax Practitioners Board, or CPA Australia. Your professional indemnity insurer expects prompt notification. The sequence matters and differs by profession. Coastal Cyber’s Cyber Health Check is designed for professional services firms and identifies your specific exposure before you are managing one.
None of these require significant capital. Together, they represent the difference between an incident that is contained, notified, and recoverable — and one that ends a professional reputation.
The OAIC publishes the list of organisations that have notified a data breach. It is publicly searchable. Clients search it.
The question a principal in this sector needs to answer is not “are we a target?” — the data confirms the answer. The question is whether, if a ransomware group hit the firm’s systems tonight, there would be documented evidence of reasonable steps. Not the intent to take reasonable steps. Not the memory of a conversation at a partners’ meeting two years ago. Documented, evidenced, testable steps.
For a legal or accounting firm, the stakes are higher than for most. A failure to protect client data is not just a regulatory event. It is a breach of the professional duty every client was relying on when they handed over their information. The cost of reasonable steps is not comparable to the cost of the alternative.
That is because it is. Managing data risk in a legal or accounting practice is not one job. It sits across IT, practice management, compliance, professional obligations, and leadership — in a firm that runs on client trust and operates under time pressure that makes internal security projects easy to defer. Doing it without a trusted partner is where most practices stall.
If you are wondering which thread to pull first, that is exactly the conversation worth having with a GRC professional before you spend a quarter going in circles. A few hours of advice early saves weeks of internal debate and considerable professional exposure later.
Book a 20-minute conversation
If your practice’s cyber and privacy posture needs a clear-eyed assessment, start here. No sales process. No commitment. Just clarity on which thread to pull first.