Cybersecurity & Resilience

The 25 Most Common Cyberattacks Australian Businesses Face

Layer 3 IT16 min read

  • Proactive IT
  • Endpoint Security
Laptop on a quiet office desk with a soft blue network visualisation over Australia, illustrating common cyberattacks for Australian businesses

A plain-English guide to the cyberattacks Australian SMBs see most often—phishing, ransomware, credential theft, and more—plus practical steps that reduce risk without enterprise theatre.

Cyberattacks are not abstract “IT problems.” For Australian businesses they show up as locked files, drained bank accounts, spoofed invoices, or a quiet week of credential theft before anyone notices. Knowing the patterns helps boards and operators ask better questions—and stop treating security as a single product purchase.

This guide covers 25 of the most common cyberattacks we discuss with clients, grouped the way they usually arrive in the real world: malware, social engineering, network abuse, software weaknesses, and account takeover. It is informed by partner education from Huntress, rewritten for Australian small and mid-sized businesses rather than US enterprise theatre.

If you want the wider programme view afterwards, start with our cybersecurity basics for Australian SMBs or the Essential Eight guide.

On this page

  1. What counts as a cyberattack?
  2. How we group the threats
  3. Malware-based attacks
  4. Phishing and social engineering
  5. Network attacks
  6. Vulnerability exploitation
  7. Credential and identity attacks
  8. Practical protection for Australian SMBs
  9. Case studies and recovery
  10. How Layer 3 IT can help

What counts as a cyberattack?

A cyberattack is any deliberate attempt to disrupt, damage, or gain unauthorised access to systems, networks, accounts, or data. That can mean encrypting files for ransom, tricking someone into approving a payment, flooding a website offline, or quietly copying customer records.

Attackers rarely use one technique in isolation. Phishing often delivers malware. Stolen passwords enable account takeover. A compromised supplier can become someone else’s back door. The names below are useful labels—not neat boxes.

How we group the threats

Most attacks fall into a handful of families:

  1. Malware — unwanted software that steals, encrypts, spies, or hides other tools
  2. Social engineering — tricking people into trust, clicks, or approvals
  3. Network attacks — abusing connections, DNS, or traffic paths
  4. Vulnerability exploitation — using software or website flaws as the entry point
  5. Credential and identity abuse — guessing, spraying, or replaying passwords and sessions

Australian operators should also keep Privacy Act / APP expectations and the Notifiable Data Breaches scheme in mind when personal information is involved. Controls that look “good enough” overseas may not answer the questions directors ask here.

Malware-based attacks

1. Viruses and malware loaders

Malicious code still arrives through everyday channels: email attachments, “invoice” downloads, and compromised websites. Older-style viruses attach to legitimate files and spread when those files run. Modern campaigns often skip the textbook virus model and drop loaders that fetch the real payload later.

What to do: keep endpoints patched, block risky attachment types by default, and pair email filtering with user reporting. DNS filtering helps when malware tries to call home—see our DNS content filtering guide.

2. Ransomware

Ransomware encrypts files (and often backups it can reach), then demands payment—usually cryptocurrency—sometimes with a second threat to publish stolen data. Entry is commonly phishing, exposed remote access, or stolen credentials.

What to do: immutable or offline backups, tested restores, least-privilege admin accounts, and rapid isolation playbooks. Read backup lessons from real incidents and our disaster recovery services page.

3. Trojans

Trojans pretend to be useful software—fake updates, cracked tools, or “urgent” helpers—then open a path for theft, remote control, or further malware. They rely on deception rather than self-replication.

What to do: software allow-listing where practical, signed update channels, and a clear rule that staff do not install tools from random download sites.

4. Spyware

Spyware watches quietly: browsing, messages, sometimes microphones or cameras. The goal is intelligence—credentials, quotes, customer lists—not noisy disruption.

What to do: endpoint detection that looks for persistence and unusual outbound traffic, plus clear BYOD rules for devices that touch business mail.

5. Infostealers

Infostealers specialise in harvesting browser passwords, session cookies, autofill data, and tokens. They are a major reason “we never clicked anything weird” still ends in account takeover: a single infected home PC can empty a saved Microsoft 365 session.

What to do: phishing-resistant MFA where you can, conditional access, and treating endpoint health as part of identity security. See Microsoft 365 security basics.

6. Worms

Worms spread across networks with little or no user action, often by exploiting unpatched services. They create congestion and can carry secondary payloads.

What to do: patch discipline, network segmentation, and turning off unused services—especially on servers and edge devices.

7. Keyloggers

Keyloggers capture what people type: passwords, banking details, one-time codes typed into forms. They may arrive as spyware components or as part of a broader Trojan package.

What to do: keep browsers and OS current, prefer password managers and MFA, and investigate unexpected browser extensions.

8. Rootkits

Rootkits hide malware and attacker tools from normal security checks. Once installed, they make “clean” scans look healthy while persistence remains.

What to do: reputable EDR with behavioural detection, and a willingness to rebuild hosts that show deep compromise rather than endless clean-up theatre.

Phishing and social engineering

These attacks target people and processes. They remain among the highest-volume risks for Australian offices—especially finance, payroll, and anyone who can approve payments.

9. Phishing

Broad phishing casts a wide net: fake bank notices, parcel scams, fake Microsoft sign-ins, or “shared document” lures. Urgency and fear do most of the work.

What to do: report-button culture, banner marking for external mail, and MFA so a stolen password is not enough.

10. Spear phishing

Spear phishing is researched and personal. The email may reference a real project, supplier, or colleague. Detection is harder because the story fits.

What to do: out-of-band verification for money movement and credential changes; train managers as hard as frontline staff.

11. Whaling

Whaling aims at executives and other high-trust roles—CEOs, CFOs, practice principals. The ask is often a wire transfer, gift cards, or silent approval of a “confidential” deal.

What to do: dual-control payments, callback procedures on published numbers, and executive MFA that is actually enforced.

12. Baiting

Baiting offers something tempting: free software, a “lost” USB in the car park, exclusive downloads. Curiosity installs the payload.

What to do: block unknown USB devices where policy allows, and treat unsolicited freebies as hostile until proven otherwise.

13. Pretexting

Pretexting builds a believable story—“IT support needing your password,” “ATO calling about a refund,” “bank fraud team on the line.” The attacker plays a role until the victim complies.

What to do: verify identity through official channels; never share passwords or MFA codes with callers.

Network attacks

14. Denial-of-service (DoS)

A DoS flood overwhelms a service from a limited source so legitimate users cannot get through. Even short outages hurt bookings, portals, and reputation.

What to do: resilient hosting, rate limits, and a contact path with your ISP or cloud provider before you need it in a panic.

15. Distributed denial-of-service (DDoS)

DDoS uses many compromised devices at once. It is harder to filter and often used for extortion or disruption.

What to do: CDN / DDoS protection for public sites, and keep secondary communication channels (phone, status page) ready.

16. Adversary-in-the-middle

Also called man-in-the-middle: the attacker sits between you and a service—often on hostile Wi-Fi—to steal or alter traffic.

What to do: prefer known networks and VPN for sensitive work; teach staff that “free cafe Wi-Fi plus banking” is a bad combination.

17. DNS spoofing

DNS spoofing (cache poisoning) redirects a trusted name to a malicious IP. Users think they opened the real bank or Microsoft page.

What to do: secure DNS resolution, HTTPS awareness, and DNS filtering that blocks known-bad destinations—covered in our DNS filtering article.

Vulnerability exploitation

18. SQL injection

Attackers send crafted input into website forms so the database runs unintended commands—dumping data or bypassing login.

What to do: keep CMS and plugins patched, use parameterised queries, and treat public forms as hostile input. Website hygiene belongs in website maintenance and security thinking as much as “antivirus.”

19. Cross-site scripting (XSS)

XSS injects scripts into pages other users view, often to steal sessions or rewrite content.

What to do: patch web apps, sanitise input/output, and limit who can post HTML into customer-facing sites.

20. Session hijacking

If an attacker steals a session cookie, they can act as the logged-in user without the password.

What to do: HTTPS everywhere, short session lifetimes for admin portals, and endpoint controls that reduce cookie theft via malware.

21. Zero-day exploits

Zero-days abuse flaws with no public patch yet. They are rarer for typical SMBs than phishing—but devastating when aimed at popular edge software or browsers.

What to do: rapid patching when fixes appear, reduce exposed services, and keep defence-in-depth so one unknown flaw is not the only gate.

Credential and identity attacks

22. Brute force

Automated guessing against a login until something works. Slow accounts and noisy logs are common side effects.

What to do: lockouts or throttling, ban common passwords, and MFA on internet-facing admin portals.

23. Password spraying

Instead of hammering one account, attackers try a few common passwords across many users—less likely to trip lockouts.

What to do: block known-bad passwords, monitor impossible travel / unfamiliar sign-ins, and enforce MFA broadly. Essential Eight multi-factor authentication guidance is summarised in our Essential Eight guide.

24. Credential stuffing

Stolen username/password pairs from one breach are replayed against Microsoft 365, Xero, banks, and webmail. Password reuse turns someone else’s incident into yours.

What to do: unique passwords (managers help), MFA, and dark-web / breach monitoring where it earns its keep.

25. Supply chain attacks

Attackers compromise a trusted vendor, update channel, or library so malware arrives through something you already allow. Defenders struggle because the package “looks legitimate.”

What to do: minimise third-party admin rights, prefer vendors with clear security practices, stage updates, and monitor unusual behaviour after software changes. Pair this with a managed security posture on our cybersecurity services page rather than hoping procurement alone will catch every risk.

Practical protection that fits Australian SMBs

You do not need every enterprise tool on day one. You do need a short list you can sustain:

  • Identity first: MFA, fewer global admins, conditional access where licensed (Microsoft 365 security basics)
  • Email and web filtering: stop the easy deliveries; DNS filtering adds another layer
  • Patched endpoints and servers: close the worm and exploit paths
  • Backups you have restored recently: ransomware plans fail without evidence
  • Clear payment and access procedures: defeat whaling and pretexting
  • An Essential Eight-shaped roadmap: prioritise, do not theatre—see the Essential Eight guide

Layer 3 partners with specialist security platforms (including Huntress) where managed detection earns its place beside everyday IT hygiene. Tools help; ownership and follow-through matter more.

Case studies: how big incidents unfolded—and what recovery looked like

Large organisations get hit for the same reasons smaller ones do: identity gaps, exposed access, and supply-chain trust. The difference is scale. A few standout cases from recent years show what “recovery” actually involved when the stakes were public.

Medibank (Australia, 2022) — data theft and extortion

In October 2022, Medibank disclosed a cybercrime event involving stolen customer data and later confirmed it would not pay a ransom, citing expert advice that payment was unlikely to secure the data and could put more people at risk. The company worked with specialised responders, the Australian Cyber Security Centre (ACSC), and supported an AFP investigation, while expanding customer support (identity protection, wellbeing, and hardship measures) and commissioning an external review. Official updates remain on the Medibank newsroom and in Australian Government briefings such as the Department of Infrastructure summary.

Takeaway for SMBs: recovery is not only “systems back online.” For privacy events it includes notification, customer support, regulator engagement, and a deliberate ransom decision—aligned with Australian Notifiable Data Breaches expectations.

DP World Australia (2023) — contain first, then restore operations

In November 2023, DP World Australia detected unauthorised access to its corporate network and disconnected from the internet to contain the incident—temporarily disrupting land-side port operations across major terminals. Ports recommenced after successful system testing a few days later; within about ten days of detection the company reported clearing a backlog of more than 30,000 containers. Its later statement confirmed the incident was confined to Australian operations, that no ransomware was deployed, and that some employee personal information had been exfiltrated, with support offered via IDCARE and related services. See DP World’s official incident update.

Takeaway for SMBs: decisive containment (isolate, then rebuild confidence with tests) often beats hoping a compromised network can be “cleaned in place” while operations continue as normal.

Colonial Pipeline (United States, 2021) — ransomware on critical infrastructure

In May 2021, Colonial Pipeline proactively shut down pipeline operations after a DarkSide ransomware incident that disrupted fuel delivery along much of the US East Coast. The US Department of Energy timeline notes the system restarted about a week later. The company paid a cryptocurrency ransom; the FBI attributed the attack to DarkSide, and the US Department of Justice later announced seizure of a large portion of the ransom proceeds. Public reporting also emphasised that business continuity and backups mattered more to restoring operations than the decryption tool alone.

Takeaway for SMBs: paying a ransom is not a recovery plan. Tested restores, isolation playbooks, and working with authorities matter more than hoping a decryptor arrives quickly.

Change Healthcare (United States, 2024) — ransomware with nationwide ripple effects

In February 2024, a ransomware attack on UnitedHealth Group’s Change Healthcare subsidiary disrupted medical claims, pharmacy, and payment flows across much of the US health system. UnitedHealth’s April 2024 update described phased restoration (pharmacy and claims prioritised) and temporary financial support for affected providers while systems were rebuilt. Recovery ran for months—not days—because the platform sat in the middle of many organisations’ billing workflows.

Takeaway for SMBs: if a critical supplier goes down, your incident response includes manual workarounds and cash-flow contingencies, not only your own firewall. Map which vendors you cannot operate without.

These cases reinforce the earlier list: ransomware, credential theft, and supply-chain trust failures are not theoretical. Australian operators should pair technical controls with rehearsal—exactly the theme of our Essential Eight guide and backup lessons from real incidents.

How Layer 3 IT can help

Layer 3 delivers cybersecurity and managed IT services from Newcastle—Hunter Valley and Brisbane metro on-site, Australia-wide remotely. We help businesses translate attack names into controls that fit lean teams: identity, email, endpoints, backup, and incident-ready reporting.

If you want a structured review without a hard sell, contact Layer 3. For foundations first, read cybersecurity basics for Australian SMBs.

← Back to all articles