A ransomware group calling itself CMD Organization has listed Tasmanian multi-technology and building services firm Contact Group on its dark web leak site, auctioning the allegedly stolen data to the highest bidder - 10 bitcoin at the time the leak site was viewed. Contact Group has not confirmed the incident. The claim follows a confirmed attack by the same gang in April, when a Goodstone Group spokesperson told Cyber Daily, "On April 18, 2026, The Goodstone Group began responding to a cyber security incident," after hackers published employee passport scans and financial documents from the Tasmanian hospitality operator.
Two Tasmanian firms targeted by one group inside four months reflects a pattern insurance broker Gallagher has advised clients on: small businesses are increasingly breached not through their own systems, but through vendors and technology partners.
In a case study, Gallagher described a small Australian business whose ransomware attack was traced back to infrastructure managed by its managed service provider (MSP), where investigators discovered encrypted systems and ransom notes linked to one of the world's most active ransomware-as-a-service groups. The business faced a ransom demand of approximately US$100,000 ($142,633) and, as a firm handling sensitive client data, the incident raised concerns about client trust and the potential for reputational damage and regulatory scrutiny tied to the theft of data.
Gallagher's report sets out who carries the greatest exposure and what to do about it. On risk: professional services firms - including accounting, legal and consulting businesses - often hold large volumes of sensitive client and commercial information, which can be highly valuable to attackers. Businesses that rely heavily on managed service providers, cloud platforms and other third-party technology partners face additional risk if those partners suffer a cyber incident, and organisations offering remote system access face increased exposure if permissions aren't regularly reviewed.
Gallagher's core message to clients is direct: "If your suppliers or technology partners are exposed, so is your business. In an interconnected environment, their security standards matter just as much as your own." It also stresses timing: early action can help contain an incident, reduce disruption and support a faster recovery - understanding who to contact and what steps to take before an incident occurs can make a significant difference.
On what cover should deliver, Gallagher points to more than a payout. In its case study, within hours of contacting the insurer's emergency response hotline, specialist cyber incident-response teams were mobilised to investigate the breach, contain the threat and help the organisation navigate the crisis, while legal advisers guided the business on notification requirements. Gallagher said it had proactively negotiated the client's policy to address its specific risks and exposures, then helped coordinate access to specialist response services during the incident.
The exposure Gallagher describes reflects a broader trend. Verizon's 2026 Data Breach Investigations Report recorded third-party involvement in 48% of all breaches analysed globally - the highest share in the report's history and a 60% jump on the prior year's 30%. Locally, the Australian Signals Directorate has flagged the same shift: an organisation's supply chain can often be its weakest link, with malicious actors exploiting trusted vendor-customer relationships to steal information or deliver malware. Yet only around one in five Australian small and medium-sized businesses carries standalone cyber insurance.
Brokers are encouraged to check that a client's cover extends to breaches starting at a vendor, not just their own systems - especially for clients who outsource IT, and in data-heavy sectors like professional services and healthcare.