A cyberattack on Alliance Distribution Services (ADS), the distribution subsidiary of Hachette Australia, has disrupted book supply chains nationally in the lead-up to the Christmas trading period – and produced a working illustration of a coverage question that applies well beyond publishing: when a distributor goes down due to a cyber event, do the businesses that depend on it have a policy that responds? Hachette Australia said unauthorised activity on ADS computer systems was believed to have occurred on July 18. As of August 27, the company had not confirmed a timeline for restoring full operations, and whether a ransomware payment was made has not been publicly disclosed.
The commercial structure of this event is one that insurance brokers encounter across many sectors. Income losses have flowed to independent booksellers and authors who have no direct policy relationship with ADS. Jaye Chin-Dusting, owner of Mary Martin Bookshop in Melbourne, said ADS had previously accounted for 15% to 20% of her shelf stock. Six weeks into the disruption, she was sourcing replacement inventory through channels Hachette had suggested – including online retailer Booktopia and international suppliers – at additional freight cost. “Of course, that then increases the cost of the book because of the freight that comes through,” Chin-Dusting said, as reported by ABC.
This is the scenario contingent business interruption (CBI) coverage is designed to address. However, the product’s response to cyber-caused supplier outages is far from standard. According to Gallagher’s 2026 Cyber Insurance Market Outlook, carriers now commonly require written contracts between policyholders and impacted vendors as a condition of CBI coverage, and some insurers have begun limiting CBI specifically to IT vendor losses while excluding non-IT vendor disruptions entirely. For a bookseller whose distributor is neither an IT vendor nor a named party in their policy, that means the loss sits outside the scope of most standard cyber CBI clauses.
Aon’s March 2026 cyber market report notes that organisations can expect cyber insurers to be increasingly focused on the usage and management of supply chain vendors, with ransomware activity accelerating in retail among other sectors. The implication for brokers is direct: underwriters are tightening scrutiny of supply chain dependencies at renewal, but the coverage responding to those dependencies has not kept pace.
Matthew Warren, director of RMIT University’s Centre for Cyber Security Research and Innovation, said the most likely cause of the ADS disruption was a ransomware attack, in which malicious actors exploit system vulnerabilities through malware before demanding payment. “I imagine it may be more to do with a ransomware attack that has locked down their book distribution system at their main warehouse, and they’re literally trying to find alternate ways to distribute books,” he said, as reported by ABC.
If that assessment is correct and a payment was made, Hachette Australia would be subject to mandatory reporting obligations under the Cyber Security Act 2024 (Cth). As of May 30, 2025, entities carrying on business in Australia with annual turnover exceeding $3 million must report any ransomware payment to the Australian Signals Directorate (ASD) within 72 hours, with civil penalties of up to $19,800 for non-compliance. The Department of Home Affairs moved from an education-first approach to active compliance enforcement from January 1, 2026. Whether any reporting obligation has been triggered in this case is not publicly known, but brokers advising clients in retail, distribution, and logistics should note that non-reporting now carries active enforcement risk.
The incident arrives in an Australian cyber insurance market with structurally low uptake despite favourable conditions. SME cyber insurance penetration in Australia sits at between 5% and 20%, described by Cowbell VP of underwriting and distribution for the UK and Australia, Claud Bilbao, as “definitely an existing protection gap.” Australian Prudential Regulation Authority (APRA) data shows the cyber class posted a positive insurance service result in each of the three most recent quarters: $17 million in September 2025, $10 million in December 2025, and $10 million in March 2026. Cyber premiums fell approximately 10% through 2025, according to EBM Insurance and Risk’s May 2026 market outlook. The combination of profitability and lower pricing creates conditions that should drive take-up – yet uptake is declining. The Australian Institute of Criminology’s Cybercrime in Australia 2025 report recorded a second consecutive annual fall in cyber insurance take-up among those surveyed, down to 3.7% from 4.6% the year before.
The threat environment is running in the opposite direction. Gallagher’s September 2025 Cyber Insurance Market Update identified ransomware as the leading cyber threat, with claims rising 32.5% in 2024 and incidents returning to levels last seen in 2021, with supply chain attacks specifically increasing as threat actors target service providers to reach a wider range of victims. The ASD’s Annual Cyber Threat Report 2024-25 recorded more than 1,200 cyber security incidents – an 11% increase on the prior year – and the average self-reported cost of cybercrime for small businesses rose 14% to $56,600. Warren said the trajectory would not improve. “You’re certainly going to see an increase in these cyber incidents as these cyber attackers start to work out how to use AI to help them with their criminal activities. It’s really a responsibility that organisations have to undertake and own themselves,” he said, as reported by ABC.
In a statement, Hachette said it remained focused on a resolution. “Restoring full operations securely remains our top priority, and we are grateful for the patience and support of everyone across the industry while we work through this,” a spokesperson said, as reported by ABC. Melbourne author Maxine Beneba Clarke drew public attention to the disruption on Instagram, writing that it could mean the loss of a large part of her income, possibly for years. Children’s author Danielle Binks said her planned school visits and September book launch in Adelaide were in doubt because Hachette could not confirm which retailers held stock or supply additional copies.
The ADS incident is a practical prompt for reviewing client programs across any sector reliant on single-distributor or sole-supplier arrangements – food services, retail, manufacturing, and logistics among them. The key questions are whether CBI coverage extends to cyber-caused outages at third-party distributors, whether the distributor is specifically named in the policy, and whether written contract evidence would be required to satisfy a claims trigger under current carrier terms. With carriers now actively restructuring CBI language around IT versus non-IT vendor distinctions, and some limiting cover to named vendors only, a policy that appeared adequate at last renewal may no longer match a client’s actual supply chain exposure. In a market where premiums have fallen and underwriting results are sound, the conditions for addressing that gap are more accessible than they have been in years.