Ransomware activity continues to affect organisations across Australia, with new victims appearing regularly on dark web leak sites operated by cybercriminal groups.
In 2025, 24.3% of organisations paid ransomware demands, up from 14.4% the year before. Attackers have been getting better at finding the information most likely to force a payment.
What we are seeing on ransomware leak sites
Groups now run highly automated operations. Access brokers, phishing kits and credential harvesting tools let them test thousands of organisations at once.
Instead of targeting only large corporations, attackers now rely more on volume. They scan broadly and exploit whichever organisation has the weakest defences.
This shift means more SMBs are appearing on ransomware leak portals.
A few days ago, a major NSW orthodontics provider was named on the leak site of Safepay, a relatively new ransomware extortion group.
The listing first appeared on 6 March, with files allegedly published several days later. At the time of writing the incident has not been publicly confirmed by the organisation and the full scope of the breach has not been independently verified.
Why healthcare providers are often targeted
Healthcare and dental practices store highly sensitive personal information.
This can include names, contact details, treatment records, billing information and insurance details. Administrative systems may also contain staff records, financial documents and internal communications.
Attackers aren’t interested in treatment plans themselves. The value lies in the identity and financial information that sits behind them.
Their goal is to use the data for identity fraud, phishing campaigns or secondary extortion attempts. Many clinics also retain records for years, which increases the potential impact if systems are compromised.
Who is Safepay
Safepay is a relatively new ransomware operation that has appeared on several dark web monitoring platforms over the past year.

Safepay leak site branding, including the group’s public claim that it does not operate as a ransomware as a service model.
The group follows the same operating model used by well known ransomware operations such as LockBit and Akira. Attackers gain access to a network, steal data and then threaten to publish it unless a ransom is paid.
Gridware tracks a wide range of ransomware leak sites as part of ongoing threat monitoring. We’re seeing more of these newer groups emerge as AI lowers the barrier to building and running cybercrime operations.
Why attack a small business?
Many people assume ransomware groups only pursue large enterprises. They used to. But the reality today is very different. Phishing kits and credential harvesting tools let attackers attempt thousands of intrusions at once, with convincing AI-generated English.
So instead of searching for a single high value target, many groups now rely on volume. They scan widely and exploit whichever organisation has the weakest defences.
Healthcare providers, dental clinics and other small family practices often become victims because they manage sensitive data while operating with limited security resources.
For ransomware operators, this means quick opportunities for extortion. And as automation increases, more organisations are finding themselves in scope**.**



