Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Exclusive: NSW accounting and advisory firm allegedly hit by SafePay ransomware

Threat actors have claimed a cyber attack on an NSW-based accounting and advisory firm and are threatening to leak allegedly stolen data in just a few days.

Tue, 21 Jul 2026
Exclusive: NSW accounting and advisory firm allegedly hit by Safepay ransomware

The firm, AC Small Maxwell & Co, is a Grafton, NSW-based boutique accounting and advisory company that has been servicing the Clarence Valley region since it was founded in 1916 by Ambrose Cecil Small. The company offers accounting and taxation, financial planning, payroll admin, estate planning, SMSF, and other services.

AC Small Maxwell & Co was listed on the dark web leak site of the SafePay ransomware gang, which set the date for the release of the allegedly stolen data to just over two days from the time of writing.

However, the threat actor provided no information about the cyber attack, nor did it provide any form of data sample or other evidence to verify its claims.

 
 

Cyber Daily has reached out to AC Small Maxwell & Co for more information.

Who is SafePay?

SafePay was first observed in October 2024 and has since claimed more than 500 victims.

The group has been observed targeting businesses in Australia, the United Kingdom, the United States, Italy, New Zealand, Canada, Belgium, Brazil, Germany, Barbados, and Argentina.

According to the group, it is not a ransomware-as-a-service (RaaS) operation.

“SafePay ransomware has never provided and does not provide the RaaS,” SafePay said on its leak site.

In June, the threat group claimed a cyber attack on a major Australia-based real estate firm, Harcourts.

Speaking with Cyber Daily, Harcourts has confirmed it is aware of the claim and has launched an investigation.

“We are aware that an external party has made a claim about our company online,” said a Harcourts spokesperson.

“As soon as we became aware of this claim, we took immediate steps to engage specialist cyber security experts to commence an urgent investigation. We have also introduced containment measures to reduce risk and strengthen the security of our environment while we continue our investigation.”

The firm added that while it was in the early stages of its investigation, it had yet to note any evidence of impact.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags:

Daniel Croft

Born in the heart of Western Sydney, Daniel Croft is a passionate journalist with an understanding for and experience writing in the technology space. Having studied at Macquarie University, he joined Momentum Media in 2022, writing across a number of publications including Australian Aviation, Cyber Security Connect and Defence Connect. Outside of writing, Daniel has a keen interest in music, and spends his time playing in bands around Sydney.