Ransomware in 2026 rarely starts with a skull wallpaper and a locked screen. It starts with an email that looks like a colleague, a supplier, or Microsoft. Proofpoint’s 2026 AI-Era Ransomware Report found that 67% of Australian organisations hit by ransomware said AI made the attack more effective — mainly by making phishing, impersonation, and credential theft more convincing.
Seventy percent of those Australian incidents involved data theft, not just encryption. Paying to “unlock the files” does not rewind a copy of your customer list sitting on someone else’s laptop. This is what businesses in Melbourne and across Australia should actually change.
Quick Navigation
It Starts in the Inbox, Not on the Desktop
In Australia, Proofpoint reported phishing and email social engineering as the initial entry in 37% of ransomware incidents. Malicious attachments and links were the most common initial threats (47%), followed by business email compromise (38%) and conversation hijacking (26%). Endpoint antivirus still matters. It is not where most of these stories begin.
Phishing
A login page or attachment that looks routine. AI has removed the spelling-mistake tell.
Stolen identity
Once they have a mailbox, they send the next invoice from you. Customers have no reason to doubt it.
Extortion
Data is copied out. Encryption may come later — or not at all. The leak threat is the leverage.
Treat It as a People and Identity Problem
If you only buy more endpoint tools, you are preparing for the last decade’s ransomware. 2026 attacks exploit trust: a real-looking email, a familiar voice, a one-time code typed into the wrong box.
- ✓ MFA on every mailbox and remote login. Prefer an authenticator app or a hardware key over SMS where you can. Never read a code out over the phone.
- ✓ Make reporting easy. A “report phishing” button and a no-blame culture. The first person who spots a fake invoice is doing you a favour.
- ✓ Lock down who is a global admin. One compromised owner account should not equal the whole tenant.
- ✓ Have someone to call after hours. Attackers do not work business hours. Neither should your only response plan.
Ask What Protects the Tools That Protect You
In August 2026 the Australian Cyber Security Centre warned that attackers were actively exploiting remote monitoring and management (RMM) software used by managed service providers. If a provider’s management platform is exposed to the internet and unpatched, every customer they manage is in the blast radius.
Fair questions for any IT provider — including us
- 1.Is your remote management stack patched, and is the console exposed to the whole internet?
- 2.How do you get into our network — MFA, named accounts, logging?
- 3.If you were hit, how would we find out, and how fast?
- 4.Are our backups offline or immutable enough that a wide-open management tool could not encrypt them too?
You do not need the CVE numbers. You need a provider who patches quickly and does not leave the keys to your office on a public login page.
Backups Attackers Cannot Quietly Encrypt
A backup that is always connected to the same network the ransomware is on will get encrypted too. Separate copies, versioning, and a restore test are the difference between a bad week and a closed business.
Not enough
A USB disk in the drawer, an external drive that stays plugged in, or “it’s in OneDrive” with no other copy.
Much better
A cloud backup with version history, a copy the malware cannot see, and a restore you have timed — including Microsoft 365 mail and files.
Five Things To Do This Week
- 1.Turn on MFA for every Microsoft 365 (or Google) account. No shared passwords on a sticky note.
- 2.Tell staff: unexpected payment or login requests get verified on a second channel.
- 3.Ask your IT provider the four questions above. Write down the answers.
- 4.Confirm you have a backup of email and files that is not only sitting on the same PCs.
- 5.Save an after-hours number. If a mailbox is hijacked on Saturday, waiting until Monday is how invoices go out in your name.
Want 24/7 Eyes on This?
Local support, MFA done properly, backups that restore, and someone to call when the convincing email already got clicked.