This Isn't Just a Warning.
It's Already Happening.

Every case on this page is a matter of public record — court judgments, regulator actions and named security research. Nothing here is hypothetical.

An aisle of a public records room at night, shelves of bound judgments lit red

Not Warnings.
Public Record.

These aren’t hypothetical scenarios. These aren’t scare stories about stolen email addresses. 

These are real businesses that got taken over.

Ransomware that locked them out of their own systems. 

Attackers who moved in, sat quietly, and destroyed everything when they were ready.

Every one of them had a website.

Every one of them thought someone was looking after it.

An empty formal courtroom at night lit by a single hard red light
Australian Clinical Labs — $5.8m penalty. Federal Court of Australia [2025] FCA 1224.
A filing cabinet with every drawer wrenched open and its contents spilled across the floor
Pressure Dynamics International, WA — 106+ GB of corporate and employee data taken, then published. Cyber Daily exclusive, 2025.
A deserted office with chairs on the desks and the reception shutter down, closed for days
Micon Office National — 34 GB taken, three-day shutdown, and their fourth incident. Cyber Daily, Nov 2024.
A desk telephone handset lying off the hook on a dark desk, lit red
A cloned voice on the phone, €220,000 wired on the strength of it. Wall Street Journal / Trend Micro.
A long rack row of identical compute boards all working in unison under red light
36% of attacks on Australian businesses in 2024 were AI-generated — a higher rate than the US or UK. Cyble Threat Intelligence Report 2024.
A tray of many keys, every one cut to a different pattern, lit red
EvilAI — 114 organisations across three continents, every malware variant unique. Trend Micro Research, Sept 2025.
Icon of a hand holding a key

How a Case Gets
Onto This Page

A named source. Every case cites the court, the regulator or the research team it came from. If we can’t point at a source, it doesn’t go up.

Public record only. Court judgments, regulator media releases, published threat research. Nothing on this page came out of a private engagement.

Their numbers, not ours. Dollar figures, record counts and dates are quoted from the source document. We don’t estimate them and we don’t round them up.

No customer is named. What we find on a client’s site stays between us and them. That is the deal — and it is why there are no company logos anywhere on this page.

This isn’t a portfolio. It’s a reading list — the evidence we hand people who ask whether any of this actually happens to businesses their size.

✓ You can check every one of these yourself.

The case number, the regulator, the research team — all printed on the card. Go and read the source.

A single bound volume open on a desk with a bookmark ribbon, under one green lamp

It's Happening Here.
In Western Australia.

A Western Australian industrial yard at night with one site office lit red from inside

A WA resources company called Inoteq paid an invoice. Someone had been sitting in the email chain, and sent the same invoice again with different bank details. $235,400 went to the wrong account. Only $43,000 came back. When it reached the WA District Court, the court found that Inoteq — the business that got defrauded — was partly liable, because it should have verified the details. [2024] WADC 114.

Pressure Dynamics International services oil, gas, offshore and defence out of WA. DragonForce ransomware didn’t only lock their systems. It took 106 gigabytes of corporate and employee records out the door first — then published them. Cyber Daily exclusive, 2025.

A Perth family law firm was hit by Anubis. The attackers didn’t smash and grab; they moved in and stayed. Client files ended up on the dark web, down to crypto wallet details. Cyber Daily / Lawyers Weekly, 2025.

Three WA businesses. None of them are ours, and none of them thought they were a target.

⚠️ In WA, not knowing has already cost a business money.

The District Court put part of the bill on the company that got defrauded. [2024] WADC 114.

One Report Every
Six Minutes.

Australia reports a cybercrime once every six minutes. These are the published figures — not our estimates.

84,700  cybercrime reports a year in Australia. One every six minutes. ACSC 2024–25.

$56,600  average cost of a single small-business incident, up 14%. That’s a new ute, or an apprentice’s wages for a year. ACSC 2024–25.

309,000  Australian small businesses targeted. Mastercard.

$152.6m  lost to business email compromise in Australia in 2023–24. AFP.

334 million  malicious domains blocked by the ASD in a year — up 307%. ASD 2024–25.

Every figure is lifted from the agency that published it, with the reporting year printed beside it. Go and check them.

⚠️ $56,600 is an average, not a worst case.

The businesses at the wrong end of that average paid a great deal more.

A towering wall of identical pigeonhole slots, every one filled, lit red

When the Regulator
Sends the Bill.

A long empty boardroom table with one chair pulled out and a single closed folder at that seat

$5.8 million — Australian Clinical Labs. 223,000 patient records taken. No multi-factor authentication. Firewall logs kept for one hour. The Federal Court itemised it: $4.2m for failing to secure the data, $800,000 for failing to investigate, $800,000 for failing to report it quickly enough. The first civil penalty ever imposed under the Privacy Act. [2025] FCA 1224, OAIC prosecution.

$2.5 million — Fiig Securities. “Inadequate cybersecurity measures” for more than four years, then a breach. It wasn’t the privacy regulator that came — it was ASIC, under their financial services licence. First time the Federal Court imposed civil penalties for cybersecurity failures under AFS licence obligations. ASIC v Fiig Securities, Federal Court of Australia, 2025.

Part of the loss — Inoteq, WA. Defrauded by an intercepted invoice, and still found partly liable for not verifying the payment details. [2024] WADC 114.

We’re reporting what the courts did to other businesses. What a court would make of yours is not ours to promise — and anyone who tells you otherwise is selling.

⚠️ The court called it a failure to act with care and diligence.

Not a failure to be lucky. A failure to do the ordinary things, and to have a record of doing them.

We Didn't Read A Case Study.
We Ran The Experiment.

Most people selling website security have never watched a live infection happen. They’ve read about them. We wanted to see one with our own eyes, so we set up a target and waited.

One. We built a real website, then did the one thing we tell everyone never to do. We left it alone. No updates. Old plugins. The default settings nobody ever changes — the exact state most people are in the day they first call us.

Two. The moment you switch on the padlock, your site’s name is published to a public list. It has to be. That is how the padlock works. And that list is watched.

Three. Automated scanners read the list and start probing brand-new sites. So a website is at its most defenceless in the exact window when the padlock announces it to the whole internet.

Four. Ours got found, catalogued and broken into — exactly the way we said it would. We didn’t write the malware and we didn’t stage the break-in. A real intruder moved in, actually resident, doing the quiet things they do. From the outside the site kept loading perfectly.

Five. Then we pointed our own monitoring at it. Overwatch surfaced the intruder in four minutes. That is the only test worth running, and you cannot run it on a clean site.

We won’t be naming the site, and it was never a customer’s. It was ours, set up to be a sitting duck on purpose. Whatever our tools caught, and whatever they missed, we found out on our own property instead of on yours.

⚠️ You can’t test a smoke alarm in a house that isn’t burning.

So we lit one. On our own property, on purpose, and we watched it burn.

A small isolated glass enclosure on a bench with one red observation lamp trained on it

This Is Not Identity Theft

A bare office desk with only severed cable ends and a dust outline where the computer stood

Forget the old story about hackers stealing your credit card number. That’s last decade.

What these tutorials teach is total machine takeover.

In the zSecurity demonstration, an AI-assisted backdoor bypassed 93% of the signature-based scanners tested on VirusTotal — 67 out of 72. That is one tested sample, not a guarantee that security software can never detect it.

A compromised website — maybe yours — can also carry a fake CAPTCHA. In the ClickFix attacks documented by Microsoft, the visitor is tricked into copying and running a malicious command, believing it is part of verification. That extra step can install the malware.

Depending on the malware installed, the attacker can gain:

  • Screen recording — watching banking sessions live
  • Keylogging — capturing every password as it’s typed
  • Full remote access — controlling the computer through Discord like they’re sitting in front of it
  • Camera and microphone access — turning the device into a surveillance tool
  • Crypto wallet extraction — AI uses OCR to read seed phrases from screenshots

This isn’t a smash and grab. It’s someone living inside your customer’s computer for weeks. Watching. Recording. Harvesting. Waiting until they’ve extracted maximum value — then selling access to the next attacker.

The computer can keep working normally while the attacker watches. A familiar-looking website and a quiet antivirus are no proof that everything is safe.

Sources: zSecurity demonstration, October 2025; Microsoft’s ClickFix analysis.

The front of an ordinary small commercial building seen from across a dark street at night

None of These Were
Looking Either.

The scan is free, it runs from outside, and it tells you what an attacker can already see from the public internet. No obligation, no card.

In a
Nutshell.

These are other people’s cases, not ours. Every one comes from a court judgment, a regulator’s action, or published security research, and every one names its source.

It is already happening here. A WA resources company, a WA industrial supplier, a Perth law firm. None of them thought they were a target.

The courts have started putting a price on it. $5.8m. $2.5m. And in Western Australia, part of the loss landed on the business that got defrauded.

You won’t see a client logo on this page. What we find on a customer’s site stays between us and them.

And the part nobody else will say out loud: nobody can guarantee you won’t get hit. There is no lock that can’t be picked. The difference is whether you find out in minutes and handle it in the open — or find out from a lawyer.

That’s a smaller promise than “you’ll never get hacked”. It’s also the only one that’s true.

One bound volume lying closed alone on a dark table under a soft green light

Ready to Stop Being a
Sitting Duck?

Every business on this page had a website. Every one of them thought someone was looking after it.