The privacy regulator just published the worst annual breach numbers since mandatory reporting began — and legal services made the most-affected list again. This fortnight: a record year the OAIC would rather not be reporting, a critical ACSC alert that probably applies to your firm's own website, hard numbers showing ransomware gangs have repriced what your files are worth, and a Patch Tuesday so large it broke records.
🔐 4 things law firm leaders should know right now:
1. The OAIC posts a record year — and legal services is on the leaderboard again.
On 6 July the Office of the Australian Information Commissioner released its 2025 numbers: 1,205 data breach notifications for the calendar year — up 8% on 2024 and the highest annual total since the Notifiable Data Breaches scheme began in 2018. Malicious or criminal activity caused 716 of them, with hacking the leading culprit. Health providers topped the sector table, but look further down the list and there it is: legal, accounting and management services, once again among the most-affected sectors in the country. Two things to sit with. First, these are only the breaches assessed as likely to cause serious harm — the reportable tip of a much larger iceberg. Second, your sector isn't an occasional visitor to this list; it's a permanent resident. The OAIC has also released a new quick reference guide on assessing a suspected breach and deciding whether notification is required — worth putting in front of whoever owns your incident response plan this week, because working that out for the first time mid-incident is how firms blow the 30-day assessment window. [OAIC / Digital Watch]
2. A critical ACSC alert that almost certainly applies to your firm's website.
On 9 July the ASD's ACSC issued a critical-rated alert: a large-scale global campaign is actively exploiting vulnerabilities in website content management systems — with Australian small and medium businesses specifically affected. Attackers are mass-scanning for vulnerable CMS platforms and plugins (WordPress plugins feature heavily, alongside Joomla and Craft CMS), then using unauthenticated file-upload and remote-code-execution flaws to plant webshells — malicious scripts giving them ongoing remote control of the web server. From there: credential theft, malware distribution to your site's visitors, or a quiet foothold for a deeper intrusion. Why this is a law firm story: your firm's website almost certainly runs on WordPress, built by an agency years ago, with a stack of plugins nobody has audited since. A webshell on the site that carries your brand — and possibly your client portal — is both a security problem and a reputational one. Two questions for your web provider this week: "What CMS and plugins does our site run, and when were they last updated?" and "Have you reviewed our server logs for signs of compromise since the 9 July alert?" Vague answers are themselves an answer. [Cyber.gov.au]
3. Ransomware gangs have repriced your files: legal-sector demands up 60% in a year.
QBE's supplementary threat report on the legal and professional services sector, now getting wide coverage, puts numbers on what the incident lists have been telling us. Average ransom demands against legal-sector organisations climbed roughly 60% in a single year — from about US$383,000 to US$611,000, close to A$930,000 — while attack volumes against the sector rose 54% over the same period. Professional services ranked among the top three most-targeted industries globally in 2025 and has held a top-five position into 2026. Read that alongside item #1 and the picture is coherent: attackers have worked out precisely what privileged material, settlement funds and client trust are worth, and they're pricing accordingly. One more shift worth knowing: phone-based social engineering is now the second most common way attackers get in, and at least one extortion crew has made a specialty of ringing lawyers directly while posing as the firm's IT helpdesk to get remote access. The phishing email now has a voice — see this fortnight's tip. [Insurance Business / QBE]
4. A record Patch Tuesday: 622 fixes, 416 of them for Windows.
Microsoft's July update, released 15 July, addressed 622 vulnerabilities — a record — including a record-breaking 416 in Windows alone. For a law firm the significance isn't any single CVE; it's the volume. Every fee-earner laptop, practice-management server and reception PC in your firm is carrying some slice of those 416 flaws until the update lands, and attackers reverse-engineer patches into working exploits within days of release — unpatched exploitation remains the number-one way networks get breached. The question for your IT provider is not "are we patching?" (everyone says yes) but "what percentage of our machines had the July updates installed within 14 days — and can you show me?" If they can't produce that number, patching at your firm is a hope, not a process. [Cyber Daily]
🔧 Tool: WPScan (free)
WPScan is a free scanner backed by the largest database of known WordPress vulnerabilities — it checks a site's WordPress core version, themes and plugins against every published flaw, including the ones being actively exploited in the campaign behind item #2. This is the fastest way to turn the ACSC's alert from an abstract warning into a concrete answer about your site. You don't need to run it yourself: ask your web provider to run WPScan against your firm's site this week and send you the report. A clean scan takes minutes and costs nothing. A provider who won't run it — or won't show you the results — has just told you how your site is being maintained. → wpscan.com
💡 Tip: No remote access from an inbound call. Ever.
Attackers targeting law firms are now phoning fee-earners directly, posing as the firm's own IT support, and talking them into installing remote-access software — no malware, no dodgy link, just a confident voice. Kill it with one rule: nobody grants remote access, resets a credential, or installs software at the request of an inbound call — no matter who the caller claims to be. Hang up, and call IT back on the number the firm already holds. It's the callback rule from last edition's payment scams, applied to your systems instead of your trust account. Put it in writing this month, and make sure reception and PAs get it too — they're called first.
📖 Resource:
Item #1 is the regulator counting breaches. Item #3 is what the demand letter will say when it's your turn. If your leadership team has never actually rehearsed the space between those two — do we pay, who calls the OAIC, what gets reported to the ASD and when — that's precisely what my CPD-accredited session recreates. "Navigating a Cyber Breach: A Live Decision-Making Experience" runs your leadership team through a live ransomware simulation using my Colour Code Method™ — built to help a firm survive the attack, not just talk about preventing it. Built exclusively for legal-sector leaders.
Cyooda: Navigating a Cyber Breach — [Aug 19 10am] — [register your interest here →]
💬 Quote:
"Even entities with the strongest defences may experience a data breach." — Carly Kind, Australian Privacy Commissioner
Something here worth a 15-minute conversation? → [Book a Cyber Chat]
— John
The Legal Cyber Brief — monthly cyber intelligence for law firm leaders. Threats, regulatory shifts, and practical tools from the field. No fluff.
The Legal Cyber Brief — monthly cyber intelligence for law firm leaders.