Ransomware just hit an Australian construction consultancy — the lesson for every project business
An Australian construction consultancy was listed by a ransomware crew this month. Why project businesses are targets, and the controls that keep sites moving.
This month a ransomware crew added an Australian construction project-management consultancy to its leak site. If your business runs on project data, this one is worth five minutes.
In August 2026 a ransomware group known as Storm listed an Australian construction consultancy among its victims, claiming to hold the firm's internal data. We are not naming the firm — being extorted is not a crime, and they deserve room to recover. But the incident is a clear signal for every project-driven business: the crews have worked out that construction is a soft, high-pressure target.
Why do ransomware crews target construction businesses?
Ransomware crews target construction because the pressure to pay is built into the industry. A builder or project consultancy that loses access to its systems cannot certify progress claims, issue variations, access drawings or pay subcontractors — and every day of delay has a contractual cost attached.
Progress claims stop.
If the claim does not go in, the money does not come in — and cash flow is the thing that kills construction businesses.
The paper trail is the business.
Contracts, variations, site diaries and safety records are exactly what a crew steals before encrypting, then threatens to leak.
Many parties, one weak link.
Head contractors, consultants, subbies and suppliers all email each other constantly — one compromised mailbox can be leveraged against the whole project.
Thin internal IT.
Most construction firms have no dedicated security staff, and attackers know it.
What actually happens when a project business is hit?
When ransomware hits a project business, the encryption is usually the second blow — the data was stolen first. Modern crews exfiltrate contracts, financials and personal information, then encrypt systems and open two negotiations at once: pay to decrypt, and pay again so the stolen files are not published. That is why backups alone are not enough — a backup restores your systems, but it does not un-steal your data.
How does a construction business defend itself?
A construction business defends itself with a short list of controls done properly, not a shelf of products. These are the ones that matter most for project-driven firms:
Multi-factor authentication on everything
email, remote access, the project platform. Most incidents still start with one stolen password.
Immutable, tested backups
copies a crew cannot delete or encrypt, restored and verified quarterly, so the recovery path is proven before you need it.
Separation between office and site systems
so one infected laptop cannot reach everything the business owns.
Someone actually watching
ransomware moves from first foothold to full encryption in hours. Our in-house 24/7 SOC exists to catch that movement while it is still one machine, not the whole company.
A practised incident plan
who isolates, who calls the insurer and lawyer, who talks to clients. See our incident response service for what the first hour should look like.
The insurance and tender angle
There is a commercial upside to getting this right. Head contractors and government projects increasingly ask for evidence of security controls before awarding work, and insurers ask for the same before writing cover. A construction business that can show Essential Eight alignment does not just reduce its risk — it clears tender and insurance hurdles its competitors trip on.
Frequently asked questions
We're a small subcontractor — would a crew really bother with us?
Yes, in two ways: automated attacks do not check your size before encrypting, and small firms are used as the way into bigger ones. Being small makes you a stepping stone, not invisible.
If we have backups, can we just ignore a ransom demand?
Backups solve the encryption problem, not the stolen-data problem. If the crew took contracts or personal information before encrypting, you still face the leak threat and possible notification obligations — which is why prevention and early detection matter as much as recovery.
What should we do in the first hour of a suspected attack?
Disconnect affected machines from the network (do not wipe them), preserve evidence, and call for help — our 24/7 line is 1300 053 948. Fast containment is the difference between one machine and the whole business.
Do we have to report a ransomware incident?
If personal information was taken, the Notifiable Data Breaches scheme likely applies — and if your turnover is over $3 million and you pay a ransom, the payment must be reported to the Australian Signals Directorate within 72 hours. Read our enforcement explainer.
The next step
If this article made you wonder how your own firm would hold up, that is worth acting on. Our construction IT and security page covers how we work with builders and project consultancies, or start with a free cybersecurity health check.
Related Key IT services
More insights
Ransomware reporting now has teeth
Australia's 72-hour ransomware payment reporting rule moved from education to enforcement in 2026…
Read article →RansomwareAustralia's 72-hour ransomware reporting rule
Pay a ransom in Australia and you have 72 hours to report it. From Jan 2026 enforcement applies…
Read article →RansomwareWhy backups alone won't stop ransomware
Ransomware gangs delete backups and steal data before encrypting. Here's why backups alone aren't…
Read article →Book your free IT & Cyber Security Review
See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.