●  Melbourne-based · Local support you can actually reach
← All insights
Cyber security

A top-tier law firm got breached. The lesson isn't the one you'd expect

In 2023, one of Australia’s largest law firms, HWL Ebsworth, was hit by ransomware. The ALPHV gang, also known as BlackCat, claimed to have taken around four terabytes of data. When the firm refused to pay, the attackers published more than a terabyte of it, over a million documents, on the dark web. The material reportedly included sensitive client files, and the firm’s clients included government departments and a major bank. Even the national privacy regulator turned out to be a client whose files were caught up in it.

When a firm of that size and sophistication gets hit, the natural reaction from a smaller practice is “well, that’s a big-firm problem”. It’s the wrong lesson, and getting it wrong is how small firms end up exposed. Here’s what the HWL Ebsworth breach actually teaches the rest of us.

A big target, but the same doors

A large firm is a bigger target, no question. There’s more data, and more reason for a serious criminal group to spend effort. But size doesn’t change how the attackers get in. Ransomware groups, whether they’re hitting a national firm or a four-person practice, overwhelmingly come through the same handful of doors: a phishing email, a stolen or reused password, a system that wasn’t patched. The scale of the prize differs. The method usually doesn’t.

And a small firm has less room to absorb the hit. A national firm has the resources to weather the storm, the legal and PR teams, the cash. For a small practice, a serious breach can be the thing that ends it.

You don’t beat this by outspending it

Here’s the part worth sitting with. HWL Ebsworth had resources a small firm can only dream of, and it was still breached. That tells you the protection was never really about budget. It’s about whether the fundamentals are actually in place and kept running, day in and day out. A small firm with the basics genuinely managed can be in better shape than a large one where they’ve quietly lapsed.

That’s the encouraging bit. The things that matter most aren’t expensive. They’re just unglamorous, and they have to be maintained.

You can’t pay your way out either

HWL Ebsworth refused to pay the ransom, reportedly around five million dollars. That was the right call. Paying funds organised crime, marks you as someone who pays, and guarantees nothing. But notice what happened anyway: the data still got published. Refusing to pay was correct, and it didn’t undo the damage.

The lesson is blunt. There’s no version of this where you buy your way back to safety after the fact. The only real protection is not getting to that point. That means two things working together: stopping the attack getting in, and being able to recover if it does, from tested, offline backups, without the attacker’s help.

Protect the data, not just the systems

Modern ransomware does two things at once. It locks your systems, and it steals your data to publish if you don’t pay. This is why “we have backups” isn’t a complete answer anymore. Backups get your systems back. They do nothing about the copy of your clients’ confidential files now sitting on a criminal’s server.

So protecting the data itself matters as much as protecting the systems: limiting who can reach what, so a single compromised account can’t hoover up the whole firm; multi-factor authentication so accounts are hard to take over in the first place; and only holding the sensitive data you actually need.

The fundamentals that move the needle

None of this is exotic. For a small firm, the list that does the heavy lifting:

  • Multi-factor authentication on every account
  • Patching, promptly and consistently
  • Least-privilege access, so no one account opens everything
  • Tested, offline backups you’ve actually restored from
  • Staff trained to spot phishing
  • A plan for the first 24 hours, written before you need it (we covered the first hour after a breach separately)

The takeaway

The headline was a giant firm. The lesson is universal, and it’s almost dull: size makes you a target, but the basics, actively managed, are what keep you standing. Nobody can promise you’ll never be hit. What you can control is whether the doors are closed and whether you could recover if one were forced. For a small firm, that’s not a budget question. It’s a discipline question, and it’s a very answerable one.

Are your firm's basics actually managed?

Book a free Security X-Ray. In a few days you'll know how your firm tracks against the fundamentals that matter most, and the simplest gaps to close.

Actively managed IT

Want your protection this clear?

Every article here comes from how we look after Melbourne businesses every day. See where your business stands, and what “actively managed” really feels like.

Book a free assessment

Or explore cyber security in Melbourne.