Attacks Are Targeting Smaller Organisations
Ransomware operators are targeting the most vulnerable. Mid-market organisations, running 50 to 1000 users, sit in what we call the “awkward middle.” Large enough to hold data worth stealing, connected enough to serve as entry points into larger supply chains, but too small to staff the kind of 24/7 security operations that make attacks harder to execute undetected.
Attackers know this. They’re counting on it.
What’s Actually Happening in ANZ
These aren’t hypothetical scenarios. These are real breaches affecting real organisations in Australia and New Zealand, all from the second half of 2025.
Defence supply chain: IKAD Engineering
In December 2025, ransomware groups exfiltrated 800GB of data from IKAD Engineering, a specialist defence contractor. The stolen data related to Australia’s Hunter Class frigate and Collins Class submarine programs. This specialised defence contractor was targeted because it did not have enterprise-grade security resources, making it an enticing entry point into a larger defence network.
Healthcare: Manage My Health
Also in December 2025, hackers breached Manage My Health, a patient portal used by over 1.8 million New Zealanders. The method? A valid user password. The attacker got in “through the front door.” More than 120,000 patients had medical records, test results, and prescription details compromised. Managed My Health wasn’t a large hospital with the type of security protections that comes with one. It was a privately owned portal that medical practices across New Zealand would have assumed was secure.
Primary care: Point Lonsdale Medical Group
In October 2025, a small Victorian medical practice discovered that unauthorised access to their email systems had potentially exposed patient data, including health summaries, treatment plans, and referral information. A local GP clinic, dealing with the same data exfiltration techniques deployed against major hospital networks.
SME operations: Benedict Industries
That same month, Benedict Industries, a NSW-based landscaping and recycling firm with approximately 100 employees, had 270GB of company data stolen by the INC Ransom group. HR files. Payroll data. Employee information. A landscaping business, facing the same organised ransomware gangs that typically target enterprises ten times its size.
The Supply Chain Makes Your Security Posture Everyone’s Problem
The targeting logic extends beyond your own data.
If your organisation sits within a supply chain serving government, finance, healthcare, manufacturing or critical infrastructure, your 80-person business isn’t flying under the radar. Attackers will see it as an access path. Nation-state reconnaissance doesn’t stop at enterprise boundaries. The compromise path runs through smaller organisations precisely because they present softer targets.
Unfortunately, this means your security posture isn’t just your problem. It becomes someone else’s breach vector. And when attackers do get in, they already know how to exploit the gap between your tools and your capacity to operate them.
[Read more: How Attackers Breach Mid-Market Organisations →]
The Mid-Market Reality Check
Four things worth sitting with:
- Ransomware demands aren’t proportionally smaller. The ransom your smaller business faces aren’t scaled to your revenue. It’s calculated against the value of the data and your willingness to pay to avoid operational disruption.
- Dwell time runs longer without continuous monitoring. How long attackers operate undetected in your environment averages just as long, sometimes longer, when nobody’s actively watching. Monitoring tools without monitoring teams means alerts pile up unread.
- Cyber insurers evaluate you against the same threat actors. Your insurer isn’t comparing you to other similar-sized businesses. They’re assessing your exposure to the same ransomware groups hitting ASX 200 companies. That’s why premiums keep climbing even though your security budget hasn’t changed.
- Attack economics don’t scale down either. A phishing campaign costs attackers the same whether they target 100 employees or 10,000. Exploit kits work identically against mid-market infrastructure. Command and control systems don’t distinguish based on company size.
You’re facing enterprise-grade problems without enterprise-grade budgets. This is the structural reality we call the mid-market security paradox [Read: The Mid-Market Security Paradox ←], and it runs deeper than the threats alone.
→ Zero Trust Detection & Response (ZDR): Learn More
→ Assess Your Organisation: Request a Security Assessment
→ Close Your Security Gaps: Book a Security Consultation
→ Follow Virtual IT Group on LinkedIn for ongoing insights on security



