Last week the Direwolf group added Adelaide game studio Mighty Kingdom to its darknet leak site, claiming it had copied more than 260 code repositories — with no mention of anything being locked or encrypted (Cyber Daily). That’s data exfiltration: the unauthorised copying of data out of your network and into someone else’s hands. No scrambled files, no ransom note on the screen — just your information, quietly gone.
This is where a lot of Australian businesses hold the wrong mental picture. We’re trained to imagine a cyber attack as something you’d notice — systems down, staff locked out, a big red demand. Exfiltration is the opposite, and that’s the point. Everything keeps working while the attacker quietly holds your customer records, donor lists or client files and threatens to publish them. Crews like Direwolf increasingly skip encryption altogether and go straight to theft-and-leak, because stolen data pays without the hassle.
So the real question isn’t “can we recover?” — it’s “would we even know data had left the building?” Most small businesses can’t answer that honestly, because no one is watching what leaves. Start there: log and review outbound traffic, tighten who can access and copy sensitive files, and set alerts for unusual transfers. And mind the compliance angle — if the data includes personal information, you may owe the OAIC a Notifiable Data Breach report, encryption or not.
Not confident you’d spot data walking out the door? That’s the gap worth closing. Our team can give you visibility over your data and access before it’s tested — start with our cybersecurity services or a chat about data protection.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
