Insights · Retail security

Ransomware Is Coming For Australian Retail. The ERP Is The Prize.

What recent incidents show about where retail actually gets hit, and the five questions every retail leader should be able to answer this week.

Free 2-minute checkSample

Where are your passwords kept?

Pick the closest to reality, not the ideal.

Your snapshotSample result
68out of 100
Passwords & identity72
Backups & recovery55
People & email64
See your snapshot

Last week, furniture retailer Nick Scali told the ASX it was investigating a cyber incident. Certain systems were taken offline. Customer orders were impacted. That is all the public knows so far, and it is enough, because that one sentence, systems offline, orders impacted, is the entire anatomy of what cyber incidents do to retailers. Not stolen laptops. Not defaced websites. The machinery that takes an order and turns it into a delivery, stopped.

Nobody outside that investigation knows yet what happened or which systems were hit, and this article makes no claim about that. But the shape of the disruption is worth every Australian retailer's attention, because the pattern behind incidents like it is now well documented, and it points somewhere most retailers never look.

01

Retail is the top target, and it is not close

The numbers for Australia are stark. Threat intelligence firm Cyble tracked 92 sales of compromised network access to Australian and New Zealand organisations on criminal marketplaces over the past year, and retail was the most targeted sector of all, accounting for roughly a third of them. In one documented case, access to a large Australian retail chain, including a database with tens of thousands of customer records, was listed with an opening price of 1,500 US dollars.

Read that again. The way into a retail business, sold for less than the cost of one POS terminal.

The broader tide is rising with it. NSB Cyber's Q2 2026 ransomware report recorded a 23.8 per cent rise in ransomware claims across Oceania for the quarter, overwhelmingly Australian victims. The Australian Signals Directorate fielded over 84,700 cybercrime reports in its last reporting year, roughly one every six minutes, and put the average self-reported cost of an incident for a small business at $56,600. Recent months alone have seen claimed or confirmed incidents at an Australian fine jewellery brand, a national beauty retailer, and hospitality groups running point-of-sale across dozens of venues.

~1 in 3initial-access sales target retailCyble, AU/NZ
+23.8%Oceania ransomware claims, Q2 2026NSB Cyber
$56,600average incident cost for an Australian small businessASD
02

Why the ERP is the prize

Ask a retailer what needs protecting and you will hear the POS, the website, maybe the customer database. Almost nobody says the ERP. Yet the ERP is the one system that touches everything: stock, purchasing, supplier payments, pricing, invoicing, and usually the integrations that make the POS and the website work at all.

Ransomware operators do not think in terms of your org chart. They think in terms of blast radius. Encrypt one workstation and you have inconvenienced somebody. Compromise the ERP and the whole business stops at once: stores cannot sell, the warehouse cannot ship, suppliers cannot be paid, and nobody can even see what stock exists. For a criminal deciding where to spend effort inside a compromised network, that concentration of consequence makes the decision for them.

The entry is rarely dramatic. A finance login without multi-factor authentication. A vendor portal integration nobody reviewed after go-live. An ERP server two years behind on updates because it runs fine and touching it is scary.

The systems too important to patch become the systems too compromised to save.

03

The double bind: extortion without encryption

There is a second shift worth knowing about. NSB Cyber's analysis notes that extortion is decoupling from encryption: a growing share of the most damaging attacks now involve stealing data and threatening to publish it, without locking a single file. For a retailer, the stolen ERP and customer data is the leverage, your supplier terms, your margins, your customers' details, and the threat is publication, not downtime.

This matters because backups, the standard answer to ransomware, do nothing against it.

Encrypted files

You can restore encrypted files.

Stolen data

You cannot restore secrecy.

04

The legal clock that starts ticking

Australian law has also moved. Under the Cyber Security Act 2024, businesses with annual turnover above $3 million that make a ransomware payment must report it to the Australian Signals Directorate within 72 hours, with enforcement in full effect since January 2026. Separately, if personal information is likely to have been accessed and likely to result in serious harm, the Notifiable Data Breaches scheme requires notifying affected individuals and the OAIC.

72h

Ransomware payment report

Cyber Security Act 2024: turnover above $3 million, payment reported to the ASD within 72 hours. Enforced in full since January 2026.

NDB

Notifiable Data Breaches scheme

Personal information likely accessed, serious harm likely: affected individuals and the OAIC must be notified.

In other words, the moment an incident lands, a retailer is not just managing recovery. They are managing legal obligations on a clock, insurer requirements with declared controls attached, and customers who will hear about it one way or another. The businesses that handle that morning well are, without exception, the ones that had decided who does what before it happened. That is a rehearsal problem, and it is exactly what a tabletop exercise is for.

05

Five questions for every retail leader

You do not need a security team to make progress this week. You need honest answers to five questions.

  1. Who can log into your ERP from outside the building, and how?Every remote path should require multi-factor authentication, with no exceptions for seniority.
  2. When was the ERP last updated, and who owns that decision?'It runs fine' is not a patching strategy.
  3. What else lives on the same network?If the guest wifi, the music system and the back office can reach the systems that run the business, one infected device anywhere is a path to everything.
  4. If the ERP went down at 8am on a Saturday, what exactly would still work?If the honest answer is 'we are not sure', that is the finding.
  5. Could you prove your security controls to your insurer today?The controls you declared at renewal are what get checked at claim time.
06

Where to start

The fixes that matter most for mid-market retail are rarely expensive. Multi-factor authentication enforced everywhere, networks separated so the checkout does not share a path with the guest wifi, ageing systems updated or isolated, backups tested by actually restoring one, and a leadership team that has rehearsed the bad morning once.

Multi-factor authentication enforced everywhere
The checkout separated from the guest wifi
Ageing systems updated or isolated
Backups tested by actually restoring one
The bad morning rehearsed once

If you want to know where you actually stand, our free check takes two minutes, asks seventeen plain-English questions, and gives you an honest snapshot. No login, no sales call attached: https://app.vintaris.com

Free 2-minute check

Find out where your business actually stands.

Seventeen plain-English questions, an honest snapshot of your security posture, and the gaps worth closing first. No login, no sales call attached.

Prepared and reviewed by the Vintaris security team. General information, not legal advice.