Nick Scali hit by ransomware and reportedly engaging with hacker through an intermediary
August 14, 2026 |
In Australia, it is not illegal to pay a ransome to a hacker. It is illegal not to advise the Government that a ransom has been paid. The process of when and how to report is set out in the Cyber Security Act 2024 (the “CS Act”). Consistent with the Privacy Act 1988 the CS Act only commercial entities operating in Australia with an annual turnover of AUD $3 million or more are covered. As with the Privacy Act there are specific inclusions, in this case critical infrastructure operators.
Under the Act
- if a business pays a ransom, it must report the payment within 72 hours via the Cyber.gov.au Reporting Portal.
- it must report the amount demanded, the amount paid, the type of malware used, and details of any communications with the hackers.
Notwithstanding that payment of a ransom is not criminalised the Government has always maintained a “Never Pay” position. It claims, with some justification that paying a ransom does not guarantee a return of data. That is true. There is a real possibility of hackers not returning the data, or only part of it. Or they copy it before they return it. What is more common is that in providing the key to unlock the ransomware data is often corrupted, to a greater or lesser degree.
Some businesses do pay ransoms and do not notify the Government. How many is not known for obvious reasons. But it does happen.
The Australian reports in Nick Scali hires intermediary to deal with hacker, ransom threat that the company has suffered a ransomware attack that has disrupted its warehouse and dispatching functions. It has engaged a middleman to negotiate with the hacker to “defuse the attack.” That generally means, “how much”, “by what crypto coin” and “where to be delivered”. It is also is
Interestingly customer names and financial details were not accessed, only delivery details. Which is bad enough. That is unusual in the normal course. Unless the security of credit card and personal information was properly protected. Or that the delivery system is a separate system, possibly run by a third party or a subsidiary of Nick Scalli. It is often hard to find out exactly what happened because Australian entities are notoriously unforthcoming about the circumstances of an attack.
The article provides:
An organised gang of cyber criminals have obtained customer details from furniture chain Nick Scali, including residential addresses, after the retailer confessed to being the victim of a security breach.
The cyber criminals, believed to be based offshore, have also sent a ransom request to Nick Scali, but at this stage, it is unknown the precise financial demand.
The cyber security incident has thrown the warehouse and dispatching functions of the $1.43bn Nick Scali network into mayhem with the delivery of furniture orders to customers now delayed. The shutdown of the Nick Scali IT system has meant orders must be processed manually.
Nick Scali has employed an unknown firm, or middleman, to directly communicate with the hackers to defuse the attack. While it is believed sensitive customer data such as credit cards were not obtained by the hackers, they are believed to have gained access to the property addresses where furniture was to be sent, according to a company insider’s account on Thursday morning.
Late on Thursday, Nick Scali confessed to the ASX it is currently investigating a “security incident”. “In light of the security incident, the company elected to take certain systems offline. While we appreciate that this may have caused some delays for, and uncertainty with, customers, we are now in the process of bringing those systems back online,” its ASX statement read.
“We note that the company is continuing to complete sales orders and deliveries. However, our response times to customers are currently slower than normal.”
Nick Scali, whose executive chairman and major shareholder is Anthony Scali, said at this time, the retailer did not have any evidence of unauthorised access using the customer data.
“Our customers remain our key priority.”
Nick Scali has notified the Australian Cyber Security Centre and the Australian Federal Police. “The company will provide further updates as appropriate.”