Crisis event · Cyber attack

Cyber attack on your business: recovery steps and keeping cash moving

Ransomware, hacked email or stolen payments? Who to call, what to do in the first day and week, and how to keep the business funded while systems recover.

Updated 1 October 2026 · Emergency Funding editorial team

See if you qualify →No credit check to enquire
Business owner working late on a laptop in a dim office

Quick answer

If your business is hit by a cyber attack, disconnect affected devices, change passwords from a clean device and call the Australian Cyber Security Hotline on 1300 292 371. Tell your bank immediately if money has been sent or accounts accessed. IDCARE offers free help for small businesses on 1800 595 170. Check whether you have privacy or reporting obligations. Then plan cash for the weeks systems and invoicing are disrupted.

Key points

  • Minutes matter if money has been diverted — call your bank before anything else.
  • The Australian Cyber Security Hotline (1300 CYBER1) is the national starting point.
  • IDCARE's small business line is free: 1800 595 170.
  • The hidden cost is disrupted invoicing and collections — plan cash for that.
Cyber hotline
1300 CYBER1 (1300 292 371)
Free small business support
IDCARE 1800 595 170
Scams
scamwatch.gov.au
Unsecured options
Typically $5,000 to $500,000

A cyber attack doesn’t flood the shop or burn the shed, but it can stop a business just as completely. Ransomware locks the files, the accounting system goes dark, a customer pays a fake invoice, or someone quietly reads the director’s email for a month and then empties an account.

The practical damage is often cash flow. You can’t invoice, you can’t see who owes you, and staff can’t work normally. This page covers what to do first and how to keep money moving. The “Cyber attack” option in our emergency action checklist has it as a tick-list.

What should you do in the first hours after a cyber attack?

  1. If money has moved, call your bank now. Fraud teams can sometimes stop or recall payments, but only if they hear quickly.
  2. Disconnect affected devices from the network and Wi-Fi. Don’t wipe them — you may need them for investigation.
  3. Change passwords from a clean device, starting with email, banking and accounting software. Turn on multi-factor authentication.
  4. Call the Australian Cyber Security Hotline: 1300 CYBER1 (1300 292 371). It’s the national starting point for advice and reporting.
  5. Call IDCARE’s small business line (1800 595 170). It offers free, expert support to help small businesses recover from cyber incidents.
  6. Ring your insurer’s cyber hotline if you have cyber cover. Many policies include incident response.
  7. Write down what happened and when. Screenshots, ransom notes, suspicious emails and timestamps.

What needs doing in the first week?

  • Work out what data was affected. If personal information about customers or staff may have been accessed, read the OAIC’s guidance on Notifiable Data Breaches and check whether it applies to your business.
  • Check your reporting obligations more broadly with your adviser, including any ransomware-related reporting rules on cyber.gov.au.
  • Restore from backups once your IT provider says the environment is clean.
  • Warn customers and suppliers by phone that your bank details haven’t changed and won’t be changed by email. Our guide to payment redirection scams explains why.
  • Rebuild your debtor list. Use bank statements and past invoices to work out who owes what, then follow up.
  • Map your cash for the next 13 weeks with collections delayed. The shutdown cash runway tool helps.

Who should you call after a cyber attack?

ContactWhyNumber
Your bank’s fraud teamStop or recall payments, secure accountsNumber on the back of your card or your bank’s website
Australian Cyber Security HotlineAdvice and reporting1300 292 371
IDCARE (small business)Free recovery support1800 595 170
Your IT providerContainment, clean-up, restoreDirect
Your insurerCyber cover, incident responsePolicy schedule
ScamwatchReport scamsscamwatch.gov.au

How does a cyber attack hit cash flow?

The loss people expect is the ransom or the stolen payment. The losses that actually hurt are quieter:

Cash drainWhy it happens
Delayed invoicingAccounting or job systems unavailable
Slower collectionsCustomers unsure which bank details are real
Paying staff to redo workLost files, manual workarounds
IT recovery costsForensics, rebuilds, new hardware
Lost salesWebsite or booking system down
Diverted paymentsFunds sent to a criminal’s account

Even a well-run business can find itself short for a few weeks while all this settles. If that’s you, start a short enquiry and a real person will call to talk it through. There’s no credit check when you first enquire.

How do businesses fund the recovery from a cyber attack?

  • Unsecured cash-flow funding — typically $5,000 to $500,000, sized on turnover and bank statements. Suits bridging delayed collections and paying recovery costs. See unsecured emergency cash.
  • Line of credit — useful where the disruption is uneven and you only want to draw what you need.
  • Property-secured loan — suits larger losses such as a diverted supplier payment, from $20,000 to $5,000,000.
  • Wages support — if payroll is the pressure point, see paying staff through a crisis.

Illustrative example only: a wholesale distributor’s email is compromised and a customer pays a large invoice to a fraudster’s account. The bank recovers part of it. The business still owes its own supplier on time, so it uses a short unsecured facility to pay and keep its trade terms, and repays it as normal collections resume.

What mistakes make a cyber attack worse?

  • Staying quiet with the bank. Every hour matters when money has been diverted.
  • Wiping machines too early. Investigators may need logs and devices as they were.
  • Resetting passwords on an infected computer. Use a clean phone or device instead.
  • Emailing customers new bank details from the compromised account — it trains them to trust the attacker’s emails.
  • Assuming it’s over once systems are back. Attackers sometimes return through a forgotten account or forwarding rule; your IT provider should check.

What documents should you save?

  • Timeline of the incident, screenshots and suspicious emails
  • Report reference numbers (cyber hotline, bank, police if involved)
  • IT provider’s incident report and invoices
  • Bank statements for the six to twelve months before the attack
  • Any cyber insurance policy and claim correspondence
  • Your rebuilt debtor and creditor lists

Need funding while systems recover?

A cyber incident can leave a healthy business briefly unable to invoice or collect. If you need a bridge while systems come back, talk to us.

Enquiring is free of credit checks; your file is only looked at once you’ve decided to apply. In a crisis you need fewer calls, not more, so your enquiry stays with one team. Someone who understands crisis recovery reads your enquiry and phones you personally.

Be exact about the figure, the reason, your state and any property in the picture; it saves you a second round of questions. Get the conversation started.

Frequently asked questions

Who do I report a cyber attack to in Australia?

Start with the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371) and the reporting tools at cyber.gov.au. If money was stolen, contact your bank straight away. If personal information about customers or staff may have been exposed, check the OAIC's Notifiable Data Breaches guidance.

Should we pay a ransom?

That's a serious decision to make with specialist advice, not in a panic. Payment doesn't guarantee your data comes back or stays private. Get expert help, check your backups, and check whether you have reporting obligations before doing anything.

Does business insurance cover cyber attacks?

Only if you have cyber cover, which is usually a separate policy or section. Some policies include incident response help, so ring the insurer's hotline early if you have one.

Can I get funding while our systems are down?

Yes, if the business was trading normally before the attack. Unsecured cash-flow funding is sized on bank statements, which your bank can still provide. A property-secured loan is an option for larger amounts.

How do I stop invoice fraud after an email account is compromised?

Warn customers and suppliers by phone that bank details won't change by email, verify any change request by calling a known number, and turn on multi-factor authentication. Scamwatch has guidance on business email compromise scams.

Checked the free help? Let's fund the gap.

Tell us what happened in about a minute. No credit check when you first enquire, your details stay with one team, and a real person calls you back.

No credit check to enquire

No spray-and-pray

A real person on your case