Quick answer
If your business is hit by a cyber attack, disconnect affected devices, change passwords from a clean device and call the Australian Cyber Security Hotline on 1300 292 371. Tell your bank immediately if money has been sent or accounts accessed. IDCARE offers free help for small businesses on 1800 595 170. Check whether you have privacy or reporting obligations. Then plan cash for the weeks systems and invoicing are disrupted.
Key points
- Minutes matter if money has been diverted — call your bank before anything else.
- The Australian Cyber Security Hotline (1300 CYBER1) is the national starting point.
- IDCARE's small business line is free: 1800 595 170.
- The hidden cost is disrupted invoicing and collections — plan cash for that.
- Cyber hotline
- 1300 CYBER1 (1300 292 371)
- Free small business support
- IDCARE 1800 595 170
- Scams
- scamwatch.gov.au
- Unsecured options
- Typically $5,000 to $500,000
A cyber attack doesn’t flood the shop or burn the shed, but it can stop a business just as completely. Ransomware locks the files, the accounting system goes dark, a customer pays a fake invoice, or someone quietly reads the director’s email for a month and then empties an account.
The practical damage is often cash flow. You can’t invoice, you can’t see who owes you, and staff can’t work normally. This page covers what to do first and how to keep money moving. The “Cyber attack” option in our emergency action checklist has it as a tick-list.
What should you do in the first hours after a cyber attack?
- If money has moved, call your bank now. Fraud teams can sometimes stop or recall payments, but only if they hear quickly.
- Disconnect affected devices from the network and Wi-Fi. Don’t wipe them — you may need them for investigation.
- Change passwords from a clean device, starting with email, banking and accounting software. Turn on multi-factor authentication.
- Call the Australian Cyber Security Hotline: 1300 CYBER1 (1300 292 371). It’s the national starting point for advice and reporting.
- Call IDCARE’s small business line (1800 595 170). It offers free, expert support to help small businesses recover from cyber incidents.
- Ring your insurer’s cyber hotline if you have cyber cover. Many policies include incident response.
- Write down what happened and when. Screenshots, ransom notes, suspicious emails and timestamps.
What needs doing in the first week?
- Work out what data was affected. If personal information about customers or staff may have been accessed, read the OAIC’s guidance on Notifiable Data Breaches and check whether it applies to your business.
- Check your reporting obligations more broadly with your adviser, including any ransomware-related reporting rules on cyber.gov.au.
- Restore from backups once your IT provider says the environment is clean.
- Warn customers and suppliers by phone that your bank details haven’t changed and won’t be changed by email. Our guide to payment redirection scams explains why.
- Rebuild your debtor list. Use bank statements and past invoices to work out who owes what, then follow up.
- Map your cash for the next 13 weeks with collections delayed. The shutdown cash runway tool helps.
Who should you call after a cyber attack?
| Contact | Why | Number |
|---|---|---|
| Your bank’s fraud team | Stop or recall payments, secure accounts | Number on the back of your card or your bank’s website |
| Australian Cyber Security Hotline | Advice and reporting | 1300 292 371 |
| IDCARE (small business) | Free recovery support | 1800 595 170 |
| Your IT provider | Containment, clean-up, restore | Direct |
| Your insurer | Cyber cover, incident response | Policy schedule |
| Scamwatch | Report scams | scamwatch.gov.au |
How does a cyber attack hit cash flow?
The loss people expect is the ransom or the stolen payment. The losses that actually hurt are quieter:
| Cash drain | Why it happens |
|---|---|
| Delayed invoicing | Accounting or job systems unavailable |
| Slower collections | Customers unsure which bank details are real |
| Paying staff to redo work | Lost files, manual workarounds |
| IT recovery costs | Forensics, rebuilds, new hardware |
| Lost sales | Website or booking system down |
| Diverted payments | Funds sent to a criminal’s account |
Even a well-run business can find itself short for a few weeks while all this settles. If that’s you, start a short enquiry and a real person will call to talk it through. There’s no credit check when you first enquire.
How do businesses fund the recovery from a cyber attack?
- Unsecured cash-flow funding — typically $5,000 to $500,000, sized on turnover and bank statements. Suits bridging delayed collections and paying recovery costs. See unsecured emergency cash.
- Line of credit — useful where the disruption is uneven and you only want to draw what you need.
- Property-secured loan — suits larger losses such as a diverted supplier payment, from $20,000 to $5,000,000.
- Wages support — if payroll is the pressure point, see paying staff through a crisis.
Illustrative example only: a wholesale distributor’s email is compromised and a customer pays a large invoice to a fraudster’s account. The bank recovers part of it. The business still owes its own supplier on time, so it uses a short unsecured facility to pay and keep its trade terms, and repays it as normal collections resume.
What mistakes make a cyber attack worse?
- Staying quiet with the bank. Every hour matters when money has been diverted.
- Wiping machines too early. Investigators may need logs and devices as they were.
- Resetting passwords on an infected computer. Use a clean phone or device instead.
- Emailing customers new bank details from the compromised account — it trains them to trust the attacker’s emails.
- Assuming it’s over once systems are back. Attackers sometimes return through a forgotten account or forwarding rule; your IT provider should check.
What documents should you save?
- Timeline of the incident, screenshots and suspicious emails
- Report reference numbers (cyber hotline, bank, police if involved)
- IT provider’s incident report and invoices
- Bank statements for the six to twelve months before the attack
- Any cyber insurance policy and claim correspondence
- Your rebuilt debtor and creditor lists
Need funding while systems recover?
A cyber incident can leave a healthy business briefly unable to invoice or collect. If you need a bridge while systems come back, talk to us.
Enquiring is free of credit checks; your file is only looked at once you’ve decided to apply. In a crisis you need fewer calls, not more, so your enquiry stays with one team. Someone who understands crisis recovery reads your enquiry and phones you personally.
Be exact about the figure, the reason, your state and any property in the picture; it saves you a second round of questions. Get the conversation started.
Frequently asked questions
Who do I report a cyber attack to in Australia?
Start with the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371) and the reporting tools at cyber.gov.au. If money was stolen, contact your bank straight away. If personal information about customers or staff may have been exposed, check the OAIC's Notifiable Data Breaches guidance.
Should we pay a ransom?
That's a serious decision to make with specialist advice, not in a panic. Payment doesn't guarantee your data comes back or stays private. Get expert help, check your backups, and check whether you have reporting obligations before doing anything.
Does business insurance cover cyber attacks?
Only if you have cyber cover, which is usually a separate policy or section. Some policies include incident response help, so ring the insurer's hotline early if you have one.
Can I get funding while our systems are down?
Yes, if the business was trading normally before the attack. Unsecured cash-flow funding is sized on bank statements, which your bank can still provide. A property-secured loan is an option for larger amounts.
How do I stop invoice fraud after an email account is compromised?
Warn customers and suppliers by phone that bank details won't change by email, verify any change request by calling a known number, and turn on multi-factor authentication. Scamwatch has guidance on business email compromise scams.