DragonForce, a ransomware-as-a-service operation with links to LockBit, listed Access Group International on its dark web leak site on 2026-07-11, claiming an estimated attack date of 2026-07-10 and roughly 42 gigabytes of exfiltrated data. The Canning Vale, Western Australia-headquartered firm hires access, material handling, power generation and construction equipment across Australia and the Middle East. Screenshots the gang published show credit applications, tax invoices and a spreadsheet of customer account and contract details — hire dates, delivery dates, site locations (Cyber Daily). As of publication, Access Group International has made no public statement, and there is no confirmation a ransom was paid.
That unresolved detail is precisely why the incident matters as policy, not just as another entry in DragonForce's list of roughly 600 claimed victims. Australia's Cyber Security Act 2024 established the country's first mandatory ransomware and cyber extortion payment reporting regime, requiring any business with annual turnover above $3 million — or any entity responsible for a critical infrastructure asset under the Security of Critical Infrastructure Act 2018 — to notify the Australian Signals Directorate within 72 hours of making, or becoming aware of, a ransomware payment (Cyber Security Act 2024, Part 3; Cyber Security (Ransomware Payment Reporting) Rules 2025). The obligation took effect on 30 May 2025, but Home Affairs ran an explicit 'education-first' grace period through 31 December 2025. Since 1 January 2026, the department has been in active compliance and enforcement mode. If Access Group paid — or pays — DragonForce, this is the kind of mid-sized, non-critical-infrastructure case the regime was built to surface once the training wheels came off.
The case for the rule
The strongest argument for mandatory reporting is that ransomware payments have historically been invisible to regulators. Victims quietly settle through insurers or negotiators, law enforcement learns little, and the state loses the aggregate picture it needs to track which gangs are actually being paid, how much, and by whom. A national ransomware payment ledger — even a incomplete one — lets ASD correlate incidents, warn other likely targets, and feed sanctions and law enforcement referrals with real data instead of dark-web leak-site claims. Treasury and Home Affairs also built in a real incentive to cooperate: information in a ransomware payment report cannot be used as evidence against the reporting entity in civil or criminal proceedings, outside narrow exceptions for false statements (Gadens). That is a genuinely well-designed feature — it tries to buy visibility with legal protection rather than by threatening the victim a second time.
Where the design is still thin
But the regime is narrower, and gentler, than headlines about 'mandatory ransomware reporting' suggest — and that narrowness cuts both ways. The obligation is payment-triggered, not breach-triggered: a company that gets encrypted and doubly-extorted but never pays owes ASD nothing under this Part, even though the national threat picture is arguably just as degraded by an unpaid, unreported intrusion. If Access Group does not pay DragonForce — plausible, given the gang's low ransom-collection rate industry-wide — this incident will generate no report at all under the ransomware-specific regime, whatever other notification duties apply under the Privacy Act or SOCI Act.
The 72-hour clock is also tight for the population it targets. Large critical infrastructure operators have incident response retainers and legal counsel on speed-dial; a privately owned equipment hire firm juggling forensics, customer notifications and insurer negotiations in the same 72 hours is a different proposition. And the penalty for missing the deadline — 60 penalty units, currently $19,800 — is trivial next to plausible six- or seven-figure ransom demands, meaning the rule functions more as a norm-setting exercise than a deterrent with real teeth. That may be the right calibration for a first-of-its-kind regime; a punitive penalty risks pushing firms further into the shadows rather than toward the reporting portal. But it does mean Phase 2 'active enforcement' should be read as active monitoring for compliance culture, not active punishment.
The proportionate path forward
None of this argues for scrapping the regime — a light-touch, payment-triggered, evidence-protected reporting duty is close to the least-restrictive design that still gives government usable data, and it beats prescriptive security mandates that would burden every firm regardless of risk. What Canberra should do next is publish aggregate, anonymised statistics from the reports it has now been collecting under active enforcement for over six months, so the public and industry can judge whether the $3 million threshold is capturing the right population and whether reports are translating into actual disruption of gangs like DragonForce — rather than sitting in a database nobody outside Home Affairs ever sees.