Qilin ransomware gang lists Melbourne firm MKA Accountants as a victim
- Organization
- MKA Accountants
- Exploit
- Ransomware
- Industry
- Professional Services
MKA Accountants, an accounting and business advisory firm based in Moonee Ponds in Melbourne's north west, was named on the darknet leak site of the Qilin ransomware operation in May 2025. The leak-site monitoring service Ransomware.live recorded the listing on 15 May 2025 and dated the underlying attack to 14 May.
Qilin posted twelve documents alongside the listing as proof of access. Cyber Daily, which first reported the incident, described the sample as containing internal correspondence, financial statements and insurance records. The gang did not publish a ransom demand, a deadline, or an estimate of the total volume of data taken.
A spokesperson for the firm told Cyber Daily that MKA was aware of the claim and was treating verification as a priority, saying that if it found information had been affected it would contact the parties concerned. The firm said it had already contacted clients as a precaution, and that it had reported the incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner.
Qilin had been active since August 2022 and, by Cyber Daily's count at the time, had claimed more than 400 victims worldwide, including several Australian organizations in the preceding months. No further public update on the scope of the MKA intrusion was issued in the days after the listing.