A Gold Coast civil contracting firm lost more than $223,000 in a single transaction. It happened even though the firm was paying a cybersecurity provider every month to stop exactly this kind of attack.
Only $3.73 was ever recovered.
This is how it happened, what Ezylegal did about it, and what every Australian business should take from it.
What the provider promised
The Burleigh Heads firm had signed up with an external cybersecurity provider for enterprise-grade email and network protection. The monthly service promised:
- 99.9% guaranteed spam detection
- 99.99% virus detection
- 24/7 incident monitoring and response
Promotional material later tendered in court went further. It claimed the service would guarantee the identification and stopping of all phishing emails, and that no staff training was required.
For a busy small business, that sounds like the problem is handled.
How the attack unfolded
8 July 2024: A scammer sent a series of phishing emails to the firm’s director from a compromised external account. The system blocked some of them but let others through. The director interacted with one, and the scammer captured his Microsoft 365 login details.
Within 24 hours: The scammer had control of the director’s email account. They created a fake invoice for $223,333, posing as a supplier the firm already dealt with, and sent it to the accounts team. It looked like it came from the director himself.
16 July 2024: The accounts team paid the invoice. The money went straight to a bank account controlled by the scammers.
The firm reported it to the Queensland Police Service, which confirmed it was business email compromise. The Australian Cyber Security Centre lists this type of fraud among the most financially damaging cyber threats facing Australian businesses.
With the money gone and no realistic way to get it back through the police, the firm came to Ezylegal.
Taking the provider to court
In May 2025, Ezylegal started proceedings in the District Court of Queensland against the cybersecurity provider. The firm alleged breach of contract, negligence, and misleading and deceptive conduct under the Australian Consumer Law.
The Statement of Claim alleged the provider’s systems:
- failed to block the malicious emails
- failed to detect the intrusion
- failed to notify the firm of the breach
- failed to deliver the protection it had promised in its contract and its marketing
The firm also alleged that the provider’s limitation-of-liability clauses (the fine print that caps what a provider has to pay if things go wrong) could not be relied on. The argument was that the failures went to the heart of what the firm was paying for, and that the clauses were unfair terms under the small business protections in the Australian Consumer Law.
The provider fought back
The provider defended the claim. It argued that no cybersecurity product can stop every phishing email, and that the real cause of the loss was the firm not verifying the payment request before transferring the money.
What followed was more than a year of contested litigation. The provider’s lawyers filed defences and amended defences, and relied on their limitation-of-liability clauses to try to shut the claim down.
Ezylegal kept pushing. We filed an Amended Statement of Claim, then a Further Amended Statement of Claim adding misleading and deceptive conduct allegations, along with applications challenging the provider’s exclusion clauses as unfair terms.
The matter was resolved at mediation in August 2026.
Why we took this case
“This is exactly the kind of case that falls through the cracks,” said Michael Drummond, Principal of Ezylegal.
“A quarter of a million dollars is a devastating loss for a small business, but the cost of running District Court litigation against a well-resourced defendant with insurance lawyers makes it prohibitive for most firms to take on. That is why no-win, no-fee matters.”
The central question, Drummond said, is simple.
“If you are paying a cybersecurity provider to protect you, and they are guaranteeing detection rates of 99.9 per cent, you are entitled to expect that protection to actually work. When it does not, and you lose a quarter of a million dollars as a result, who is responsible?”
A growing problem for Australian businesses
The Australian Cyber Security Centre’s Annual Cyber Threat Report for 2023-24 recorded more than 94,000 cybercrime reports, with self-reported losses of more than $600 million. Business email compromise remained one of the most reported cybercrime types, with some of the highest average losses per incident.
“Businesses are spending significant money on cybersecurity services, often because they have been told by their providers that they will be protected,” Drummond said.
“But when something goes wrong, these same providers point the finger back at the client. They hide behind limitation-of-liability clauses and say the client should have done more. That is not acceptable when you have made explicit guarantees about your level of protection.”
What your business should do now
1. Read your cybersecurity contract. Know what it covers, what it excludes, and what it says happens if the system fails.
2. Keep the marketing material. If a provider sold you on guarantees, save the brochures, emails and web pages. What a business promises when it sells to you can matter under the Australian Consumer Law, whatever the contract says.
3. Verify every payment change by phone. If an invoice or bank detail change arrives by email, even from your own director, call a number you already have on file before paying.
4. Act fast if you’ve been hit. Contact your bank immediately, report it to police and at cyber.gov.au, and keep every email and record.
5. Don’t assume the fine print ends the conversation. Limitation clauses can sometimes be challenged, especially for small businesses under the unfair contract terms laws.
“For cybersecurity providers, the message is equally clear,” Drummond said. “If you market your services with guarantees of near-perfect detection, you cannot then disclaim responsibility when those services fail. The Australian Consumer Law does not allow you to have it both ways.”
Lost money to a provider that didn’t deliver?
Ezylegal works on a no-win, no-fee basis across consumer, commercial and insurance disputes.
“Big companies and their insurers know that most people cannot afford to fight them. They rely on that,” Drummond said. “We take that advantage away. If you have a legitimate claim, you should not have to abandon it because you cannot afford a lawyer.”