The SafePay ransomware cartel listed an unnamed New South Wales-based accounting and financial advisory firm on its dark web extortion portal. The threat actors claim to have breached internal network directories and exfiltrated confidential client financial profiles, tax documentation, and practice management files, threatening a public data release if extortion demands are unmet. Incident response and local threat analysis remain active to determine initial access vectors (likely targeting remote access infrastructure or compromised VPN credentials).