CSIDB logo
Incident

William Buck

Incident posture

Attack window
Apr 2025
Location
Australia
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-02 11:32

Linked entities

Victim
William Buck
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Apr 2025
Disclosed
Apr 2025
Resolved
Pending

Summary

The Australian accounting and advisory firm William Buck experienced a cyber incident involving unauthorised access to its IT systems and potentially some data held on them. Upon detection, the company activated its incident response plan, mobilised a Crisis Management Team, and engaged external experts to investigate and contain the threat. A limited number of potentially impacted files were identified, and the firm began directly notifying affected clients while stressing that its core systems remained operational with no service interruption. The firm also reported awareness of impersonation attempts using William Buck email addresses and urged vigilance. Notifications were submitted to the Australian Cyber Security Centre, relevant government entities, and law enforcement, and a precautionary injunction was obtained in both Australia and New Zealand to prevent the sharing, dissemination, or access of any data involved in the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

William Buck, an Australian professional services firm, publicly disclosed on 1 April 2025 that it was investigating a cyber incident involving unauthorised access to its IT systems and potentially to some data held on those systems. The disclosure was made through a statement published on the company's website, indicating that the firm had detected the intrusion and responded by activating its established incident response protocols. According to the company's account, the unauthorised access was identified through internal monitoring processes, prompting immediate action from senior leadership and external specialists to determine the scope and nature of the breach.

Upon detection of the incident, William Buck implemented its formal incident response plan and mobilised its Crisis Management Team to coordinate the firm's response and ensure the ongoing security of its systems. The company also engaged external cybersecurity experts to assist with the investigation and to validate the steps being taken in response to the intrusion. These external advisors were brought in to provide specialised technical capability and to help ensure that the firm's containment, eradication, and recovery efforts aligned with industry best practices. The firm communicated that its systems continued to be operational throughout the incident response period, and it stated that there should be no interruption to services provided to clients as a result of the cyber event.

As part of its investigative efforts, William Buck identified a limited number of potentially impacted files within its environment. Rather than waiting until the full scope of the incident was determined, the company adopted a direct notification approach, reaching out to affected clients to inform them that their information may have been compromised. The statement did not specify the exact number of files involved, the types of data contained within those files, or the specific client segments affected, leaving the precise scope of data exposure to be determined through the ongoing investigation. The firm committed to providing further updates as additional information became available, indicating that the forensic review was still in progress at the time of the initial public disclosure.

In addition to notifying impacted clients, William Buck reported the incident to the Australian Cyber Security Centre and other relevant government entities and law enforcement agencies. This reporting aligned with the firm's stated commitment to cyber security and the protection of data, and it positioned the incident within the broader regulatory and law enforcement framework that governs cyber incidents affecting Australian organisations. The company also took the precautionary legal step of obtaining an injunction to prevent the sharing, dissemination, or access to any data impacted by the incident. According to the statement, this injunction operates in both Australia and New Zealand, providing court-ordered protection to William Buck's client base across both jurisdictions. Any attempt to view, share, or otherwise access the impacted data would be considered a contravention of this court order, placing potential recipients of leaked information at legal risk.

William Buck also used the disclosure to warn its broader stakeholder community about impersonation attempts being conducted using William Buck email addresses. The company asked clients and other parties interacting with the firm to remain vigilant and to report any unusual activity, particularly in email communications. Stakeholders were advised to contact their William Buck partner directly if they identified anything unusual in their interactions with the firm. This warning suggested that threat actors may have been leveraging the incident to conduct secondary attacks, such as phishing or business email compromise, by impersonating William Buck staff members. The inclusion of this advisory in the initial disclosure indicated that the firm was actively monitoring for fraudulent activity linked to the breach and was taking steps to protect its stakeholders from downstream harms. Media enquiries related to the incident were directed to Hugh Bastiaan, Group Chief Operating Officer, whose contact details were provided in the statement.

The company's communications emphasised cooperation with authorities and a structured, multi-track response involving internal crisis management, external forensic expertise, regulatory notification, legal remedies, and direct stakeholder communication. No further details regarding the timeline of the intrusion, the specific attack vector used, or the identity of the threat actor were included in the initial public statement, as those aspects remained under investigation at the time of disclosure.

Sources

Sources available to members: 1 source.

CSIDB