A.C. Small & Maxwell Data Breach

Alleged

Ransomware claim involving A.C. Small & Maxwell

Published: Jul 20, 2026 SafePay
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
A.C. Small & Maxwell
Industry
Business Services
Threat Actor
SafePay
Date of Incident
Jul 20, 2026

Executive Summary

A.C. Small & Maxwell, a business services company based in Australia, has been listed as a victim on the SafePay ransomware group’s dark web portal, published on July 20, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The organization operates in the business services sector, one of the segments SafePay has hit most often in recent weeks. As an Australian entity, A.C. Small & Maxwell sits slightly outside the group’s dominant German cohort in this window. In the 60 days prior to this listing, SafePay has claimed 36 other victims across its leak portal. The group has shown a strong targeting pattern in the business services, manufacturing, and technology sectors. Geographically, its victims are heavily concentrated in Germany, with smaller clusters in Japan, Canada, and the United States. Other recent SafePay listings that overlap with A.C. Small & Maxwell’s business-services profile include Mende Grundbesitz, TimeTEX, LBB Treuhand, and Cenesco. A.C. Small & Maxwell matches SafePay’s sector focus on business services but diverges geographically, as Australian victims are comparatively rare in the group’s recent listing population.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for acsmallmaxwell.com.au in the queried slice. A null result is not the same as a clean bill of health. The query reflects a partial, paginated sample of a single source; credentials tied to the organisation could exist under alternate domains, sit in feeds outside this dataset, or be associated with personal email aliases that never map to the corporate domain. The finding should be read as “nothing in this slice,” not as confirmation that no exposure exists. For ransomware groups such as SafePay, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. The absence of evidence in this query does not rule that scenario out — credentials may have surfaced in feeds outside this dataset, been used and rotated before indexing, or been harvested under personal email aliases. CTI teams should treat continued monitoring and proactive credential-hygiene checks as the appropriate response rather than reading a null query as exoneration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.