Back Smartcompany.Au Nick Scali manually processes orders after cyber breach forced systems offline
Furniture maker Nick Scali was forced to take some of its systems offline, after the company was hit by a major cybersecurity incident.
It means the $1.43 billion business has been manually processing orders and deliveries for its sofas and beds, causing delays and slower response times for customers.
The ASX-listed company informed the market the incident on Thursday afternoon and said it does not have “any evidence of unauthorised access to our customer data”.
However, The Australian reports customer details, including residential addresses, may have been accessed.
According to that report, the cyber attack is believed to have been carried out by offshore cyber criminals, who have demanded Nick Scali pay a ransom.
Nick Scali said it is now in the process of restoring its online systems, after the breach reportedly happened in the middle of last week.
“While we appreciate that this may have caused some delays for, and uncertainty with, customers, we are now in the process of bringing those systems back online,” the company said in a statement to the ASX.
Nick Scali reassured customers that sales orders and deliveries are still being completed, but acknowledged “our response times to customers are currently slower than normal”.
The company is continuing to investigate the incident and said its customers are its “key priority”.
Nick Scali has also notified the Australian Cyber Security Centre and the Australian Federal Police the incident.
Nick Scali is far from the only Australian business to be dealing with the aftermath of a cyber breach.
Australian firms experienced more cyberattacks than their international counterparts during 2025, and were also more likely to pay ransom demands, according to a global study by data security firm Cohesity released in November 2025.
The study of large public and private organisations found 85% of Australian enterprise businesses reported suffering a materially significant cyberattack in the prior 12 months compared to a global average of 54%.
Of these businesses, nearly all of them (96%) said they made ransom payments. Two in five businesses (41%) said they paid, on average, between $153,000 and $1,528,000, while the same proportion of businesses (41%) paid more than $1,532,000 each.
The Australian government advises businesses and individuals to never pay ransoms, as there are no guarantees access to systems will be restored or information won’t be sold or leaked online.
Businesses can call the Australian Signals Directorate’s Australian Cyber Security Centre’s 24/7 Hotline on 1300 CYBER1 ( 1300 292 371 ) if they need cybersecurity assistance.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
