[{"data":1,"prerenderedAt":3523},["ShallowReactive",2],{"all-projects":3,"navigation":1663,"cyber-security-insights":1721,"companies":3409,"testimonials":3448,"services":3469,"socials":3508},[4,37,264,426,657,849,1030,1246],{"id":5,"title":6,"body":7,"card":14,"description":22,"extension":23,"meta":24,"metadata":25,"navigation":26,"path":27,"platform":28,"quote":25,"quoteAuthor":25,"seo":29,"sitemap":30,"stem":31,"subtitle":32,"summary":33,"technologies":34,"__hash__":36},"projects\u002Faltruid-systems.md","Investment Fund Rebranding",{"type":8,"value":9,"toc":10},"minimark",[],{"title":11,"searchDepth":12,"depth":12,"links":13},"",2,[],{"title":6,"summary":15,"image":16,"logo":17,"order":20,"background":21},"A complete visual rebrand for an investment fund, giving them a cohesive, professional identity across every touchpoint - logo, letterhead and email signatures.","portfolio\u002Faltruid-systems\u002Fcard-image.png",{"width":18,"src":19},136,"portfolio\u002Faltruid-systems\u002Flogo.png",10,"#0d1a4c","Rebranding for Altruid Systems, an alternative investments software solution","md",{},null,true,"\u002Faltruid-systems","Web, Email",{"title":6,"description":22},{"loc":27},"altruid-systems","Rebranding","Rebranding for Altruid Systems, an alternative investments software solution, giving them a cohesive, professional identity across every touchpoint - logo, letterhead and email signatures.",[35],"Design & UX","jFs1mvFRLxRHUKp_6U3BygH-LIXoLXZqeXM4TPgrur0",{"id":38,"title":39,"body":40,"card":239,"description":248,"extension":23,"meta":249,"metadata":250,"navigation":26,"path":253,"platform":254,"quote":25,"quoteAuthor":25,"seo":255,"sitemap":256,"stem":257,"subtitle":258,"summary":259,"technologies":260,"__hash__":263},"projects\u002Fcolor-magic.md","AI Color Palette Generator",{"type":8,"value":41,"toc":232},[42,47,51,69,72,76,79,116,120,145,152,156,159,197,200,204,213,229],[43,44,46],"h2",{"id":45},"ai-web-app-development","AI web app development",[48,49,50],"p",{},"Our team rebuilt ColorMagic.app and introduced new tools and features to the existing AI colour palette generator. The web application turns any keyword, brand name, image and hex code into a matching colour scheme within seconds. Since its launch, users have generated generated over 4 million palettes, and the platform has grown to serve more than 800,000 designers worldwide.",[52,53,54],"blockquote",{},[48,55,56,63,64,68],{},[57,58,62],"a",{"href":59,"rel":60},"https:\u002F\u002Fcolormagic.app\u002F",[61],"nofollow","ColorMagic.app"," is an ",[65,66,67],"strong",{},"AI colour palette generator",". Users can enter a theme, upload an image or provide a hex code to create harmonious colour combinations, complete with CSS, gradients and downloadable swatches.",[48,70,71],{},"The platform is designed for both digital artists and people without design experience. It therefore needed to be visually engaging, easy to use and accessible across desktop and mobile devices, and discoverable in search results. With millions of colour palettes, server-side rendering was used to support fast page loading and effective SEO.",[43,73,75],{"id":74},"web-development-services-for-an-ai-saas-product","Web development services for an AI SaaS product",[48,77,78],{},"Our project manager, UI\u002FUX designer and software engineers delivered the complete redevelopment of the application and introduced new functionality, including:",[80,81,82,86,89,92,95,98,101,104,107,110,113],"ul",{},[83,84,85],"li",{},"Product and web app architecture",[83,87,88],{},"OpenAI API integration and prompt engineering",[83,90,91],{},"UI\u002FUX design for the colour generator, palette pages and supporting tools",[83,93,94],{},"Front-end and back-end development using Nuxt.js",[83,96,97],{},"Database redesign for palettes, user accounts and saved favourites",[83,99,100],{},"Image-based colour extraction",[83,102,103],{},"Colour contrast and accessibility tools",[83,105,106],{},"Server-side rendering",[83,108,109],{},"Responsive development for desktop and mobile",[83,111,112],{},"SEO optimisation",[83,114,115],{},"Project management and delivery.",[43,117,119],{"id":118},"tech-stack-for-an-ai-colour-palette-generator","Tech stack for an AI colour palette generator",[80,121,122,133,139],{},[83,123,124,127,128,132],{},[65,125,126],{},"Framework:"," ",[57,129,131],{"href":130},"\u002Fvue-js-development-services","Nuxt.js"," supports server-side rendering, responsive user interfaces and fast page delivery across the platform’s palette and design-tool pages.",[83,134,135,138],{},[65,136,137],{},"AI integration:"," OpenAI API generates palettes from user prompts. Prompt design, response validation and caching help produce reliable results while managing performance and API costs.",[83,140,141,144],{},[65,142,143],{},"Database:"," MySQL stores generated palettes, user accounts, saved favourites and application data.",[48,146,147,148,151],{},"Together, ",[65,149,150],{},"Nuxt.js, OpenAI and MySQL"," stack helped us to redevelop the application, launch new features and improve its performance and search visibility.",[43,153,155],{"id":154},"ai-web-app-features","AI web app features",[48,157,158],{},"This platform includes:",[80,160,161,164,167,170,173,176,179,182,185,188,191,194],{},[83,162,163],{},"AI colour palette generation from keywords, brand names or hex codes",[83,165,166],{},"Colour extraction from uploaded images and photos",[83,168,169],{},"CSS gradient generator with copy-ready code",[83,171,172],{},"A colour mixer for blending and adjusting colours",[83,174,175],{},"A random colour generator",[83,177,178],{},"Colour contrast checking",[83,180,181],{},"User accounts and saved favourites",[83,183,184],{},"Palette downloads as PNG files",[83,186,187],{},"Copy-ready CSS and hex values",[83,189,190],{},"A searchable library of curated colour palettes",[83,192,193],{},"Responsive UI\u002FUX for desktop and mobile",[83,195,196],{},"Server-side rendered pages optimised for SEO.",[198,199],"hr",{},[43,201,203],{"id":202},"hire-developers-for-your-ai-powered-web-app","Hire developers for your AI-powered web app",[52,205,206],{},[48,207,208,209,212],{},"Planning to add AI features to your product or build a new AI-powered SaaS platform? Our developers have practical experience with ",[57,210,211],{"href":130},"Vue.js and Nuxt.js development"," and OpenAI API integration. We can help you plan the architecture, design the user experience, integrate AI functionality and develop a fast, scalable and SEO-friendly web application.",[214,215,219],"div",{"dataCmsId":216,"className":217},"cta-button",[218],"align-center",[214,220,223],{"className":221},[222],"button",[57,224,228],{"href":225,"className":226},"\u002Fcontact",[227],"cta","Get in touch",[230,231],"br",{},{"title":11,"searchDepth":12,"depth":12,"links":233},[234,235,236,237,238],{"id":45,"depth":12,"text":46},{"id":74,"depth":12,"text":75},{"id":118,"depth":12,"text":119},{"id":154,"depth":12,"text":155},{"id":202,"depth":12,"text":203},{"title":39,"summary":240,"hubSummary":241,"image":242,"logo":243,"order":246,"background":247},"An AI-powered web application that creates colour palettes from keywords, images and hex codes.","An AI-powered web application that creates colour palettes from keywords, images and hex codes. ColorMagic is used by more than 800,000 designers and digital artists worldwide.","portfolio\u002Fcolormagic\u002Fcolor-magic-card-image.png",{"width":244,"src":245},220,"companies\u002Fcolor-magic-logo.svg",7,"#f4f4f4","An AI colour palette generator built with Nuxt.js, MySQL and the OpenAI API.",{},{"title":251,"description":252},"AI Web App Development with Nuxt.js & OpenAI","See how IT Club rebuilt and expanded ColorMagic.app, an AI colour palette generator, using Nuxt.js, MySQL and OpenAI API.","\u002Fcolormagic","Web",{"title":39,"description":248},{"loc":253},"color-magic","UI\u002FUX | AI web app development","We rebuilt and expanded this AI-powered colour palette generator, which is used by more than 800,000 designers and digital artists worldwide. The app helps create colour schemes, extract colours from images, check colour contrast and and access other practical design tools. The platform was redeveloped using Nuxt.js, MySQL and the OpenAI API.",[131,261,262],"OpenAI API","MySQL","OIdciGk2Lp9Wjxfw3iHqtuXzVLt21vdwbMjfGpnBd4A",{"id":265,"title":266,"body":267,"card":403,"description":410,"extension":23,"meta":411,"metadata":412,"navigation":26,"path":415,"platform":254,"quote":416,"quoteAuthor":417,"seo":418,"sitemap":419,"stem":420,"subtitle":421,"summary":422,"technologies":423,"__hash__":425},"projects\u002Fnathan-nankervis.md","Animated Artist Portfolio Website",{"type":8,"value":268,"toc":396},[269,273,280,290,293,297,324,330,334,337,359,363,373,375,379,385,394],[43,270,272],{"id":271},"artist-portfolio-web-development","Artist portfolio web development",[48,274,275,276,279],{},"An artist's website has one job: to make the work feel as good on screen as it does in person. For ",[65,277,278],{},"NathanNankervis.com",", our team developed an animated portfolio website for one of Australia's most versatile creatives - pairing a Nuxt.js front-end with a headless CMS, fluid animations and motion-led interactions.",[52,281,282],{},[48,283,284,289],{},[57,285,288],{"href":286,"rel":287},"https:\u002F\u002Fnathannankervis.com\u002F",[61],"Nathan Nankervis"," is a Melbourne-based multidisciplinary artist, illustrator and designer whose work spans fine art, sculpture, furniture, apparel and public art He has collaborated with brands including Nike, Cartier, Swatch and PlayStation. His studio website showcases his growing body of work and connects visitors with his Shopify store, where they can can buy limited pieces.",[48,291,292],{},"The portfolio is the heart of the website, so every scroll, hover and transition had to feel considered. The animation is an important part of Nathan’s distinctive creative identity.",[43,294,296],{"id":295},"tech-stack-for-an-animated-portfolio","Tech stack for an animated portfolio",[80,298,299,306,312,318],{},[83,300,301,127,303,305],{},[65,302,126],{},[57,304,131],{"href":130}," - the Vue.js framework - for server-side rendering, fast page loads and SEO-friendly project pages.",[83,307,308,311],{},[65,309,310],{},"Headless CMS:"," Contentful allows Nathan publish new artworks, projects and case studies through a clean editorial interface.",[83,313,314,317],{},[65,315,316],{},"E-commerce:"," A direct connection to Nathan's Shopify store, keeping his portfolio and online shop separated.",[83,319,320,323],{},[65,321,322],{},"Animation:"," A custom animation layer for scroll-triggered reveals, hover interactions and smooth page transitions that make the portfolio feel alive.",[48,325,147,326,329],{},[65,327,328],{},"Nuxt.js and Contentful"," give Nathan a lightning-fast, editorially flexible portfolio that connects visitors directly to his Shopify store without compromising on the heavy, expressive animation the brand is known for.",[43,331,333],{"id":332},"portfolio-features","Portfolio features",[48,335,336],{},"The artist portfolio website includes:",[80,338,339,342,345,348,351,354],{},[83,340,341],{},"An animated, editorially-curated collection of artwork, furniture, apparel and public work",[83,343,344],{},"Individual projects with imagery, video and detailed captions",[83,346,347],{},"Contentful headless CMS for content publishing",[83,349,350],{},"Scroll-triggered animations, hover interactions and smooth page transitions",[83,352,353],{},"Fast image delivery for a media-heavy, visual-first site",[83,355,356,357],{},"Direct access to Nathan’s Shopify store\n",[230,358],{},[43,360,362],{"id":361},"in-nathans-words","In Nathan's words",[52,364,365],{},[48,366,367,368,370,372],{},"“Elena and Ruslan were an absolute breeze to work with and I would not be able to share my creativity with the world if it wasn't for extremely talented people like them. You are a master of the interwebs and I'm looking forward to continuing working with you.”",[230,369],{},[230,371],{}," - Nathan, Artist",[198,374],{},[43,376,378],{"id":377},"build-a-portfolio-website-that-brings-your-work-to-life","Build a portfolio website that brings your work to life",[48,380,381,382,384],{},"Planning a portfolio, Shopify store, or visually rich website? Our developers have hands-on experience with ",[57,383,211],{"href":130},", headless CMS platforms like Contentful and Shopify e-commerce. We can help you build a fast, animated, easy-to-manage website that presents your work at its best.",[214,386,388],{"dataCmsId":216,"className":387},[218],[214,389,391],{"className":390},[222],[57,392,228],{"href":225,"className":393},[227],[230,395],{},{"title":11,"searchDepth":12,"depth":12,"links":397},[398,399,400,401,402],{"id":271,"depth":12,"text":272},{"id":295,"depth":12,"text":296},{"id":332,"depth":12,"text":333},{"id":361,"depth":12,"text":362},{"id":377,"depth":12,"text":378},{"title":266,"summary":404,"image":405,"logo":406,"order":409,"background":247},"An animated portfolio for Melbourne-based multidisciplinary artist Nathan Nankervis.","portfolio\u002Fnathan-nankervis-card-image.png",{"width":407,"src":408},200,"companies\u002Fnathan-nankervis_secondary_logo_wobble_face.avif",3,"An animated portfolio website built with Nuxt.js and Contentful, linking through to a Shopify store.",{},{"title":413,"description":414},"Artist Portfolio Website Development with Nuxt.js","How we built nathannankervis.com, an animated artist portfolio, with Nuxt.js, a Contentful headless CMS and rich scroll animations, linked to his Shopify store.","\u002Fnathannankervis","Elena and Ruslan were an absolute breeze to work with and I would not be able to share my creativity with the world without them.","Nathan Nankervis, Artist",{"title":266,"description":410},{"loc":415},"nathan-nankervis","Website development","An animated portfolio for Melbourne-based multidisciplinary artist Nathan Nankervis. Built with Nuxt.js and Contentful, the site makes it easy to showcase Nathan’s work and directs visitors to his Shopify store.",[131,424],"Contentful","C_GXJWfsRFXWoY1XobXup4kOD8jYJZnLpSm5zYvhde8",{"id":427,"title":428,"body":429,"card":637,"description":646,"extension":23,"meta":647,"metadata":25,"navigation":26,"path":648,"platform":254,"quote":25,"quoteAuthor":25,"seo":649,"sitemap":650,"stem":651,"subtitle":652,"summary":653,"technologies":654,"__hash__":656},"projects\u002Fschool-holidays.md","Custom Two-Sided Marketplace",{"type":8,"value":430,"toc":630},[431,435,442,455,458,470,474,481,506,510,519,542,546,553,603,605,609,619,628],[43,432,434],{"id":433},"e-commerce-platform-web-development","E-commerce Platform Web Development",[48,436,437,438,441],{},"As most of our team members are parents, we were extremely excited to be involved in the web development of a ",[65,439,440],{},"custom-built e-commerce platform"," for families with kids - schoolholidays.com.au. This project has a great mission and brings so much value to Australian families with kids.",[52,443,444],{},[48,445,446,63,451,454],{},[57,447,450],{"href":448,"rel":449},"https:\u002F\u002Fschoolholidays.com.au\u002F",[61],"schoolholidays.com.au",[65,452,453],{},"e-commerce platform"," for families that connects small and large Australian service providers, including government organisations, with parents. This app helps parents and carers plan their children’s school holidays, extracurriculars and after school time.",[48,456,457],{},"Our team enjoyed being involved in the web development of this unique marketplace. We worked hard and are proud to show you the results. Check it out! It's zippy, clean and has some great features and capabilities.",[48,459,460,127,466,468],{},[461,462],"img",{"alt":463,"src":464,"title":465},"schoolholidays.com.au - branding, design UX and web development","\u002Fuploads\u002FMarketplace_e-commerce_custom_solution_development_listing_activity_page_promotional_offer_UI_UX.jpg","Branding UI\u002FUX design and web development for schoolholidays.com.au",[230,467],{},[230,469],{},[43,471,473],{"id":472},"web-development-services-for-a-custom-built-e-commerce-platform","Web development services for a custom-built e-commerce platform",[48,475,476,477,480],{},"Our team of talented project managers, UI\u002FUX designers and software engineers provided our client with ",[65,478,479],{},"a wide range of web development services"," to build this unique app for the Australian market, such as:",[80,482,483,488,493,498,501,503],{},[83,484,485,486],{},"creating the web app architecture",[230,487],{},[83,489,490,491],{},"UI\u002FUX design",[230,492],{},[83,494,495,496],{},"front-end development",[230,497],{},[83,499,500],{},"back-end development",[83,502,112],{},[83,504,505],{},"Project management.",[43,507,509],{"id":508},"tech-stack-for-e-commerce-platform","Tech stack for e-commerce platform",[48,511,512,513,516,517],{},"The ",[65,514,515],{},"frameworks"," that our web developers used include:",[230,518],{},[48,520,521,127,524,529,530,127,532,535,536,127,538,541],{},[65,522,523],{},"Frontend:",[57,525,528],{"href":526,"rel":527},"https:\u002F\u002Fitclub.com.au\u002Fvue-js-development-services",[61],"Vue.js"," \u002F Nuxt.js",[230,531],{},[65,533,534],{},"Backend:"," Node.js",[230,537],{},[65,539,540],{},"Cloud Servers \u002F Serverless infrastructure:"," A combination of servers and serverless has been used for different modules of the web application.",[43,543,545],{"id":544},"marketplace-features","Marketplace Features",[48,547,548,549,552],{},"Some of the ",[65,550,551],{},"main features"," of this e-commerce website include:",[80,554,555,558,561,564,567,570,573,576,579,582,585,588,591,594,597,600],{},[83,556,557],{},"API development",[83,559,560],{},"Fully-responsive website with a lightning-fast site search (Algolia)",[83,562,563],{},"Custom-built e-commerce platform",[83,565,566],{},"Custom-built CMS",[83,568,569],{},"Business (tenants) registration and management",[83,571,572],{},"Listing registration and management",[83,574,575],{},"Product registration and management",[83,577,578],{},"Admin side for Super Admins and registered businesses",[83,580,581],{},"Offers and coupons and their management",[83,583,584],{},"Custom-built checkout",[83,586,587],{},"Payment integrations (Stripe)",[83,589,590],{},"Ticketing solution",[83,592,593],{},"Competitions module",[83,595,596],{},"Affiliates and Partner management",[83,598,599],{},"Responsive UI\u002FUX design",[83,601,602],{},"Progressive web application (PWA).",[198,604],{},[43,606,608],{"id":607},"hire-javascript-experts-for-your-e-commerce-site-web-project-or-idea","Hire JavaScript experts for your e-commerce site, web project or idea",[52,610,611],{},[48,612,613,614,618],{},"Need a consult for your project or a team of extremely talented web developers? Chat with us. Our experienced Vue.js and Node.js developers have helped many startups and established Australian businesses to build ",[57,615,617],{"href":616},"\u002Fcase-studies","server-side rendered web applications",". Our team is ready to help you!",[214,620,622],{"dataCmsId":216,"className":621},[218],[214,623,625],{"className":624},[222],[57,626,228],{"href":225,"className":627},[227],[230,629],{},{"title":11,"searchDepth":12,"depth":12,"links":631},[632,633,634,635,636],{"id":433,"depth":12,"text":434},{"id":472,"depth":12,"text":473},{"id":508,"depth":12,"text":509},{"id":544,"depth":12,"text":545},{"id":607,"depth":12,"text":608},{"title":638,"summary":639,"hubSummary":640,"image":641,"logo":642,"order":645,"background":247},"E-commerce Platform","A two-sided marketplace that connects Australian families with school holiday activities.","A two-sided marketplace that connects Australian families with school holiday activities. An e-commerce experience used by thousands of Australian families every month.","portfolio\u002Fschoolholidays\u002Fcard-image.png",{"width":643,"src":644},230,"portfolio\u002Fschoolholidays\u002Flogo.png",1,"An e-commerce platform and two-sided marketplace built with Vue.js, Nuxt.js, Node.js, Algolia, AWS, Vercel.",{},"\u002Fschoolholidays",{"title":428,"description":646},{"loc":648},"school-holidays","UI\u002FUX | E-commerce platform development","A custom two-sided marketplace that connects Australian families with school holiday activities. Built with Vue.js, Nuxt.js, Node.js, Algolia, AWS, Vercel.",[528,131,655],"Node.js","MoLxWkwpAv222K_QvLT8jNhjYdEpFBb1mNNxzFyv1d0",{"id":658,"title":659,"body":660,"card":824,"description":832,"extension":23,"meta":833,"metadata":834,"navigation":26,"path":837,"platform":254,"quote":25,"quoteAuthor":25,"seo":838,"sitemap":839,"stem":840,"subtitle":841,"summary":842,"technologies":843,"__hash__":848},"projects\u002Fsong-quiz.md","Multiplayer Music Game",{"type":8,"value":661,"toc":817},[662,666,677,686,689,693,696,715,719,722,752,759,763,766,791,793,797,806,815],[43,663,665],{"id":664},"real-time-multiplayer-game-development","Real-time multiplayer game development",[48,667,668,669,672,673,676],{},"Rebuilding a browser game where several players compete in the same room at the same time is a very different challenge from developing a classic website. For ",[65,670,671],{},"SongQuiz.io",", our team redesigned and rebuilt the existing ",[65,674,675],{},"real-time multiplayer music quiz game"," as a fast and responsive web app. The new version has improved UI\u002FUX and keeps players, scores and game rounds synchronised across every device.",[52,678,679],{},[48,680,681,685],{},[57,682,671],{"href":683,"rel":684},"https:\u002F\u002Fsongquiz.io\u002F",[61]," is a free online guess-the-song game. Players choose a playlist, listen to short audio clips and identify the song title and artist from the available options. They can play solo, with friends in private multiplayer rooms or take part in a daily Heardle-style challenge.",[48,687,688],{},"The game runs entirely in the browser, with no downloads or registration. This means every interaction must feel immediate: pages have to load quickly, audio has to start without delay, and scores have to update for every player in real time.",[43,690,692],{"id":691},"web-development-services-for-a-multiplayer-browser-game","Web development services for a multiplayer browser game",[48,694,695],{},"Our project manager, UI\u002FUX designer and software engineers delivered the complete redevelopment of the web application, including:",[80,697,698,701,704,707,710,713],{},[83,699,700],{},"UI\u002FUX design for desktop and mobile",[83,702,703],{},"Front-end development with Svelte",[83,705,706],{},"Back-end development with Node.js and WebSockets",[83,708,709],{},"Database design and query optimisation",[83,711,712],{},"SEO optimisation to support organic growth",[83,714,115],{},[43,716,718],{"id":717},"tech-stack-for-a-real-time-multiplayer-game","Tech stack for a real-time multiplayer game",[48,720,721],{},"Low latency was one of the main technical requirements, so our engineers chose a tech stack built for speed:",[80,723,724,729,735,741,747],{},[83,725,726,728],{},[65,727,523],{}," Svelte - a compiler-based JavaScript framework that produces lightweight applications and keeps the game interface responsive even on older mobile devices.",[83,730,731,734],{},[65,732,733],{},"Real-time layer:"," WebSockets provide two-way communication between the browser and server. Guesses, scores and round changes are sent to every player instantly rather than repeatedly requested by the browser.",[83,736,737,740],{},[65,738,739],{},"Back end",": Node.js manages the game logic, player actions and communication between connected users.",[83,742,743,746],{},[65,744,745],{},"In-memory data:"," Redis stores live game state, room activity and real-time messaging between server instances - the key to scaling multiplayer rooms horizontally. It help the application support multiple multiplayer rooms.",[83,748,749,751],{},[65,750,143],{}," PostgreSQL stores persistent data such as playlists, song metadata, daily challenges and player statistics.",[48,753,754,755,758],{},"This combination of ",[65,756,757],{},"Svelte, Node.js, WebSockets, Redis and PostgreSQL"," allows the game handle many concurrent rooms while keeping every player's screen in sync.",[43,760,762],{"id":761},"multiplayer-game-features","Multiplayer game features",[48,764,765],{},"The rebuilt music trivia web application includes:",[80,767,768,771,774,777,780,783,786,788],{},[83,769,770],{},"Real-time multiplayer rooms",[83,772,773],{},"Private rooms with custom invite codes",[83,775,776],{},"Public multiplayer rooms",[83,778,779],{},"A daily Heardle-style song challenge",[83,781,782],{},"Music Trivia Arcade mode with autoplay",[83,784,785],{},"Quizzes by various music genres",[83,787,193],{},[83,789,790],{},"SEO-optimised landing pages",[198,792],{},[43,794,796],{"id":795},"hire-developers-for-your-real-time-web-application","Hire developers for your real-time web application",[52,798,799],{},[48,800,801,802,805],{},"Multiplayer games, live dashboards, chat platforms, auctions and collaborative tools - anything where users see each other's actions instantly needs a reliable real-time architecture. Our experienced JavaScript developers have rebuilt and developed ",[57,803,804],{"href":616},"web applications"," with Node.js, WebSockets, Redis and PostgreSQL and can help you modernise an existing application, improve its performance or choose the right tech stack for a new real-time project.",[214,807,809],{"dataCmsId":216,"className":808},[218],[214,810,812],{"className":811},[222],[57,813,228],{"href":225,"className":814},[227],[230,816],{},{"title":11,"searchDepth":12,"depth":12,"links":818},[819,820,821,822,823],{"id":664,"depth":12,"text":665},{"id":691,"depth":12,"text":692},{"id":717,"depth":12,"text":718},{"id":761,"depth":12,"text":762},{"id":795,"depth":12,"text":796},{"title":659,"summary":825,"hubSummary":826,"image":827,"logo":828,"order":831,"background":247},"A real-time multiplayer music quiz where players guess songs in the browser.","A real-time browser-based music quiz where players guess songs. We rebuilt the platform to support synchronised multiplayer rooms, daily challenges and solo trivia for thousands users each month.","portfolio\u002Fsongquiz\u002Fsong-quiz-card-image.png",{"width":829,"src":830},173,"companies\u002Fsong-quiz-long-logo.png",4,"A real-time multiplayer browser game built with Svelte, WebSockets, Node.js, Redis and PostgreSQL.",{},{"title":835,"description":836},"Real-Time Multiplayer Game Development with Svelte","See how IT Club rebuilt SongQuiz.io using Svelte, Node.js, WebSockets, Redis and PostgreSQL to deliver fast, synchronised multiplayer gameplay.","\u002Fsongquiz",{"title":659,"description":832},{"loc":837},"song-quiz","UI\u002FUX | Real-time multiplayer game development","We rebuilt and modernised an existing multiplayer music quiz where players guess songs together in the browser in real time. Built with Svelte, WebSockets, Node.js, Redis and PostgreSQL.",[844,845,655,846,847],"Svelte","WebSockets","Redis","PostgreSQL","cmL7Ctg15-xpw-oUGM1O64FOaCCqeViFJ7t4_2IKDnY",{"id":850,"title":851,"body":852,"card":1009,"description":1016,"extension":23,"meta":1017,"metadata":1018,"navigation":26,"path":1021,"platform":254,"quote":25,"quoteAuthor":25,"seo":1022,"sitemap":1023,"stem":1024,"subtitle":1025,"summary":1026,"technologies":1027,"__hash__":1029},"projects\u002Fspotify-stats.md","Music Analytics Platform",{"type":8,"value":853,"toc":1002},[854,858,861,871,874,878,885,914,918,940,946,950,953,976,978,982,991,1000],[43,855,857],{"id":856},"laravel-web-development-with-third-party-api-integration","Laravel web development with third-party API integration",[48,859,860],{},"SpotifyStats.com is built around the Spotify Web API. This made secure authentication, data caching and fast response times central to the development process.",[52,862,863],{},[48,864,865,870],{},[57,866,869],{"href":867,"rel":868},"https:\u002F\u002Fspotifystats.com\u002F",[61],"SpotifyStats.com"," is a music analytics platform that allows listeners to connect their Spotify account and explore their top artists, most streamed tracks, favourite genres and recently played music.",[48,872,873],{},"Users expect to see their personalised listening data within seconds of connecting their account, regardless of the device they use. The web application has to retrieve, process and present Spotify data quickly.",[43,875,877],{"id":876},"web-development-services-for-a-music-analytics-application","Web development services for a music analytics application",[48,879,880,881,884],{},"Our UI\u002FUX designer and ",[65,882,883],{},"Laravel developer"," delivered this project from planning through to launch, including:",[80,886,887,890,893,896,899,902,905,908,910,912],{},[83,888,889],{},"Web app architecture built around the Spotify Web API",[83,891,892],{},"Secure OAuth 2.0 authorisation flow",[83,894,895],{},"UI\u002FUX design for music analytics dashboards",[83,897,898],{},"Back-end development using Laravel",[83,900,901],{},"Spotify API integration",[83,903,904],{},"API response caching and rate-limit management",[83,906,907],{},"MySQL database design",[83,909,109],{},[83,911,112],{},[83,913,115],{},[43,915,917],{"id":916},"tech-stack-for-a-spotify-powered-web-application","Tech stack for a Spotify-powered web application",[80,919,920,929,934],{},[83,921,922,127,924,928],{},[65,923,534],{},[57,925,927],{"href":926},"\u002Flaravel-development-services","Laravel"," provides the application structure, business logic, authentication processes and integration layer for the Spotify Web API.",[83,930,931,933],{},[65,932,143],{}," MySQL stores user profiles, cached listening and other application data.",[83,935,936,939],{},[65,937,938],{},"API Integration:"," The Spotify Web API with the full OAuth 2.0 authorisation-code flow, token refresh handling, and smart caching so repeat visits load instantly without hammering the API or hitting rate limits.",[48,941,942,945],{},[65,943,944],{},"PHP, Laravel and MySQL"," provide a reliable and cost-effective foundation for API-driven web applications - fast to build, easy to host and flexible to maintain as the product grows.",[43,947,949],{"id":948},"music-analytics-features","Music analytics features",[48,951,952],{},"The application includes:",[80,954,955,958,961,964,967,970,973],{},[83,956,957],{},"One-click connection to Spotify using OAuth 2.0",[83,959,960],{},"Top artists rankings across three time periods",[83,962,963],{},"Most streamed tracks across three time periods",[83,965,966],{},"Music genre analysis based on listening history",[83,968,969],{},"Cached Spotify API responses for faster repeat visits",[83,971,972],{},"Secure token storage and automatic token refresh",[83,974,975],{},"Responsive design for desktop and mobile",[198,977],{},[43,979,981],{"id":980},"hire-laravel-developers-for-your-api-integration-project","Hire Laravel developers for your API integration project",[52,983,984],{},[48,985,986,987,990],{},"Integrating a third-party service such as Spotify, Stripe, Xero or Shopify involves more than simply connecting an AP: OAuth, webhooks, rate limits,  caching, security and error handling. Our experienced ",[57,988,989],{"href":926},"Laravel developers"," build secure, API-driven web applications and can help you plan the architecture, integrate third-party services and bring your product to market fast.",[214,992,994],{"dataCmsId":216,"className":993},[218],[214,995,997],{"className":996},[222],[57,998,228],{"href":225,"className":999},[227],[230,1001],{},{"title":11,"searchDepth":12,"depth":12,"links":1003},[1004,1005,1006,1007,1008],{"id":856,"depth":12,"text":857},{"id":876,"depth":12,"text":877},{"id":916,"depth":12,"text":917},{"id":948,"depth":12,"text":949},{"id":980,"depth":12,"text":981},{"title":851,"summary":1010,"hubSummary":1011,"image":1012,"logo":1013,"order":1015,"background":247},"A Spotify analytics web application that helps listeners explore their top artists, most streamed tracks, favourite genres and listening habits.","A Spotify analytics web application that helps listeners explore their top artists, most streamed tracks, favourite genres and listening habits. The platform provides secure Spotify account connection and fast, personalised music insights to thousands of users each month.","portfolio\u002Fspotifystats\u002Fspotify-stats-card-image.png",{"width":407,"src":1014},"companies\u002Fspotify-stats-logo.png",5,"A Spotify analytics web application built with Laravel, MySQL and Spotify Web API integration.",{},{"title":1019,"description":1020},"Laravel Development & Spotify API Integration","See how IT Club built SpotifyStats.com using Laravel, MySQL and the Spotify Web API, with secure OAuth login, caching and personalised music insights.","\u002Fspotifystats",{"title":851,"description":1016},{"loc":1021},"spotify-stats","UI\u002FUX | Laravel development | API integration","A Spotify analytics web application that helps listeners explore their top artists, most streamed tracks, favourite genres and listening habits. Designed and developed using Laravel, MySQL and the Spotify Web API.",[927,262,1028],"Spotify API","3KfleMsToT5c2TAgpOw5X_bWNVDbIdxxiEQ2dMPR-TA",{"id":1031,"title":1032,"body":1033,"card":1223,"description":1230,"extension":23,"meta":1231,"metadata":1232,"navigation":26,"path":1235,"platform":254,"quote":1236,"quoteAuthor":1237,"seo":1238,"sitemap":1239,"stem":1240,"subtitle":1241,"summary":1242,"technologies":1243,"__hash__":1245},"projects\u002Fterran-industries.md","Sustainability B2B Website",{"type":8,"value":1034,"toc":1215},[1035,1039,1046,1060,1067,1074,1078,1085,1111,1115,1137,1144,1148,1151,1176,1180,1190,1192,1196,1204,1213],[43,1036,1038],{"id":1037},"uiux-design-website-development","UI\u002FUX design & website development",[48,1040,1041,1042,1045],{},"A sustainability company’s website should feel as considered as its mission. For the original version of TerranIndustries.com.au, our team delivered the complete ",[65,1043,1044],{},"UI\u002FUX design and website development"," - turning a broad B2B sustainability offering into a clear, easy-to-use website built with Next.js and Contentful.",[52,1047,1048],{},[48,1049,1050,1055,1056,1059],{},[57,1051,1054],{"href":1052,"rel":1053},"https:\u002F\u002Fterranindustries.com.au\u002F",[61],"Terran Industries"," is an Australian company that helps businesses replace single-use plastics and synthetic products with ",[65,1057,1058],{},"eco-friendly, sustainable alternatives",". It connects companies with sustainable products, recycling providers, buyers for excess material and sustainability specialists - making the transition to a circular economy simpler and more achievable.",[48,1061,1062,1063,1066],{},"The website had to do two things at once: clearly explain a wide range of services and let businesses tell Terran Industries exactly what they needed. To support this, we created a custom ",[65,1064,1065],{},"\"Find Alternatives\" selection tool",", where a visitor selects the products and waste services they want greener options for. Their selections are then included in a single enquiry.",[48,1068,1069,1070,1073],{},"The Terran Industries team also needed to manage their services, packages, team members and website content independently, so a ",[65,1071,1072],{},"headless CMS"," was essential.",[43,1075,1077],{"id":1076},"web-development-services-for-a-sustainability-website","Web development services for a sustainability website",[48,1079,1080,1081,1084],{},"Our designer and software engineers delivered the complete ",[65,1082,1083],{},"UI\u002FUX design and development"," of the foriginal Terran Industries website, including:",[80,1086,1087,1090,1093,1096,1099,1102,1105,1108],{},[83,1088,1089],{},"UI\u002FUX design across the homepage, About, How It Works, What We Do, Services, How It Works, Blog and supporting pages",[83,1091,1092],{},"Design and development of the interactive \"Find Alternatives\" tool",[83,1094,1095],{},"Front-end development with Next.js",[83,1097,1098],{},"Headless CMS configuration and content modelling in Contentful",[83,1100,1101],{},"A dynamic enquiry form that includes each visitor's products and services",[83,1103,1104],{},"Responsive development across desktop, tablet and mobile",[83,1106,1107],{},"Performance optimisation and SEO foundations",[83,1109,1110],{},"Project management, testing and delivery.",[43,1112,1114],{"id":1113},"technology-used-to-build-the-sustainability-website","Technology used to build the sustainability website",[80,1116,1117,1123,1132],{},[83,1118,1119,1122],{},[65,1120,1121],{},"UI\u002FUX design:"," A clean, approachable interface designed around Terran Industries' brand and illustrations, guiding visitors from initial exploration to enquiry.",[83,1124,1125,127,1127,1131],{},[65,1126,126],{},[57,1128,1130],{"href":1129},"\u002Freact-js-development-services","Next.js",", a React framework that supports fast page loads, server-side rendering and a reusable component architecture.",[83,1133,1134,1136],{},[65,1135,310],{}," Contentful, allowing the Terran Industries team can manage services, team members and blog posts through a structured editorial interface, independent of the code.",[48,1138,1139,1140,1143],{},"The combination of ",[65,1141,1142],{},"Next.js and Contentful"," produced a fast, maintainable website with a custom enquiry tool at its centre, giving Terran Industries a strong foundation for launching its business.",[43,1145,1147],{"id":1146},"website-features","Website features",[48,1149,1150],{},"The main features of this sustainability website include:",[80,1152,1153,1156,1159,1162,1165,1168,1171],{},[83,1154,1155],{},"An interactive \"Find alternatives\" tool for selecting products and waste services",[83,1157,1158],{},"A single enquiry form that includes the visitor's selections",[83,1160,1161],{},"Some page content and blog posts managed in Contentful",[83,1163,1164],{},"Service packages and a \"book an appointment\" flow",[83,1166,1167],{},"Team, partners and newsletter sections",[83,1169,1170],{},"Fully-responsive layouts across desktop, tablet and mobile",[83,1172,1173,1174],{},"An SEO-friendly website structure and metadata for organic search visibility.\n",[230,1175],{},[43,1177,1179],{"id":1178},"what-terran-industries-say","What Terran Industries say",[52,1181,1182],{},[48,1183,1184,1185,1187,1189],{},"Elena and her team are incredible! I could not be happier with the website she designed for me - it was beyond my expectations! She is full of knowledge and advice, and will always deliver you the best outcome. I will definitely be working with her on my next project.",[230,1186],{},[230,1188],{}," - Evannah, Founder of Terran Industries",[198,1191],{},[43,1193,1195],{"id":1194},"planning-a-new-business-website","Planning a new business website?",[48,1197,1198,1199,1203],{},"Launching a business or rebuilding an existing website? Our designers and ",[57,1200,1202],{"href":1201},"\u002Fnext-js-framework","Next.js developers"," create fast, professional websites using modern headless CMS platforms such as Contentful - so your team can manage its content with ease.",[214,1205,1207],{"dataCmsId":216,"className":1206},[218],[214,1208,1210],{"className":1209},[222],[57,1211,228],{"href":225,"className":1212},[227],[230,1214],{},{"title":11,"searchDepth":12,"depth":12,"links":1216},[1217,1218,1219,1220,1221,1222],{"id":1037,"depth":12,"text":1038},{"id":1076,"depth":12,"text":1077},{"id":1113,"depth":12,"text":1114},{"id":1146,"depth":12,"text":1147},{"id":1178,"depth":12,"text":1179},{"id":1194,"depth":12,"text":1195},{"title":1032,"summary":1224,"image":1225,"logo":1226,"order":1229,"background":247},"A website for TerranIndustries.com.au, offering eco-friendly alternatives to single-use plastics.","portfolio\u002Fterran-industries.png",{"width":1227,"src":1228},150,"companies\u002Fterran-industries-logo.png",6,"A B2B sustainability website, designed and built with Next.js and Contentful.",{},{"title":1233,"description":1234},"UI\u002FUX Design & Next.js Development with Contentful","How we designed the UI\u002FUX and built the first edition of terranindustries.com.au, a B2B sustainability website, with Next.js and a Contentful headless CMS.","\u002Fterranindustries","I could not be happier with the website Elena designed for me - it was beyond my expectations.","Evannah, Founder at Terran Industries",{"title":1032,"description":1230},{"loc":1235},"terran-industries","UI\u002FUX | Website development","We designed and built the original website for Terran Industries, a B2B sustainability company helping Australian businesses find eco-friendly alternatives to single-use plastics. The website was developed with Next.js and Contentful.",[1244,1130,424],"UI\u002FUX","oTom4S9E6xdSu-iKs14Kcjspx-iI4nboLR_Chi0s1wo",{"id":1247,"title":1248,"body":1249,"card":1646,"description":1652,"extension":23,"meta":1653,"metadata":25,"navigation":26,"path":1654,"platform":254,"quote":1655,"quoteAuthor":1656,"seo":1657,"sitemap":1658,"stem":1659,"subtitle":1660,"summary":1652,"technologies":1661,"__hash__":1662},"projects\u002Fvideo-recording-web-application.md","Video Maker Platform",{"type":8,"value":1250,"toc":1633},[1251,1255,1258,1268,1271,1282,1286,1289,1292,1303,1306,1317,1328,1331,1334,1368,1379,1383,1386,1389,1392,1395,1398,1401,1410,1413,1416,1421,1441,1445,1467,1471,1476,1480,1497,1501,1506,1565,1576,1580,1592,1602,1604,1615,1619,1622,1631],[43,1252,1254],{"id":1253},"video-recording-web-app-development","Video recording web app development",[48,1256,1257],{},"Memwah is an award-winning video recording web application to record videos in the browser, invite people to contribute, gather video recordings and merge those into fantastic video stories that can be shared or downloaded.",[52,1259,1260],{},[48,1261,1262,1267],{},[57,1263,1266],{"href":1264,"rel":1265},"https:\u002F\u002Fmemwah.com.au\u002F",[61],"Memwah"," is an online video recording app that makes recording video stories and group tribute videos easy. It's an Australian female-led startup born during the Melbourne lockdowns between 2020 and 2021. This challenging time happened to be the catalyst to create something meaningful to bring people together and help them pass their memories from older to future generations.",[48,1269,1270],{},"This video recording web app allows users to easily create personalised stories, record videos in the browser, merge selected video recordings into a compiled video story and share that complete video message with a broader audience of colleagues, friends and families.",[48,1272,1273,127,1278,1280],{},[461,1274],{"alt":1275,"src":1276,"title":1277},"memwah.com.au - UI\u002FUX design, web development & infrustructure","\u002Fuploads\u002Fmemwah-video-maker-app.png","UI\u002FUX design, web development & infrustructure for memwah.com.au",[230,1279],{},[230,1281],{},[43,1283,1285],{"id":1284},"web-development-services-for-a-video-recording-platform","Web development services for a video recording platform",[48,1287,1288],{},"This video recording website caters to older demographics. Hence, our team of talented UI\u002FUX designers, front-end and back-end developers did a great job making it intuitive, easy to use, fast and performant.",[48,1290,1291],{},"Memwah has become one of the pioneers in Australia who decided to utilise modern browser capabilities and provide its users with a completely new experience.",[52,1293,1294],{},[48,1295,1296,1297,1302],{},"Nowadays, many modern browsers (e.g. Chrome, Firefox, and ",[57,1298,1301],{"href":1299,"rel":1300},"https:\u002F\u002Fcaniuse.com\u002F",[61],"Safari v14.1 and older",") can access video and audio input from the user and allow users to record videos in the browser using JavaScript. It, however, depends on the browser's capabilities, meaning that such an experience could be fully dynamic and inlined or could be delegated to another application on the user's device.",[48,1304,1305],{},"Below are the Web Vitals metrics for the website showcasing quality user experience. As of today, the Web Vitals metrics focus on three critical aspects of the user experience:",[80,1307,1308,1311,1314],{},[83,1309,1310],{},"loading and performance,",[83,1312,1313],{},"interactivity, and",[83,1315,1316],{},"visual stability to avoid layout shifts.",[48,1318,1319,127,1324,1326],{},[461,1320],{"alt":1321,"src":1322,"title":1323},"memwah.com.au - Web Vitals metrics","\u002Fuploads\u002Fweb_vitals_metrics.jpg","Web Vitals metrics for memwah.com.au",[230,1325],{},[230,1327],{},[48,1329,1330],{},"Our team of experienced project managers, UI\u002FUX designers, and full-stack developers enjoyed helping our client build this unique web app, giving people from Australia and worldwide the opportunity to record their videos in the browser and share those special video messages with their loved ones.",[48,1332,1333],{},"The project scope included:",[80,1335,1336,1339,1342,1345,1348,1351,1354,1357,1360,1363,1366],{},[83,1337,1338],{},"Web app architecture and infrustructure;",[83,1340,1341],{},"Intuitive UI\u002FUX design and user flows for the media platform;",[83,1343,1344],{},"Front-end development to meet modern rigid requirements on the web;",[83,1346,1347],{},"Back-end development to make a secure and performant web application while processing large videos in the cloud;",[83,1349,1350],{},"Various integrations with third-party services such as Stripe, Remotion, Mailchimp and log-in with social media;",[83,1352,1353],{},"Video compilation and video production using server-side rendering;",[83,1355,1356],{},"Design and development of user roles and permissions;",[83,1358,1359],{},"AWS Lambda serverless application;",[83,1361,1362],{},"Transactional emails;",[83,1364,1365],{},"SEO optimisation;",[83,1367,115],{},[48,1369,1370,127,1375,1377],{},[461,1371],{"alt":1372,"src":1373,"title":1374},"memwah.com.au - A compiled video story","\u002Fuploads\u002Fmemwah_public_story.png","A compiled video story at memwah.com.au",[230,1376],{},[230,1378],{},[43,1380,1382],{"id":1381},"tech-stack-to-build-a-video-maker-web-app","Tech stack to build a video maker web app",[48,1384,1385],{},"Our team's challenge was to build a fast, performant and user-friendly web application that can concurrently process a large volume of videos in the cloud at a relatively low cost for the startup company.",[48,1387,1388],{},"Since we were dealing with weighty video files and their large volumes, the critical point was to avoid any adverse impact on the app performance and user experience.",[48,1390,1391],{},"As our task was to develop the project’s MVP, it was critical to consider the web app’s scalability and excellent performance inlined with the best modern practices. That’s why our software engineers decided to build a Vue and Laravel project, as this tech stack and server-side rendering allow us to build scalable web apps and speed up the web development process.",[48,1393,1394],{},"Memwah is a great Vue and Laravel 8 web app example that our team is proud to have in our portfolio.",[48,1396,1397],{},"The video processing, video compilation, and video production are performed by the AWS cloud infrastructure and AWS Lambda serverless architecture by using Laravel Vapor as a deployment tool, allowing the fastest and most seamless performance possible.",[48,1399,1400],{},"Interestingly, Memwah is an excellent example of how AWS Lambda serverless infrastructure can process significant volumes of data concurrently without affecting the website performance and user experience.",[52,1402,1403],{},[48,1404,1405,1406,1409],{},"If you have questions about how we achieved great results with AWS Lambda, whether serverless is a good fit for your project, or if you’re looking for an AWS Lambda development company, don’t hesitate to ",[57,1407,1408],{"href":225},"get in touch with our talented AWS engineers",". We would be happy to help you choose the right cost-effective tech stack for your project.",[48,1411,1412],{},"For the programmatic video production, our web developers were looking for a scalable rendering engine, which has to be compatible with any platform, has adequate rendering time and allows us to process multiple videos at the same time. They came across Remotion (React), which perfectly suited Memwah's needs while allowing a straightforward integration.",[48,1414,1415],{},"The tech stack below allowed our team to develop the project’s MVP faster, while significantly reducing the startup company's infrastructure costs and ongoing expenses.",[1417,1418,1420],"h3",{"id":1419},"frontend","Frontend",[80,1422,1423,1430,1438],{},[83,1424,1425,1426,1429],{},"Vue.js (Vue 3) to ",[57,1427,1428],{"href":130},"build a fast, high-performance SPA"," and a scalable web application.",[83,1431,1432,1433,1437],{},"Laravel Blade templating for ",[57,1434,1436],{"href":1435},"\u002Fnext-js-framework#server-side-rendering-vs-client-side-rendering","server-side rendering",".",[83,1439,1440],{},"Alpine.js, which is a modern and minimal tool for composing JavaScript behaviour directly in the markup.",[1417,1442,1444],{"id":1443},"backend","Backend",[80,1446,1447,1454,1457,1464],{},[83,1448,1449,1450,1453],{},"Laravel (Laravel 8), a robust PHP framework to speed up the ",[57,1451,1452],{"href":926},"web development of the project’s MVP"," and for faster loading and necessary security levels.",[83,1455,1456],{},"Livewire, a full-stack framework for Laravel to build modern, reactive and dynamic interfaces.",[83,1458,1459,1460,1463],{},"VideoJS \u002F RecordJS \u002F FFMPG \u002F Remotion \u002F ",[57,1461,1462],{"href":1129},"React"," to record, decode, process, transform, merge, compile and render videos.",[83,1465,1466],{},"Laravel Nova for CMS and Admin panel.",[1417,1468,1470],{"id":1469},"cloud-servers-serverless-infrastructure","Cloud Servers \u002F Serverless infrastructure",[80,1472,1473],{},[83,1474,1475],{},"Laravel Vapor (AWS Lambda) and other AWS services.",[1417,1477,1479],{"id":1478},"integrations","Integrations",[80,1481,1482,1485,1488,1491,1494],{},[83,1483,1484],{},"Payment gateway with Stripe;",[83,1486,1487],{},"Transactional emails with Amazon Simple Email Service (SES);",[83,1489,1490],{},"MailChimp for email marketing;",[83,1492,1493],{},"Google Sign-In, and",[83,1495,1496],{},"many others.",[43,1498,1500],{"id":1499},"video-recording-platform-features","Video recording platform features",[48,1502,548,1503,1505],{},[65,1504,551],{}," of this online video maker app include:",[80,1507,1508,1511,1522,1525,1528,1531,1534,1539,1542,1545,1548,1551,1556,1559,1562],{},[83,1509,1510],{},"Fast-loading pages and a fast and performant web application.",[83,1512,1513,1514,1517,1518,1521],{},"A scalable application with ",[57,1515,927],{"href":1516},"\u002Flaravel-development-services#laravel-application-development-services"," and ",[57,1519,528],{"href":1520},"\u002Fvue-js-development-services#vue-js-app-development"," to quickly develop new features as the project develops.",[83,1523,1524],{},"A fully-responsive web application with a clean and intuitive UI\u002FUX design to provide an excellent user experience for desktop and mobile users.",[83,1526,1527],{},"Fast video processing in the cloud with a serverless infrastructure and AWS Lambda.",[83,1529,1530],{},"Video recording, decoding, processing, transformation and compilation allow users to record videos in various browsers and devices.",[83,1532,1533],{},"Custom controls (e.g. play button) for Video.js.",[83,1535,1536,1537,1437],{},"Programmatic video rendering and animation using server-side rendering with Remotion and ",[57,1538,1462],{"href":1129},[83,1540,1541],{},"Video player and recorder in a browser.",[83,1543,1544],{},"Optional public URLs for a compiled video to view, share and download videos.",[83,1546,1547],{},"A CMS and Admin Panel with relevant reports and stats by using Laravel Nova.",[83,1549,1550],{},"Payment integrations using Stripe \u002F Stripe Checkout, a prebuilt and hosted payment page that is optimised for conversion.",[83,1552,1553,1437],{},[57,1554,557],{"href":1555},"\u002Flaravel-development-services#custom-laravel-solutions",[83,1557,1558],{},"Transactional emails.",[83,1560,1561],{},"Users can use the web app to record videos in the browser on Mac, Windows, Chrome, Firefox, and the latest version of Safari.",[83,1563,1564],{},"A consistent SEO performance was achieved due to the excellent website speed, responsive design, mobile optimisation, structured metadata, meta attributes, HTTPS certificate, sitemap, etc.",[48,1566,1567,1572,1574],{},[461,1568],{"alt":1569,"src":1570,"title":1571},"memwah.com.au - SEO score at 100","\u002Fuploads\u002Fseo_score_100.jpg","A perfect SEO score at memwah.com.au",[230,1573],{},[230,1575],{},[43,1577,1579],{"id":1578},"the-award-winning-web-app","The award-winning web app",[48,1581,1582,1583,1587,1588,1591],{},"Our team is thrilled and proud for Memwah, ",[57,1584,1586],{"href":1264,"rel":1585},[61],"the best online video recording software",", to be recognised with a Gold for ",[65,1589,1590],{},"Digital Innovation"," at the AusMumpreneur Vic Awards 2021. Yay 🎉",[52,1593,1594],{},[48,1595,1596,1597,1599,1601],{},"“I want to give a HUGE THANKS to Memwah's very talented Developers. Elena and Rus from IT Club are total champions. They have worked tirelessly to build this wonderful program. I'm so grateful for all the late nights, the thousand emails and keeping me grounded as I run off with all my ideas.”",[230,1598],{},[230,1600],{}," - Tammie, the Founder of Memwah",[230,1603],{},[48,1605,1606,1611,1613],{},[461,1607],{"alt":1608,"src":1609,"title":1610},"memwah.com.au - an award-winning app for digital innovation","\u002Fuploads\u002Faward-winning-app.jpg","memwah.com.au is an award-winning app for digital innovation",[230,1612],{},[230,1614],{},[43,1616,1618],{"id":1617},"need-help-with-your-project","Need help with your project?",[48,1620,1621],{},"Are you looking for some help with your project or have some questions? Chat with us. Our talented Vue.js developers, Laravel developers and AWS developers have helped many companies turn their ideas into scalable web apps, and are ready to help you!",[214,1623,1625],{"dataCmsId":216,"className":1624},[218],[214,1626,1628],{"className":1627},[222],[57,1629,228],{"href":225,"className":1630},[227],[230,1632],{},{"title":11,"searchDepth":12,"depth":12,"links":1634},[1635,1636,1637,1643,1644,1645],{"id":1253,"depth":12,"text":1254},{"id":1284,"depth":12,"text":1285},{"id":1381,"depth":12,"text":1382,"children":1638},[1639,1640,1641,1642],{"id":1419,"depth":409,"text":1420},{"id":1443,"depth":409,"text":1444},{"id":1469,"depth":409,"text":1470},{"id":1478,"depth":409,"text":1479},{"id":1499,"depth":12,"text":1500},{"id":1578,"depth":12,"text":1579},{"id":1617,"depth":12,"text":1618},{"title":1248,"summary":1647,"image":1648,"logo":1649,"order":12,"background":247},"A browser-based video recording and editing platform that records stories and combines them into a memorable video gift.","portfolio\u002Fmemwah\u002Fmemwah-card.png",{"width":1650,"src":1651},180,"portfolio\u002Fmemwah\u002Fmemwah-logo.png","A browser-based video recording and editing platform to record and merge video in the browser. Built with Vue.js, React, Laravel, AWS Lambda.",{},"\u002Fonline-video-recording-platform","Elena and Rus from IT Club are total champions - they have worked tirelessly to build this wonderful program.","Tammie, Founder of Memwah",{"title":1248,"description":1652},{"loc":1654},"video-recording-web-application","UI\u002FUX | Web development of a video recording and editing app",[528,1462,927],"hA--LLF6AlkZXciH94Bo_v-TLYqP7Z1Q7sZChfYE-8Y",{"id":1664,"extension":1665,"footer":1666,"header":1709,"meta":1718,"stem":1719,"__hash__":1720},"navigation\u002Fnavigation.yml","yml",[1667,1681,1693],{"label":1668,"items":1669,"path":11},"Web development",[1670,1672,1674,1676,1679],{"label":1671,"path":130},"Vue web development",{"label":1673,"path":1129},"React development services",{"label":1675,"path":926},"Laravel development services",{"label":1677,"path":1678},"Shopify developers Melbourne","\u002Fshopify",{"label":1680,"path":1201},"Next.js developers Melbourne",{"label":1682,"items":1683,"path":11},"Cyber security",[1684,1687,1690],{"label":1685,"path":1686},"Cyber security for small business","\u002Fcyber-security\u002Fsmall-business",{"label":1688,"path":1689},"Lessons from famous breaches","\u002Fcyber-security\u002Fbreach-lessons",{"label":1691,"path":1692},"Free cyber health check","\u002Fcyber-security\u002Fsmall-business\u002Fdiy-cyber-security-health-check",{"label":1694,"items":1695},"Navigate",[1696,1699,1701,1704,1706],{"label":1697,"path":1698},"Home","\u002F",{"label":1700,"path":616},"Case Studies",{"label":1702,"path":1703},"Cyber Security","\u002Fcyber-security",{"label":1705,"path":225},"Contact Us",{"label":1707,"path":1708},"Editorial Policy","\u002Feditorial-policy",[1710,1713,1714,1715],{"label":1711,"path":1712},"Web Development","\u002Fweb-development",{"label":1700,"path":616},{"label":1702,"path":1703},{"label":1716,"path":1717},"About","\u002Fabout",{},"navigation","vaEm85Hrq3ctMNbTgmkywbdLEBklhE1-5zsuR9ZI5Oo",[1722,2241,2794],{"id":1723,"title":1724,"authorBio":1725,"body":1726,"coverImage":2212,"date":2213,"description":2214,"extension":23,"faq":2215,"heroImage":2212,"lastReviewed":25,"meta":2228,"metadata":2229,"navigation":26,"path":2231,"readingTime":2232,"reviewedAgainst":2233,"seo":2234,"sitemap":2235,"stem":2236,"summary":2237,"tags":2238,"thumbnail":2212,"__hash__":2240},"blog\u002Fcyber-security\u002Fsmall-business\u002Fwhy-hackers-target-accounting-firms.md","Why Hackers Target Accounting Firms and How to Reduce the Risk","Written by Elena Osipova, CPA and emerging cyber security practitioner. Drawing on her accounting and business experience, Elena writes about cyber security governance, real-world incidents and practical security controls for Australian small businesses.",{"type":8,"value":1727,"toc":2200},[1728,1731,1734,1737,1740,1743,1747,1750,1795,1798,1801,1804,1808,1811,1814,1823,1827,1830,1851,1854,1858,1861,1865,1868,1900,1904,1907,2048,2052,2058,2064,2070,2076,2083,2087,2146,2149,2153],[48,1729,1730],{},"In May 2025, the Qilin ransomware group listed Melbourne accounting practice MKA Accountants on its darknet leak site. The group published 12 sample documents it claimed were taken from the firm, including financial statements, insurance information and internal correspondence.",[48,1732,1733],{},"MKA Accountants confirmed that it was investigating unauthorised access and had notified clients and relevant authorities, including the Australian Cyber Security Centre (ACSC) and the Office of the Australian Information Commissioner (OAIC). Later reports said Qilin claimed to have released more than 185GB of data, although the exact volume was not independently confirmed.",[48,1735,1736],{},"In May 2026, Brisbane accounting firm Kennedy McLaughlin & Associates confirmed unauthorised access to part of its IT environment after the same ransomware group listed it on their darknet leak site. Cyber Daily reported that a dataset containing client financial details and banking information appeared to have been published. The firm said it had notified affected individuals, the ACSC and the OAIC about this incident.",[48,1738,1739],{},"These were not large organisations. They were local accounting practices - the kind of businesses that hold tax and financial records, payroll and identity document information for many clients.",[48,1741,1742],{},"That set of valuable information is exactly what makes accounting firms attractive targets to cyber criminals.",[43,1744,1746],{"id":1745},"why-accounting-firms-are-valuable-targets","Why accounting firms are valuable targets",[48,1748,1749],{},"Cybercriminals may target an accounting firm for money, but the greater attraction is often the client information and trusted access the firm holds for every client, going back years. This may include:",[80,1751,1752,1757,1762,1767,1773,1779,1784,1789],{},[83,1753,1754],{},[65,1755,1756],{},"Tax file numbers",[83,1758,1759],{},[65,1760,1761],{},"Bank account details",[83,1763,1764],{},[65,1765,1766],{},"Financial statements",[83,1768,1769,1772],{},[65,1770,1771],{},"Payroll data"," such as clients’ employee names, addresses, salaries, bank and superannuation details",[83,1774,1775,1778],{},[65,1776,1777],{},"Identity documents information"," collected for verification",[83,1780,1781],{},[65,1782,1783],{},"Director ID numbers",[83,1785,1786],{},[65,1787,1788],{},"Trust, company and superannuation fund account details",[83,1790,1791,1794],{},[65,1792,1793],{},"Tax and lodgement access information"," like practice-management software, online services for agents, myID-linked access and authorisations that allow staff to act for their clients.",[48,1796,1797],{},"Together, these records can provide enough information for identity theft, tax fraud, and various elaborate, targeted scams.",[48,1799,1800],{},"Accounting and professional service firms are regularly affected by reportable data breaches. In 2025, the OAIC received 1,205 data breach notifications. Legal, accounting and management services accounted for 81 notifications, or approximately 6.7% of the total. This placed the combined sector among the five highest by notification volume.",[48,1802,1803],{},"The information held by accountants for their clients can be used for identity crime, refund fraud and highly convincing scams.",[43,1805,1807],{"id":1806},"what-information-attackers-want","What information attackers want",[48,1809,1810],{},"A stolen TFN isn't just sold once - it's put to work. Cybercriminals have used stolen identities to create fake myGov accounts, link them to real taxpayers' ATO records, then lodge fraudulent tax returns and activity statements and redirect the refunds.",[48,1812,1813],{},"In the two years to February 2023, the ATO cancelled more than 37,000 fraudulent tax returns and business activity statements with a claimed value of $557.8 million. This affected more than 15,000 taxpayers. Some claims were stopped before payment, and the ATO could not attribute the entire amount of claims to a single fraud method.",[48,1815,1816,1817,1822],{},"In February 2024, the ATO said it was defending its websites, services and infrastructure against an average of 4.7 million attempted cyber attacks each month. The ATO maintains the dedicated ",[57,1818,1821],{"href":1819,"rel":1820},"https:\u002F\u002Fwww.ato.gov.au\u002Fonline-services\u002Fscams-cyber-safety-and-identity-protection\u002Fhelp-with-data-breaches\u002Fdata-breach-guidance-for-tax-professionals",[61],"data breach guidance for tax professionals"," so firms can report incidents quickly when client identities, tax information or agent access may have been compromised.",[43,1824,1826],{"id":1825},"how-cyber-attacks-commonly-happen","How cyber attacks commonly happen",[48,1828,1829],{},"Three common attack paths show how a cyber incident may unfold:",[1831,1832,1833,1839,1845],"ol",{},[83,1834,1835,1838],{},[65,1836,1837],{},"Phishing and email takeover."," An employee receives a convincing email prompting them to enter their username and password on a fake but look-alike Microsoft 365 login page. The attacker gets the access and reads the mailbox for weeks, downloads client records, and uses the trusted address to send invoice-redirection emails to clients.",[83,1840,1841,1844],{},[65,1842,1843],{},"Ransomware with data theft."," An attacker gains access, quietly copies information, may then encrypt systems before threatening to publish the stolen data. The MKA Accountants and Kennedy McLaughlin & Associates incidents were publicly associated with this type of attack. Paying a ransom does not guarantee that stolen data will be deleted or kept private.",[83,1846,1847,1850],{},[65,1848,1849],{},"Credential theft against practice software and portals."," Stolen logins for practice management systems or lodgement services give cybercriminals the same reach the practice has - across every client at once.",[48,1852,1853],{},"Highly sophisticated hacking is not always required. Many incidents begin with a stolen password, a phishing message, an unpatched system or access that should have been removed.",[43,1855,1857],{"id":1856},"what-a-breach-can-cost","What a breach can cost",[48,1859,1860],{},"In 2024-25, the average self-reported financial loss per cybercrime report from a small business was approximately $56,600, 14% higher than the previous year.",[43,1862,1864],{"id":1863},"legal-and-professional-obligations","Legal and professional obligations",[48,1866,1867],{},"For an accounting practice, stolen money and ransomware demands are only the beginning. A data breach triggers a stack of obligations that most other small businesses never face. These may include:",[80,1869,1870,1876,1882,1888,1894],{},[83,1871,1872,1875],{},[65,1873,1874],{},"Privacy Act and Notifiable Data Breaches scheme."," Many small accounting practices are TFN recipients and may have Privacy Act obligations for the TFN information they hold, even when annual turnover is $3 million or less. They must notify the OAIC and affected individuals when the breach meets the legal test for an eligible data breach, including that it is likely to cause serious harm.",[83,1877,1878,1881],{},[65,1879,1880],{},"Tax Practitioners Board."," Registered tax practitioners must report a significant breach of the Code of Professional Conduct to the TPB within 30 days of when they know, or ought to know that the breach occurred. A cyber incident may trigger this obligation if it involves a significant breach of duties such as client confidentiality or causes, or is likely to cause material loss or damage. Whether reporting is required depends on the circumstances.",[83,1883,1884,1887],{},[65,1885,1886],{},"ATO notification."," Where client identities, TFNs, tax records or agent access may have been compromised, accounting firms should promptly contact the ATO, so it can assess and apply appropriate protections.",[83,1889,1890,1893],{},[65,1891,1892],{},"Professional standards."," Members of professional accounting bodies, such as CPA Australia, may also have confidentiality obligations under APES 110, the Code of Ethics for Professional Accountants. Registered tax practitioners have separate confidentiality obligations under the TPB Code of Professional Conduct. A failure to take reasonable safeguards may also raise professional and ethical issues, depending on the circumstances.",[83,1895,1896,1899],{},[65,1897,1898],{},"Reputational damage and client attrition."," Clients trust their accountants with everything. A public data leak can cause lasting damage to client trust and the firm’s reputation.",[43,1901,1903],{"id":1902},"controls-that-reduce-the-risk","Controls that reduce the risk",[48,1905,1906],{},"The following controls help reduce the risks discussed above. And most of them are low effort.",[1908,1909,1910,1932],"table",{},[1911,1912,1913],"thead",{},[1914,1915,1916,1922,1927],"tr",{},[1917,1918,1919],"th",{},[65,1920,1921],{},"Control",[1917,1923,1924],{},[65,1925,1926],{},"Risk it reduces",[1917,1928,1929],{},[65,1930,1931],{},"Effort",[1933,1934,1935,1947,1957,1968,1978,1988,1998,2008,2018,2028,2038],"tbody",{},[1914,1936,1937,1941,1944],{},[1938,1939,1940],"td",{},"MFA on email, practice software and tax-related accounts",[1938,1942,1943],{},"Account takeover after password theft",[1938,1945,1946],{},"Low",[1914,1948,1949,1952,1955],{},[1938,1950,1951],{},"Password manager and strong, unique passwords",[1938,1953,1954],{},"Password reuse and credential-stuffing attacks",[1938,1956,1946],{},[1914,1958,1959,1962,1965],{},[1938,1960,1961],{},"Protected backup copy",[1938,1963,1964],{},"Loss of all recoverable copies during ransomware",[1938,1966,1967],{},"Medium",[1914,1969,1970,1973,1976],{},[1938,1971,1972],{},"Segregation of payment duties and independent verification of changed payment details",[1938,1974,1975],{},"Invoice and payment-redirection fraud",[1938,1977,1946],{},[1914,1979,1980,1983,1986],{},[1938,1981,1982],{},"Practical staff training on phishing, unexpected MFA prompts and payment changes",[1938,1984,1985],{},"Staff responding to phishing, unexpected MFA prompts and approving fake payment requests",[1938,1987,1946],{},[1914,1989,1990,1993,1996],{},[1938,1991,1992],{},"Automatic security updates on operating systems and practice software",[1938,1994,1995],{},"Exploitation of known vulnerabilities in unpatched software",[1938,1997,1946],{},[1914,1999,2000,2003,2006],{},[1938,2001,2002],{},"Regular access reviews and offboarding checklist for staff",[1938,2004,2005],{},"Unnecessary access and active former-staff access",[1938,2007,1946],{},[1914,2009,2010,2013,2016],{},[1938,2011,2012],{},"Regular review of third-party, contractor and connected-app access",[1938,2014,2015],{},"Unnecessary access by old providers, contractors or connected apps",[1938,2017,1967],{},[1914,2019,2020,2023,2026],{},[1938,2021,2022],{},"Sign-in and administrator alerts",[1938,2024,2025],{},"Undetected misuse of compromised accounts",[1938,2027,1967],{},[1914,2029,2030,2033,2036],{},[1938,2031,2032],{},"Data retention and secure deletion",[1938,2034,2035],{},"Unnecessary exposure of old client records and identity documents",[1938,2037,1967],{},[1914,2039,2040,2043,2046],{},[1938,2041,2042],{},"Tested incident-response plan",[1938,2044,2045],{},"Delayed containment and missed reporting steps",[1938,2047,1967],{},[1417,2049,2051],{"id":2050},"four-controls-worth-a-closer-look","Four controls worth a closer look",[48,2053,2054,2057],{},[65,2055,2056],{},"Review what you keep."," Retain records for the periods required by law and professional standards, but securely delete duplicate files, outdated identity documents and other information when there is no longer legal, professional or business reason to keep it. Holding less unnecessary information reduces the potential impact of a breach.",[48,2059,2060,2063],{},[65,2061,2062],{},"Review connected services."," Check which cloud platforms, software integrations, contractors and service providers can access client information. Remove unused and unnecessary connections, confirm who has administrator access and understand how each provider protects and backs up your data.",[48,2065,2066,2069],{},[65,2067,2068],{},"Train staff on real warning signs."," Make sure employees know how to recognise suspicious login pages, unexpected MFA prompts and urgent payment requests. They should know who to contact and what to do before clicking, approving a prompt or making a payment.",[48,2071,2072,2075],{},[65,2073,2074],{},"Protect at least one backup copy."," Keep one backup offline, immutable or otherwise protected from normal user accounts and devices. Test regularly that important files can be restored from it.",[48,2077,2078,2079,2082],{},"Use our ",[57,2080,2081],{"href":1692},"DIY cyber security health check"," for a structured review of your accounts, payments, backups, devices and business processes.",[43,2084,2086],{"id":2085},"five-actions-to-take-this-week","Five actions to take this week",[1831,2088,2089,2095,2114,2120,2126],{},[83,2090,2091,2094],{},[65,2092,2093],{},"Turn on MFA"," for every supported business account, beginning with email, administrator, financial and tax-related accounts. Where available, use phishing-resistant methods like passkeys or security keys.",[83,2096,2097,2100],{},[65,2098,2099],{},"Give staff two clear rules:",[1831,2101,2102,2108],{},[83,2103,2104,2107],{},[65,2105,2106],{},"Never approve an MFA prompt they did not request",". An unexpected prompt may mean someone is trying to access the account.",[83,2109,2110,2113],{},[65,2111,2112],{},"Never change payment details based on an email alone",". Confirm the request by calling a trusted phone number already held by the firm.",[83,2115,2116,2119],{},[65,2117,2118],{},"Enable automatic security updates where supported."," Keep computers, servers, browsers, practice software, remote access tools and internet-facing devices protected against known vulnerabilities.",[83,2121,2122,2125],{},[65,2123,2124],{},"Review your user list."," Check every account and access role. Promptly disable accounts belonging to former staff. Treat any unknown or suspicious account as urgent.",[83,2127,2128,2131,2132,2135,2136,2141,2142,2145],{},[65,2129,2130],{},"Print your incident contacts."," Include the ATO's ",[57,2133,1821],{"href":1819,"rel":2134},[61],", the OAIC, the TPB, ",[57,2137,2140],{"href":2138,"rel":2139},"https:\u002F\u002Fwww.cyber.gov.au\u002Freport-and-recover\u002Fwhere-get-help",[61],"ReportCyber"," and the Australian Cyber Security Hotline ",[65,2143,2144],{},"1300 CYBER1 (1300 292 371)",". You should also include your IT or incident-response provider; cyber insurer and policy number; legal or privacy adviser; authorised decision-maker.",[48,2147,2148],{},"Cybercriminals target accounting firms because the information and access they hold can be highly valuable. The good news is that you can strengthen your defences  with basic, consistent controls to make many common attack paths much harder.",[43,2150,2152],{"id":2151},"sources-used","Sources used",[80,2154,2155,2158,2161,2164,2167,2170,2173,2176,2179,2182,2185,2188,2191,2194,2197],{},[83,2156,2157],{},"ASD, Annual Cyber Threat Report 2024-25",[83,2159,2160],{},"OAIC, Data breach notifications increase to all-time high in 2025",[83,2162,2163],{},"OAIC, Quick reference guide for responding to data breaches",[83,2165,2166],{},"OAIC, The Privacy (Tax File Number) Rule 2015 and the protection of TFN information",[83,2168,2169],{},"ATO, Agent checklist for client-to-agent linking process",[83,2171,2172],{},"ATO, Accessing Online services for agents",[83,2174,2175],{},"ATO, Data breach guidance for tax professionals",[83,2177,2178],{},"Australian Government, Privacy (Tax File Number) Rule 2015",[83,2180,2181],{},"TPB, Breach reporting obligations;",[83,2183,2184],{},"TPB, Protect your practice from cyber-attacks",[83,2186,2187],{},"TPB, Debunking myths about breach reporting",[83,2189,2190],{},"iTnews, ATO attackers filed $557 million in false claims",[83,2192,2193],{},"Cyber Daily, MKA Accountants confirms Qilin ransomware attack",[83,2195,2196],{},"Cyber Daily, Kennedy McLaughlin confirms cyber incident",[83,2198,2199],{},"ABC, Outgoing ATO boss says getting rid of work-related tax deductions would be a 'big step'",{"title":11,"searchDepth":12,"depth":12,"links":2201},[2202,2203,2204,2205,2206,2207,2210,2211],{"id":1745,"depth":12,"text":1746},{"id":1806,"depth":12,"text":1807},{"id":1825,"depth":12,"text":1826},{"id":1856,"depth":12,"text":1857},{"id":1863,"depth":12,"text":1864},{"id":1902,"depth":12,"text":1903,"children":2208},[2209],{"id":2050,"depth":409,"text":2051},{"id":2085,"depth":12,"text":2086},{"id":2151,"depth":12,"text":2152},"\u002Fcovers\u002Fcyber-security\u002Fsmall-business\u002Fwhy-hackers-target-accounting-firms.jpg","2026-07-27T00:00:00.000Z","Learn why accounting firms attract cybercriminals and the practical steps small practices can take to protect client data and reduce cyber risk.",[2216,2219,2222,2225],{"question":2217,"answer":2218},"Why would hackers target a small accounting firm instead of a big company","A small accounting firm may hold the same kinds of valuable client information as a big company, including TFNs, payroll records, bank details and identity documents. At the same time, smaller firms may have fewer dedicated IT and security resources. This combination can make them attractive to cybercriminals.",{"question":2220,"answer":2221},"Does the Privacy Act apply to my accounting practice if turnover is under $3 million?","Under the Privacy (Tax File Number) Rule 2015, many accounting practices with annual turnover of $3 million or less still have Privacy Act obligations because they receive and hold TFN information. If a breach is likely to cause serious harm, the practice may need to notify the OAIC and affected individuals under the Notifiable Data Breaches scheme. Other Privacy Act exceptions may also apply. Obtain legal or privacy advice for your circumstances.",{"question":2223,"answer":2224},"What is the single most effective protection for an accounting firm?","Multi-factor authentication (MFA) is one of the most important protections for administrator, email, practice management software and tax-related accounts. It adds another layer of protection when a password is stolen or phished.",{"question":2226,"answer":2227},"What should an accounting firm do immediately after discovering a data breach?","Where safe and appropriate, disconnect an affected computer from Wi-Fi or the network without wiping or resetting it, and seek qualified IT or incident-response support. Contact the ATO promptly if client tax information or agent access may be affected. The firm should then assess its notification obligations. These may include notifying the OAIC and affected individuals under the Notifiable Data Breaches scheme, the TPB where a significant Code of Professional Conduct breach may have occurred; professional associations, insurers, and other affected parties",{},{"description":2214,"title":2230},"Why Hackers Target Accounting Firms & How to Reduce the Risk","\u002Fcyber-security\u002Fsmall-business\u002Fwhy-hackers-target-accounting-firms",9,"Reviewed against current guidance from ASD’s Australian Cyber Security Centre, the OAIC, business.gov.au, the ATO and TPB",{"title":1724,"description":2214},{"loc":2231},"cyber-security\u002Fsmall-business\u002Fwhy-hackers-target-accounting-firms","Accounting firms hold the keys to their clients' finances - which is exactly why they're such an attractive target for cybercriminals. Here's what makes them vulnerable, and how to close the cyber security gaps.",[1702,2239],"Small Business","JKrfW2SpuQSHKmIm97ylyA-qvnCXZppsJchpqGZpN5c",{"id":2242,"title":2243,"authorBio":2244,"body":2245,"coverImage":2763,"date":2213,"description":2764,"extension":23,"faq":2765,"heroImage":2763,"lastReviewed":25,"meta":2784,"metadata":2785,"navigation":26,"path":1692,"readingTime":20,"reviewedAgainst":2788,"seo":2789,"sitemap":2790,"stem":2791,"summary":2764,"tags":2792,"thumbnail":2763,"__hash__":2793},"blog\u002Fcyber-security\u002Fsmall-business\u002Fdiy-cyber-security-health-check.md","The DIY Cyber Security Health Check for Small Business","Written by Elena Osipova, CPA, an emerging Cyber Security Practitioner. Elena writes about cyber security governance and practical security controls for Australian small businesses.",{"type":8,"value":2246,"toc":2747},[2247,2250,2256,2262,2268,2271,2275,2286,2332,2335,2355,2359,2366,2370,2373,2413,2417,2447,2451,2489,2493,2523,2528,2532,2541,2552,2555,2597,2604,2611,2615,2618,2621,2644,2648,2651,2654,2663,2672,2676,2679,2690,2692,2705,2707,2709],[48,2248,2249],{},"You don't need a consultant to find many of your most common cyber risks. One structured afternoon can uncover preventable gaps, such as a former employee's active login, a backup that doesn't restore files, or a payment process that trusts email alone.",[48,2251,2252,2255],{},[65,2253,2254],{},"To complete this checklist, allow around three to four hours",". A very small business may finish much sooner, while a business with more users, devices and cloud services may need additional time. You'll need administrator access to Microsoft 365 or Google Workspace, access to your backup system, and a notepad or spreadsheet for recording your findings.",[48,2257,2258,2261],{},[65,2259,2260],{},"The method matters more than the tools: look at evidence, not memory",". “I think only two people have admin access” is an assumption. Opening the admin panel and counting them gives you a fact. Each step below asks you to check an actual setting, process or record.",[48,2263,2264,2267],{},[65,2265,2266],{},"Write down every issue you find",". Unless some findings appear urgent, don’t stop to fix each issue as you go, or you may burn the whole afternoon on the first item. Fixing them comes later, in priority order shown below.",[48,2269,2270],{},"However, act immediately if you find a clear sign of active compromise. Tis includes an unknown account administrator, an unauthorised payment or an email forwarding rule you did not create.",[43,2272,2274],{"id":2273},"step-1-accounts-and-access-60-minutes","Step 1: Accounts and access - 60 minutes",[48,2276,2277,2278,2281,2282,2285],{},"Open the ",[65,2279,2280],{},"Microsoft 365 Admin Centre"," or ",[65,2283,2284],{},"Google Workspace Admin Console"," and check six things:",[80,2287,2288,2294,2308,2314,2320,2326],{},[83,2289,2290,2293],{},[65,2291,2292],{},"The user list."," Read every name. Is anyone no longer with the business but still active? Is there an account you cannot explain? Record former users for removal. Remove unknown users urgently.",[83,2295,2296,2299,2300,2303,2304,2307],{},[65,2297,2298],{},"MFA coverage."," Confirm that every user is required to use MFA and has completed registration. ",[65,2301,2302],{},"In Microsoft 365",", don’t rely only on the legacy per-user MFA status: MFA may instead be enforced through Security Defaults or Conditional Access. Check both - the organisation-wide policy and the users who have registered. ",[65,2305,2306],{},"In Google Workspace",", check 2-Step Verification enrolment and enforcement.",[83,2309,2310,2313],{},[65,2311,2312],{},"Who's an administrator?"," Count the accounts with administrator roles. There should be very few, and you should be able to explain why each person needs that level of access.",[83,2315,2316,2319],{},[65,2317,2318],{},"Guest and external access."," Review guest users, contractors, delegated mailbox access and connected third-party applications. Remove access that is no longer required.",[83,2321,2322,2325],{},[65,2323,2324],{},"Email forwarding rules."," Check the business owner's and finance mailboxes for rules that forward messages outside the business. Cyber criminals who compromise email accounts may create a hidden forwarding rule. It may remain active after the password is changed. Treat anything you do not recognise as urgent.",[83,2327,2328,2331],{},[65,2329,2330],{},"Account recovery."," For owner and administrator accounts, check the recovery email addresses, phone numbers and backup methods. Remove outdated details. Store emergency recovery codes securely and make sure the business - not one employee personally - controls the recovery process.",[48,2333,2334],{},"Other important account checks:",[80,2336,2337,2343,2349],{},[83,2338,2339,2342],{},[65,2340,2341],{},"Email domain protection."," If your business uses its own email domain, ask your email provider or IT administrator to confirm that SPF, DKIM and DMARC are configured correctly. These help other email systems recognise messages that falsely claim to come from your domain.",[83,2344,2345,2348],{},[65,2346,2347],{},"Domain-name protection."," Sign in to your domain registrar and confirm that your business controls the account, MFA is turned on, the recovery details are current and automatic renewal is enabled. Losing control of your domain can affect your website, email and password resets.",[83,2350,2351,2354],{},[65,2352,2353],{},"Passwords and shared accounts."," Check whether staff reuse passwords or share one login. Each person should have their own account. All important accounts should use unique passwords stored in a reputable password manager.",[1417,2356,2358],{"id":2357},"evidence-to-keep","Evidence to keep",[48,2360,2361,2362,2365],{},"Export or screenshot the user list and MFA report. Date it. ",[65,2363,2364],{},"This is your baseline"," for next time. Store this user list securely as it contains personal information and details that could help a cyber criminal.",[43,2367,2369],{"id":2368},"step-2-money-paths-30-minutes","Step 2: Money paths - 30 minutes",[48,2371,2372],{},"Review your actual payment process and recent examples:",[80,2374,2375,2385,2407],{},[83,2376,2377,2380,2381,2384],{},[65,2378,2379],{},"How do suppliers change their bank details?"," If the answer is \"by email\", record it as a finding. ",[65,2382,2383],{},"Never accept new or changed payment details without confirming the request through a separate, trusted channel."," For example, call the supplier using a phone number you already have, not a phone number provided in the email.",[83,2386,2387,2390,2391,2394,2395,2398,2399,2402,2403,2406],{},[65,2388,2389],{},"Can one person create and approve payments alone?"," Where separation of duties is not practical, use several compensating controls: ",[65,2392,2393],{},"independent verification"," of new or changed payment details, ",[65,2396,2397],{},"bank transaction limits",", ",[65,2400,2401],{},"payment alerts"," and a ",[65,2404,2405],{},"regular review of payments"," by another owner, director or trusted adviser.",[83,2408,2409,2412],{},[65,2410,2411],{},"Does your banking show information about the recipient before you approve a payment?"," This may include an account-name check, PayID name or Confirmation of Payee result. Make sure whoever pays invoices understands the message,but does not use it as a substitute for independently confirming changed payment details.",[43,2414,2416],{"id":2415},"step-3-backups-and-cloud-systems-30-minutes","Step 3: Backups and cloud systems - 30 minutes",[80,2418,2419,2425,2431,2441],{},[83,2420,2421,2424],{},[65,2422,2423],{},"What is actually backed up?"," Name the systems and information your business could not operate without. Examples may include accounting and payroll records, client files, email, customer databases, contracts, website data, source code, project files, important system settings and more. Confirm that each one is included in the backup, not just \"the computer\".",[83,2426,2427,2430],{},[65,2428,2429],{},"Is one backup copy protected?"," A permanently connected drive or a synchronised folder like OneDrive or Google Drive should not be your only backup. Deleted, encrypted, damaged files or ransomware may be synchronised across devices. Check whether your service offers separate version history or recovery features.",[83,2432,2433,2436,2437,2440],{},[65,2434,2435],{},"Restore one real file now."," Pick any recent document from your backup, restore it and open it. ",[65,2438,2439],{},"This may be the highest-value ten minutes of the whole health check",". A backup that has never been tested is only an assumption. If the restore fails, you have discovered the problem before a real emergency.",[83,2442,2443,2446],{},[65,2444,2445],{},"Critical cloud systems."," List the online services your business relies on. Examples may include accounting, payroll, CRM, website hosting and document storage. Confirm who owns each account, who has administrator access, and what recovery or export options are available.",[43,2448,2450],{"id":2449},"step-4-devices-and-updates-30-minutes","Step 4: Devices and updates - 30 minutes",[80,2452,2453,2459,2465,2471,2477,2483],{},[83,2454,2455,2458],{},[65,2456,2457],{},"Is every work computer and phone supported and automatically updating?"," Check whether the operating system is still receiving updates, and whether automatic updates are on. Put anything that no longer receives security updates on the replacement list - it cannot be protected to the same standard as a supported device.",[83,2460,2461,2464],{},[65,2462,2463],{},"Are laptops encrypted?"," Check whether BitLocker on Windows or FileVault on Mac is turned on.",[83,2466,2467,2470],{},[65,2468,2469],{},"Is computer protection working?"," Check that antivirus or other built-in security protection is turned on and up to date.",[83,2472,2473,2476],{},[65,2474,2475],{},"Do devices lock automatically?"," Make sure computers and phones lock after a short period of inactivity and require a strong password, passcode, PIN or biometric sign-in.",[83,2478,2479,2482],{},[65,2480,2481],{},"Does each person have their own login?"," Ensure that staff do not share accounts and do not use an administrator account for everyday work.",[83,2484,2485,2488],{},[65,2486,2487],{},"Lost phones."," If a phone with company email went missing today, could you wipe it remotely? If you don't know, the answer is no.",[43,2490,2492],{"id":2491},"step-5-people-and-paper-30-minutes","Step 5: People and paper - 30 minutes",[80,2494,2495,2501,2513],{},[83,2496,2497,2500],{},[65,2498,2499],{},"Offboarding checklist."," Is there a written checklist removing a departing employee or contractor’s access to every business system? If not, create one using the user list from Step 1.",[83,2502,2503,2506,2507,2509,2510,2512],{},[65,2504,2505],{},"The two rules for staff."," Make sure everyone who works with email or payments knows these rules:",[230,2508],{},"\n1 - Never approve an MFA prompt you didn't request. Repeated unexpected prompts may mean that someone already has your password.",[230,2511],{},"\n2 - Never change suppliers’ bank details based on an email alone. Confirm the changes by calling a trusted phone number you already have.",[83,2514,2515,2518,2519,2522],{},[65,2516,2517],{},"The incident card."," Print one page with your bank's fraud number, the Australian Cyber Security Hotline 1300 CYBER1 (1300 292 371) - it’s available 24\u002F7, and the ",[57,2520,2140],{"href":2138,"rel":2521},[61]," web address. Also include your cyber insurer and policy number, IT or incident-response provider, legal or privacy adviser, authorised decision-maker, domain registrar and website host. Keep this card somewhere accessible if your systems are unavailable.",[52,2524,2525],{},[48,2526,2527],{},"If you suspect an active incident, stop the health check and seek professional assistance. Do not delete files, messages or logs that may be evidence. Where safe to do so, disconnect an affected computer from Wi-Fi or the network without wiping or resetting it.",[43,2529,2531],{"id":2530},"step-6-official-checks-and-your-findings-20-minutes","Step 6: Official checks and your findings - 20 minutes",[48,2533,2534,2535,2540],{},"Finish with the Australian government’s free and anonymous ",[57,2536,2539],{"href":2537,"rel":2538},"https:\u002F\u002Fwww.cyber.gov.au\u002Fcyberhealthcheck",[61],"Cyber Health Check Tool",". It takes about five minutes and provides simple, tailored suggestions that you can compare with your findings.",[52,2542,2543],{},[48,2544,2545,2546,2551],{},"For a deeper follow-up with your team, use the ACSC's free ",[57,2547,2550],{"href":2548,"rel":2549},"https:\u002F\u002Fwww.cyber.gov.au\u002Fbusiness-government\u002Fexercise-in-a-box",[61],"Exercise in a Box",".  It provides practical exercises to help you test how your business would respond to a cyber incident.",[48,2553,2554],{},"Turn your notes into an action plan. Use one row for each finding and four columns:",[1908,2556,2557,2581],{},[1911,2558,2559],{},[1914,2560,2561,2566,2571,2576],{},[1917,2562,2563],{},[65,2564,2565],{},"Finding",[1917,2567,2568],{},[65,2569,2570],{},"Risk",[1917,2572,2573],{},[65,2574,2575],{},"Fix",[1917,2577,2578],{},[65,2579,2580],{},"Who \u002F by when",[1933,2582,2583],{},[1914,2584,2585,2588,2591,2594],{},[1938,2586,2587],{},"2 staff accounts do not have MFA",[1938,2589,2590],{},"A stolen password could allow someone to access business email",[1938,2592,2593],{},"Enforce MFA",[1938,2595,2596],{},"Me \u002F Friday",[48,2598,2599,2600,2603],{},"That simple table is the beginning of a practical ",[65,2601,2602],{},"cyber security risk register",". Over time, you can add the severity of the risk, status and date reviewed.",[48,2605,2606,2607,2610],{},"For most small businesses, repeating this ",[65,2608,2609],{},"check every three months"," is a practical starting point. Run it sooner after an employee departure, major system change or suspected incident.",[1417,2612,2614],{"id":2613},"prioritise-your-findings-or-what-should-i-fix-first-after-the-health-check","Prioritise your findings, or what should I fix first after the health check?",[48,2616,2617],{},"Deal immediately with any sign of active compromise. Examples may include an unknown administrator, unexplained email forwarding rule, unfamiliar login or unauthorised payment.",[48,2619,2620],{},"For other findings, a practical starting order is:",[1831,2622,2623,2626,2629,2632,2635,2638,2641],{},[83,2624,2625],{},"Protect administrator, email and financial accounts with MFA.",[83,2627,2628],{},"Disable former users who still have access.",[83,2630,2631],{},"Confirm that critical information can be restored from backup.",[83,2633,2634],{},"Strengthen payment verification and approval controls.",[83,2636,2637],{},"Update devices and software.",[83,2639,2640],{},"Replace unsupported devices and software.",[83,2642,2643],{},"Address the remaining findings according to their likely business impact.",[43,2645,2647],{"id":2646},"when-diy-isnt-enough","When DIY isn't enough",[48,2649,2650],{},"This health check can identify common security gaps, but it does not test your systems for technical weaknesses. Seek professional help if there’s a suspected cyber security incident, when important findings remain unfixed, when your business needs technical security testing, or when it holds sensitive or high-risk information such as health records, identity documents, TFNs or financial details.",[48,2652,2653],{},"Most Australian businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but important exceptions apply. For example, some health service providers, businesses that trade in personal information and certain Commonwealth contractors may be covered regardless of turnover.",[48,2655,2656,2657,2662],{},"Check the ",[57,2658,2661],{"href":2659,"rel":2660},"https:\u002F\u002Fwww.oaic.gov.au\u002Fprivacy\u002Fprivacy-guidance-for-organisations-and-government-agencies\u002Forganisations\u002Fsmall-business#section-privacy-checklist-for-small-business",[61],"OAIC’s Small Business Privacy Checklist"," or obtain legal advice if you are unsure whether the Privacy Act applies to your business",[48,2664,2665,2666,2671],{},"When engaging a cyber security provider, ask what framework and assessment method they will use. Depending on your systems and risks, an ",[57,2667,2670],{"href":2668,"rel":2669},"https:\u002F\u002Fwww.cyber.gov.au\u002Fbusiness-government\u002Fasds-cyber-security-frameworks\u002Fessential-eight",[61],"Essential Eight"," assessment - often beginning with Maturity Level One - may provide a structured and comparable baseline.",[1417,2673,2675],{"id":2674},"cant-spare-a-whole-afternoon","Can't spare a whole afternoon?",[48,2677,2678],{},"Do the ten-minute version:",[1831,2680,2681,2684,2687],{},[83,2682,2683],{},"Check that MFA protects the owner's email account.",[83,2685,2686],{},"Explain the payment-verification rule to anyone who pays invoices.",[83,2688,2689],{},"Restore one file from backup.",[198,2691],{},[48,2693,2694],{},[2695,2696,2697,2698,2701,2702,1437],"em",{},"This article is part of our ",[57,2699,2700],{"href":1686},"cyber security for small businesses"," series - including ",[57,2703,2704],{"href":2231},"why hackers target accounting firms",[198,2706],{},[43,2708,2152],{"id":2151},[80,2710,2711,2714,2717,2720,2723,2726,2729,2732,2735,2738,2741,2744],{},[83,2712,2713],{},"ASD’s ACSC, Cyber Health Check Tool",[83,2715,2716],{},"ASD’s ACSC, Small Business Cyber Security Guide",[83,2718,2719],{},"ASD’s ACSC, Small Business Hub",[83,2721,2722],{},"ASD’s ACSC, Preventing Business Email Compromise",[83,2724,2725],{},"ASD’s ACSC, Review Your Email Account Security",[83,2727,2728],{},"ASD’s ACSC, Exercise in a Box",[83,2730,2731],{},"ASD’s ACSC, Essential Eight",[83,2733,2734],{},"ASD’s ACSC, Cybercrime - getting help",[83,2736,2737],{},"business.gov.au, Cyber Security Checklist",[83,2739,2740],{},"OAIC, Small Business and the Privacy Act",[83,2742,2743],{},"Microsoft Learn, relevant current MFA administration guidance",[83,2745,2746],{},"Google Workspace Admin Help, relevant 2-Step Verification guidance",{"title":11,"searchDepth":12,"depth":12,"links":2748},[2749,2752,2753,2754,2755,2756,2759,2762],{"id":2273,"depth":12,"text":2274,"children":2750},[2751],{"id":2357,"depth":409,"text":2358},{"id":2368,"depth":12,"text":2369},{"id":2415,"depth":12,"text":2416},{"id":2449,"depth":12,"text":2450},{"id":2491,"depth":12,"text":2492},{"id":2530,"depth":12,"text":2531,"children":2757},[2758],{"id":2613,"depth":409,"text":2614},{"id":2646,"depth":12,"text":2647,"children":2760},[2761],{"id":2674,"depth":409,"text":2675},{"id":2151,"depth":12,"text":2152},"\u002Fcovers\u002Fcyber-security\u002Fsmall-business\u002Fdiy-cyber-security-health-check.jpg","A practical, jargon-free cyber security checklist you can complete this afternoon to see where your business is exposed - no IT department required.",[2766,2769,2772,2775,2778,2781],{"question":2767,"answer":2768},"Can a small business complete a cyber security health check without an IT provider?","Yes. A business owner or manager can check common risks, including inactive accounts, missing MFA, untested backups, unsupported devices and unsafe payment processes. Please note that a DIY review does not test networks, applications or systems for technical vulnerabilities.",{"question":2770,"answer":2771},"Do I need an IT background to run a cyber security health check?","No. You need admin access to your Microsoft 365 or Google Workspace, your backup system login, and a notepad. Follow the cyber security checklist steps and write down your findings to act on them later.",{"question":2773,"answer":2774},"Is OneDrive or Google Drive a backup?","File synchronisation may help recover earlier files, but a synchronised folder should not be your business’ only backup. Deletions, damaged files or ransomware may be synchronised across devices. Keep a separate protected backup and regularly test that you can restore files from it.",{"question":2776,"answer":2777},"How often should a small business run a cyber security health check?","Every three months is a practical starting point. Run the check sooner if there is a major change, such as a staff departure, the introduction of new software, a change of IT provider or a suspected cyber security incident.",{"question":2779,"answer":2780},"Is there a free government cyber security assessment for small businesses?","Yes. The Cyber Health Check Tool on cyber.gov.au is free and anonymous. It provides tailored suggestions based on your answers. The ACSC's free Exercise in a Box can help your team practice responding to realistic cyber incident scenarios.",{"question":2782,"answer":2783},"When should a business get professional cyber security help?","Seek professional help after a suspected cyber security incident, when important security issues remain unresolved, when a technical testing is required, or when your business holds sensitive or high-risk information, such as health records, identity documents, tax file numbers or financial details. Most Australian small businesses with annual turnover of $3 million or less are not covered by the Privacy Act, but important exceptions apply. Obtain privacy or legal advice if you are unsure whether the Privacy Act applies to your business.",{},{"description":2786,"title":2787},"A plain-English cyber security checklist Australian small businesses can complete themselves, with practical steps and no IT department required.","DIY Cyber Security Health Check for Small Business","Reviewed against current guidance from ASD’s Australian Cyber Security Centre, business.gov.au, the OAIC, Microsoft and Google",{"title":2243,"description":2764},{"loc":1692},"cyber-security\u002Fsmall-business\u002Fdiy-cyber-security-health-check",[1702,2239],"Nhqi3lLVSDN8wAzFS-1zxT1E-fupXjMiRnQ7gSAcOXw",{"id":2795,"title":2796,"authorBio":2797,"body":2798,"coverImage":3393,"date":2213,"description":3394,"extension":23,"faq":3395,"heroImage":3393,"lastReviewed":25,"meta":3396,"metadata":3397,"navigation":26,"path":3399,"readingTime":3400,"reviewedAgainst":3401,"seo":3402,"sitemap":3403,"stem":3404,"summary":3405,"tags":3406,"thumbnail":3393,"__hash__":3408},"blog\u002Fcyber-security\u002Fbreach-lessons\u002Fmedibank-breach.md","What The Medibank Breach Teaches Small Businesses","Written by Elena Osipova, CPA, an emerging Cyber Security Practitioner. Elena writes about enterprise breaches, cyber security governance and practical security controls to help Australian small businesses improve their own defences.",{"type":8,"value":2799,"toc":3377},[2800,2803,2808,2811,2814,2817,2821,2824,2827,2830,2833,2837,3005,3009,3012,3032,3039,3043,3075,3079,3123,3127,3130,3150,3154,3216,3220,3223,3227,3253,3257,3295,3299,3302,3316,3320,3323,3326,3331,3333],[48,2801,2802],{},"In October 2022, Medibank, one of Australia's largest private health insurers, disclosed that a cybercriminal had stolen about 520GB of data. The breach affected around 9.7 million current and former Medibank, ahm and international customers and representatives, including people whose sensitive health claims information was exposed.",[52,2804,2805],{},[48,2806,2807],{},"Through its Medibank and ahm brands, the group insures millions of people across Australia.",[48,2809,2810],{},"The weaknesses that contributed to this breach were not unusual. According to allegations filed by the Australian Information Commissioner, an employee of a Medibank IT contractor saved Medibank credentials in his browser profile on a work computer. When he signed into the same browser profile on a personal computer, the credentials synchronised to that device and were later stolen by malware.",[48,2812,2813],{},"A cybercriminal then used the compromised credentials to access Medibank’s remote-access VPN, which did not require MFA for that login method. Medibank’s security software raised alerts about suspicious activity, but they were delayed to triage for weeks.",[48,2815,2816],{},"Three basic controls failed in a large organisation. Every one of them could be missing in small businesses too.",[43,2818,2820],{"id":2819},"what-happened","What happened",[48,2822,2823],{},"On 13 October 2022, Medibank disclosed unusual activity on its network and initially said there was no evidence that customer data had been removed. On 19 and 22 October, an attacker contacted Medibank and supplied sample files. Medibank later confirmed that information connected to around 9.7 million people had been stolen. The OAIC alleges that about 520GB of data was exfiltrated between late August and 13 October 2022.",[48,2825,2826],{},"The attacker demanded US$10 million. Medibank refused to pay, explaining that payment could not guarantee the return or deletion of the data and might encourage further extortion.",[48,2828,2829],{},"From 9 November to 1 December 2022, stolen information was published on a dark-web leak site in stages, fully releasing the dataset. Published files included highly sensitive health claims information, including records about HIV, drug and alcohol treatment, mental health, and abortions. Australian authorities later attributed the attack to Russian national Aleksandr Ermakov, who was associated with the REvil cybercrime group.",[48,2831,2832],{},"In January 2024, Australia used its cyber sanctions framework for the first time and designated Aleksandr Ermakov for his role in the Medibank breach, imposing targeted financial sanctions and a travel ban. Dealing with a designated person or their assets can be a criminal offence carrying severe penalties, including up to 10 years’ imprisonment for an individual.",[43,2834,2836],{"id":2835},"the-timeline","The timeline",[1908,2838,2839,2853],{},[1911,2840,2841],{},[1914,2842,2843,2848],{},[1917,2844,2845],{},[65,2846,2847],{},"Date",[1917,2849,2850],{},[65,2851,2852],{},"Event",[1933,2854,2855,2865,2875,2885,2895,2905,2915,2925,2935,2945,2955,2965,2975,2985,2995],{},[1914,2856,2857,2862],{},[1938,2858,2859],{},[65,2860,2861],{},"Prior to 7 August 2022",[1938,2863,2864],{},"A contractor employee saved Medibank credentials in a browser profile on a work computer. The credentials were later synchronised to his personal computer.",[1914,2866,2867,2872],{},[1938,2868,2869],{},[65,2870,2871],{},"Around 7 August 2022",[1938,2873,2874],{},"Malware on the personal computer stole the Medibank credentials.",[1914,2876,2877,2882],{},[1938,2878,2879],{},[65,2880,2881],{},"12 August 2022",[1938,2883,2884],{},"The attacker tested the stolen admin credentials against Medibank’s Microsoft Exchange server.",[1914,2886,2887,2892],{},[1938,2888,2889],{},[65,2890,2891],{},"Around 23 August 2022",[1938,2893,2894],{},"The attacker first logged in to Medibank’s GlobalProtect VPN, with no MFA required.",[1914,2896,2897,2902],{},[1938,2898,2899],{},[65,2900,2901],{},"24 - 25 August 2022",[1938,2903,2904],{},"Medibank’s security software generated alerts, sending them to an IT operations mailbox. The OAIC alleges they were not appropriately triaged or escalated.",[1914,2906,2907,2912],{},[1938,2908,2909],{},[65,2910,2911],{},"25 August - 13 October 2022",[1938,2913,2914],{},"The attacker accessed Medibank's internal systems and exfiltrated about 520GB of data.",[1914,2916,2917,2922],{},[1938,2918,2919],{},[65,2920,2921],{},"11 October 2022",[1938,2923,2924],{},"Medibank triaged a high-severity alert and engaged its incident-response partner.",[1914,2926,2927,2932],{},[1938,2928,2929],{},[65,2930,2931],{},"13 October 2022",[1938,2933,2934],{},"Medibank publicly discloses the incident, initially stating that there was no evidence that customer data had been removed.",[1914,2936,2937,2942],{},[1938,2938,2939],{},[65,2940,2941],{},"19 and 22 October 2022",[1938,2943,2944],{},"The attacker contacted Medibank and supplied sample files with stolen data.",[1914,2946,2947,2952],{},[1938,2948,2949],{},[65,2950,2951],{},"7 November 2022",[1938,2953,2954],{},"Medibank confirmed the scale of the breach: 9.7 million people and publicly refused to pay the ransom.",[1914,2956,2957,2962],{},[1938,2958,2959],{},[65,2960,2961],{},"9 November - 1 December 2022",[1938,2963,2964],{},"Stolen information was published on the dark web in stages, ending with the full 520GB released.",[1914,2966,2967,2972],{},[1938,2968,2969],{},[65,2970,2971],{},"27 June 2023",[1938,2973,2974],{},"APRA announced a $250M increase in Medibank’s capital adequacy requirement until remediation was completed to APRA’s satisfaction.",[1914,2976,2977,2982],{},[1938,2978,2979],{},[65,2980,2981],{},"23 January 2024",[1938,2983,2984],{},"Australia imposed its first cyber sanction, designating Aleksandr Ermakov for his role in the breach.",[1914,2986,2987,2992],{},[1938,2988,2989],{},[65,2990,2991],{},"5 June 2024",[1938,2993,2994],{},"The OAIC files civil penalty proceedings in the Federal Court over alleged failure to take reasonable steps to protect personal information.",[1914,2996,2997,3002],{},[1938,2998,2999],{},[65,3000,3001],{},"As of July 2026",[1938,3003,3004],{},"The OAIC proceedings continued, and the Medibank class action remained listed as open in the Federal Court.",[43,3006,3008],{"id":3007},"how-the-attacker-gained-access","How the attacker gained access",[48,3010,3011],{},"Based on the OAIC’s allegations and Medibank’s public updates, the incident began with stolen credentials, remote access without MFA and an account with extensive privileges. Here’s how the hacker gained access:",[1831,3013,3014,3020,3026],{},[83,3015,3016,3019],{},[65,3017,3018],{},"Credential theft through infostealer malware."," TMedibank credentials saved in a contractor employee’s browser profile were synchronised to his personal computer and were stolen by malware.",[83,3021,3022,3025],{},[65,3023,3024],{},"Remote access without MFA."," The VPN was configured to accept a username and password and did not require MFA.",[83,3027,3028,3031],{},[65,3029,3030],{},"Broad access and delayed escalation."," The compromised admin account could access most Medibank systems. The OAIC alleges that security alerts were generated from 24 August onwards but were not appropriately triaged or escalated, allowing the hacker to locate and exfiltrate about 520GB of data over seven weeks.",[48,3033,3034,3035,3038],{},"The publicly available evidence describes a ",[65,3036,3037],{},"data-theft and extortion"," incident rather than ransomware with encrypted systems. The attacker simply used valid credentials to access systems and steal data, then demanded payment to prevent publication.",[43,3040,3042],{"id":3041},"_5-reasons-the-breach-had-such-a-large-impact","5 reasons the breach had such a large impact",[1831,3044,3045,3051,3057,3063,3069],{},[83,3046,3047,3050],{},[65,3048,3049],{},"No MFA on remote access."," A username and password were enough for the hacker to access Medibank’s systems. MFA would have added an important barrier and may have prevented or limited the initial access.",[83,3052,3053,3056],{},[65,3054,3055],{},"An unmanaged personal device."," Corporate credentials were synchronised to a personal computer outside Medibank’s managed environment, where malware stole them.",[83,3058,3059,3062],{},[65,3060,3061],{},"Poor alert response."," Detection software generated alerts, but the process for reviewing, triaging and escalating them did not work as intended.",[83,3064,3065,3068],{},[65,3066,3067],{},"One account had very broad access."," The service-desk account had access to \"most, if not all, systems\", so one stolen credential became keys to the whole building.",[83,3070,3071,3074],{},[65,3072,3073],{},"Known weaknesses were not fixed in time."," The OAIC alleges Medibank knew about the security gaps, including the MFA gap, through its cyber security audits, and failed to fix them in time.",[43,3076,3078],{"id":3077},"what-it-cost","What it cost",[80,3080,3081,3087,3093,3099,3105,3111,3117],{},[83,3082,3083,3086],{},[65,3084,3085],{},"Direct response and remediation costs reached tens of millions of dollars"," across several financial years, before any final litigation outcomes.",[83,3088,3089,3092],{},[65,3090,3091],{},"Blackmail and ransom demands:"," Medibank refused the US$10M ransom,  and the stolen data was later published.",[83,3094,3095,3098],{},[65,3096,3097],{},"APRA's $250 million capital adequacy adjustment:"," This was not a fine, it required Medibank to hold additional capital until APRA was satisfied with the remediation program.",[83,3100,3101,3104],{},[65,3102,3103],{},"Regulatory and legal scrutiny:"," The ongoing OAIC civil penalty proceedings and a Federal Court class action, still listed as open.",[83,3106,3107,3110],{},[65,3108,3109],{},"Harm to affected people:",": Published information included identity details and sensitive health claims data, creating risks of fraud, scams, blackmail, identity theft and emotional distress for the affected individuals.",[83,3112,3113,3116],{},[65,3114,3115],{},"Wider impact:",": The breach contributed to national debate about privacy, cyber security and ransomware. In 2024, Australia imposed its first cyber sanction in response to the incident.",[83,3118,3119,3122],{},[65,3120,3121],{},"Reputational damage:"," The incident affected customer trust and kept Medibank under public, regulatory and legal scrutiny for years.",[43,3124,3126],{"id":3125},"what-medibank-did-well","What Medibank did well",[48,3128,3129],{},"Although the breach exposed serious weaknesses and early breach figures changed as the incident investigation progressed, several aspects of Medibank’s incident response are worth recognising:",[80,3131,3132,3135,3138,3141,3144,3147],{},[83,3133,3134],{},"Medibank provided frequent public updates as the breach scope became clearer.",[83,3136,3137],{},"It also notified regulators and law-enforcement agencies.",[83,3139,3140],{},"Medibank engaged external cyber incident-response specialists.",[83,3142,3143],{},"It refused to pay ransom, aligning with the Australian Government view.",[83,3145,3146],{},"Medibank also offered support measures, including identity monitoring and hardship support for affected customers",[83,3148,3149],{},"It also committed to remediation and security investment.",[43,3151,3153],{"id":3152},"_10-lessons-for-your-business","10 lessons for your business",[1831,3155,3156,3162,3168,3174,3180,3186,3192,3198,3204,3210],{},[83,3157,3158,3161],{},[65,3159,3160],{},"Mandatory MFA."," If one control defines this breach, it's this. Enforce mandatory MFA for VPNs, emails, cloud systems, admin accounts, contractor accounts and third-party support access.",[83,3163,3164,3167],{},[65,3165,3166],{},"Properly manage contractor access."," Administrator access should be role-based rather than universal across internal systems. Privileged access should only be granted when required, time-limited, approved, monitored and reviewed regularly. Contractors should not have privileged access to all systems and databases.",[83,3169,3170,3173],{},[65,3171,3172],{},"Require managed devices for corporate access."," Personal or unmanaged devices should not access sensitive systems unless strong technical controls are in place. Access should be limited to devices that are managed, compliant, patched and monitored.",[83,3175,3176,3179],{},[65,3177,3178],{},"Apply least privilege."," Give each user only the access needed for their role. Review privileged access regularly and remove it when it is no longer required.",[83,3181,3182,3185],{},[65,3183,3184],{},"Strengthen browser and credential security."," Do not allow corporate credentials to be stored in browsers. Use an approved password manager and configure managed browsers to control password saving and profile synchronisation.",[83,3187,3188,3191],{},[65,3189,3190],{},"Every alert needs an owner."," Decide who acts on warnings from your antivirus, bank and software - and how they should respond to them.",[83,3193,3194,3197],{},[65,3195,3196],{},"Reduce sensitive data exposure."," Keep only the information you need, restrict access, separate high-risk data, encrypt it where appropriate and monitor unusual access or large data transfers.",[83,3199,3200,3203],{},[65,3201,3202],{},"Network segmentation."," Consider separating your network into secure zones to reduce access to sensitive data.",[83,3205,3206,3209],{},[65,3207,3208],{},"Act on cyber security findings."," The OAIC alleges that Medibank's cyber security audits flagged the MFA gap. Treat audit findings, penetration-test results and insurer questionnaires as actions with owners, deadlines and management oversight.",[83,3211,3212,3215],{},[65,3213,3214],{},"Train employees and contractors."," Cover secure credential storage, approved password managers, MFA methods, risk of browser synchronisation, phishing methods, incident reporting and how to correctly respond to credential theft attempts.",[43,3217,3219],{"id":3218},"how-cyber-security-frameworks-apply","How cyber security frameworks apply",[48,3221,3222],{},"While the publicly available information does not provide every technical detail of the Medibank attack, the incident can still be examined using established cyber security frameworks. This can help turn the incident into a structured set of lessons.",[1417,3224,3226],{"id":3225},"mitre-attck-helps-understand-the-attackers-behaviours","MITRE ATT&CK helps understand the attacker's behaviours",[80,3228,3229,3235,3241,3247],{},[83,3230,3231,3234],{},[65,3232,3233],{},"Credentials from Web Browsers (T1555.003):"," The OAIC alleges that Medibank credentials saved in a contractor’s work browser profile were synchronised to a personal computer and later stolen by information-stealing malware.",[83,3236,3237,3240],{},[65,3238,3239],{},"External Remote Services (T1133):"," The attacker allegedly used the stolen credentials to connect to Medibank systems through its GlobalProtect VPN.",[83,3242,3243,3246],{},[65,3244,3245],{},"Valid Accounts (T1078):"," The attacker used an active Medibank administrator account that allowed the login to appear similar to authorised activity.",[83,3248,3249,3252],{},[65,3250,3251],{},"Data from Information Repositories (T1213):"," After entering the environment, the attacker allegedly accessed internal systems and databases containing customer identity and health claims information.",[1417,3254,3256],{"id":3255},"nist-cybersecurity-framework-20-helps-organise-management-responsibilities","NIST Cybersecurity Framework 2.0 helps organise management responsibilities",[80,3258,3259,3265,3271,3277,3283,3289],{},[83,3260,3261,3264],{},[65,3262,3263],{},"Govern:"," Assign responsibility for cyber security, privacy and third-party access. Set clear security requirements for contractors and ensure that known audit findings are recorded, prioritised and fixed.",[83,3266,3267,3270],{},[65,3268,3269],{},"Identify:"," Know which accounts have broad access, which devices can connect remotely, where sensitive customer information is stored and which systems would create the greatest harm if compromised.",[83,3272,3273,3276],{},[65,3274,3275],{},"Protect:"," Require strong MFA for remote and privileged access. Use managed devices, approved password manager software, least privilege, network segmentation and controls that limit access to sensitive databases.",[83,3278,3279,3282],{},[65,3280,3281],{},"Detect:"," Monitor VPN access, privileged-account activity, unusual devices, large searches or exports and suspicious connections between internal systems. Ensure every important alert has an owner and a defined escalation process.",[83,3284,3285,3288],{},[65,3286,3287],{},"Respond:"," Maintain and test an incident-response plan. It should cover disabling compromised accounts, revoking active sessions, isolating affected systems, investigating alerts, notifying regulators and communicating with affected customers.",[83,3290,3291,3294],{},[65,3292,3293],{},"Recover:"," Restore affected services safely, support affected people, review what went wrong and improve access controls, monitoring, contractor arrangements and incident-response procedures.",[1417,3296,3298],{"id":3297},"acscs-essential-eight","ACSC’s Essential Eight",[48,3300,3301],{},"Although the Essential Eight does not cover every issue seen in this breach, it provides a useful Australian technical baseline. The most relevant to Medibank’s breach strategy include:",[80,3303,3304,3310],{},[83,3305,3306,3309],{},[65,3307,3308],{},"Multi-factor authentication:"," Require MFA for VPN access, privileged accounts, contractors and systems holding sensitive information.",[83,3311,3312,3315],{},[65,3313,3314],{},"Restrict administrative privileges:"," Give employees and contractors only the access needed for their work. Use separate privileged accounts, review access regularly and remove it when it is no longer required.",[43,3317,3319],{"id":3318},"final-takeaway","Final takeaway",[48,3321,3322],{},"The Medibank breach is sometimes framed as the work of a sophisticated Russian hacker. The practical lesson is simpler: browser-synchronised credentials were stolen from a personal device, remote access did not require MFA for the login method used, an admin account had extensive access, and security alerts were not promptly handled.",[48,3324,3325],{},"Small businesses may have fewer IT and security resources, but the same risks still matter. Know who can access your systems, require MFA, use managed devices, limit each account to the minimum access required, control browser synchronisation and make sure every important security alert has an owner.",[48,3327,2078,3328,3330],{},[57,3329,2081],{"href":1692}," to review your current controls and identify practical steps to protect your business.",[43,3332,2152],{"id":2151},[80,3334,3335,3338,3341,3344,3347,3350,3353,3356,3359,3362,3365,3368,3371,3374],{},[83,3336,3337],{},"Office of the Australian Information Commissioner, Civil penalty action against Medibank and the filed concise statement (June 2024).",[83,3339,3340],{},"Australian Prudential Regulation Authority, APRA takes action against Medibank Private in relation to cyber incident” (27 June 2023).",[83,3342,3343],{},"Australian Government - Department of Foreign Affairs and Trade, Cyber sanctions in response to Medibank Private cyber attack (23 January 2024).",[83,3345,3346],{},"Australian Government - Department of Foreign Affairs and Trade, Significant cyber incidents sanctions framework.",[83,3348,3349],{},"Australian Government - Department of Foreign Affairs and Trade — Guidance Note: Cyber sanctions.",[83,3351,3352],{},"Federal Court of Australia, Current class actions - McClure v Medibank Private Limited, VID64\u002F2023.",[83,3354,3355],{},"Medibank, Cybercrime updates published from 13 October to 1 December 2022.",[83,3357,3358],{},"MITRE ATT&CK Enterprise framework, Credentials from Web Browsers, T1555.003.",[83,3360,3361],{},"MITRE ATT&CK Enterprise framework, External Remote Services, T1133.",[83,3363,3364],{},"MITRE ATT&CK Enterprise framework, Valid Accounts, T1078.",[83,3366,3367],{},"MITRE ATT&CK Enterprise framework, Data from Information Repositories, T1213.",[83,3369,3370],{},"National Institute of Standards and Technology, NIST Cybersecurity Framework 2.0.",[83,3372,3373],{},"ASD’s Australian Cyber Security Centre, Essential Eight explained.",[83,3375,3376],{},"ASD’s Australian Cyber Security Centre, Essential Eight maturity model.",{"title":11,"searchDepth":12,"depth":12,"links":3378},[3379,3380,3381,3382,3383,3384,3385,3386,3391,3392],{"id":2819,"depth":12,"text":2820},{"id":2835,"depth":12,"text":2836},{"id":3007,"depth":12,"text":3008},{"id":3041,"depth":12,"text":3042},{"id":3077,"depth":12,"text":3078},{"id":3125,"depth":12,"text":3126},{"id":3152,"depth":12,"text":3153},{"id":3218,"depth":12,"text":3219,"children":3387},[3388,3389,3390],{"id":3225,"depth":409,"text":3226},{"id":3255,"depth":409,"text":3256},{"id":3297,"depth":409,"text":3298},{"id":3318,"depth":12,"text":3319},{"id":2151,"depth":12,"text":2152},"\u002Fcovers\u002Fcyber-security\u002Fbreach-lessons\u002Fmedibank.jpg","How stolen browser-saved credentials, remote access without MFA and missed security alerts contributed to the 2022 Medibank data breach - and what Australian small businesses can learn from it.",[],{},{"description":3398,"title":2796},"How the 2022 Medibank data breach happened & what Australian small businesses can learn about contractor access, browser-saved credentials, MFA and security alerts.","\u002Fcyber-security\u002Fbreach-lessons\u002Fmedibank-breach",11,"Reviewed against public information from the OAIC, APRA, ASD’s Australian Cyber Security Centre, DFAT, Medibank, MITRE ATT&CK and NIST SCF 2.0",{"title":2796,"description":3394},{"loc":3399},"cyber-security\u002Fbreach-lessons\u002Fmedibank-breach","The 2022 Medibank data breach made headlines, but the weaknesses that contributed to it are not unique to large companies. Here are the practical lessons small businesses can take from the incident.",[1702,3407],"Breach Lessons","DrwgvJLPjR03gDBSyfBEqBqmq6B3GAzL3RFiqFrTSww",{"id":3410,"extension":1665,"items":3411,"meta":3445,"stem":3446,"__hash__":3447},"companies\u002Fcompanies.yml",[3412,3416,3420,3423,3426,3430,3434,3438,3441],{"alt":3413,"width":3414,"src":3415},"SchoolHolidays.com.au logo",218,"companies\u002Fcompany-schoolholidays-logo.png",{"alt":3417,"width":3418,"src":3419},"Nathan Nankervis logo",160,"companies\u002Fnathan-nankervis-name-logo.png",{"alt":3421,"width":3422,"src":245},"Color Magic logo",210,{"alt":3424,"width":3425,"src":830},"Song Quiz logo",165,{"alt":3427,"width":3428,"src":3429},"Memwah logo",198,"companies\u002Fcompany-memwah-logo.png",{"alt":3431,"width":3432,"src":3433},"Terran Industries logo",118,"companies\u002Fcompany-terran-industries-logo.png",{"alt":3435,"width":3436,"src":3437},"My Sneaky Escapes logo",192,"companies\u002Fcompany-my-sneaky-escapes-logo.png",{"alt":3439,"width":3436,"src":3440},"UBookDirect logo","companies\u002Fcompany-ubookdirect-logo.png",{"alt":3442,"width":3443,"src":3444},"Sparrk Logistics logo",168,"companies\u002Fcompany-sparrk-logistics-logo.png",{},"companies","mifBF_tMCpX_Kj-ieruAyZaaDpbZpKYZrDC83Dlqo5g",{"id":3449,"extension":1665,"items":3450,"meta":3466,"stem":3467,"__hash__":3468},"testimonials\u002Ftestimonials.yml",[3451,3455,3459,3462],{"quote":3452,"name":3453,"company":3454},"\"We've been working with the IT Club team for three years building two travel platforms together. Rus and Elena have been knowledgeable, reliable and delivered high-quality work on time.\"","David","Ubookdirect | Diamond Club | My Sneaky Escapes",{"quote":3456,"name":3457,"company":3458},"\"Rus is a leader in the digital space - his understanding of current and upcoming technologies makes his experience invaluable. Personable, reliable, and easy to work with - you can't go wrong.\"","Cliff","cliff.design",{"quote":3460,"name":3461,"company":1054},"\"I could not be happier with the website Elena designed for me - it was beyond my expectations. She is full of knowledge and advice, and will always deliver the best outcome. I will definitely be working with her on my next project.\"","Evannah",{"quote":3463,"name":3464,"company":3465},"\"The guidance provided by Elena from the initial design discussion through to development and the launch of the website was excellent.\"","Ana","Hedgehog Group | Sparrk Logistics",{},"testimonials","616OFiuMje8koyvJ6R6TU1mhVH6K_Rt1O2M8icJ5zAY",{"id":3470,"extension":1665,"items":3471,"meta":3505,"stem":3506,"__hash__":3507},"services\u002Fservices.yml",[3472,3479,3488,3498],{"type":3473,"title":3474,"summary":3475,"tags":3476},"Code","Web development & UI\u002FUX","Custom web applications built by senior Vue.js, React and Laravel developers. From MVP to scale - clean architecture, honest advice on tech stack and a team that delivers.",[3477,3478,927,655],"Vue.js \u002F Nuxt.js","React.js \u002F Next.js",{"type":3480,"title":3481,"summary":3482,"tags":3483},"Solutions","E-commerce Solutions","Custom marketplaces and booking systems, travel and loyalty platforms - e-commerce experiences used by hundreds of thousands of Australians every month.",[3484,3485,3486,3487],"Shopify","Custom Marketplaces","Loyalty Solutions","Booking Systems",{"type":3489,"title":3490,"summary":3491,"tags":3492},"Design","Integrations & Platforms","Payments, booking engines, video streaming, headless CMS - the complex connections that make your platform work. Our niche skills in fin-tech, travel, e-commerce, real estate, and online payments, together with cyber security knowledge, help us all the way.",[3493,3494,3495,3496,3497],"Payment Gateways","Contentful & Headless CMS","Booking Engines","Video Streaming","Email Integrations",{"type":3499,"title":1702,"summary":3500,"tags":3501},"Mobile","Plain-English security guidance for Australian small businesses - what the Privacy Act changes mean for you, how breaches actually happen and how to check your own defences.",[3502,3503,3504],"Cyber security guides","Lean from past data breaches","Cyber security mistakes to avoid",{},"services","1koFAM6PVOU5OvVZ1lMvbxyzxAfEIcpdZcEyjXnqDy8",{"id":3509,"extension":1665,"items":3510,"meta":3520,"stem":3521,"__hash__":3522},"socials\u002Fsocials.yml",[3511,3514,3517],{"type":3512,"link":3513},"facebook","https:\u002F\u002Fwww.facebook.com\u002Fitclub.com.au",{"type":3515,"link":3516},"linkedin","https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fitclub\u002Fabout\u002F",{"type":3518,"link":3519},"behance","https:\u002F\u002Fwww.behance.net\u002Felenaitclub\u002F",{},"socials","R3zh7G2Yeky6IFraIEG2izmfHXa3EG7r0rHl4YbjpWk",1785204197820]