Report: Identity-Driven Attacks Dominate Australia and New Zealand Cyber Threat Landscape

· Original article ↗

Summary

CYFIRMA’s ANZ assessment finds credential- and access-driven compromise dominates across sectors, with Qilin the broadest ransomware actor. It also highlights state-linked pre-positioning, supply-chain exposure and exploitation of three vulnerabilities.

Key points

  • The report tracks 28 named incidents: 6 in mining, 13 in manufacturing, 9 in financial services and none confirmed at ANZ deposit-taking banks.
  • Credential stuffing, stolen credentials and initial-access-broker sales are identified as the dominant access risks across sectors.
  • Qilin has the broadest cross-sector ransomware footprint, with 34 ANZ leak-site listings; the report cautions that listings are not confirmed breaches.
  • The report describes Volt Typhoon and Salt Typhoon activity as sustained state-aligned pre-positioning, citing advisories that name Australia and New Zealand.
  • Reported exploitation includes CVE-2023-20198 affecting Cisco IOS XE, CVE-2025-59287 affecting Microsoft WSUS, and CVE-2026-41940 affecting cPanel & WHM.
  • Mining and manufacturing face supply-chain exposure through contractors, equipment providers and technology suppliers; the report says smaller suppliers can provide routes to larger targets.
  • Recommendations include phishing-resistant MFA, stronger third-party risk assessment, prompt patching of internet-facing critical vulnerabilities, and IT/OT segmentation.

Article Details

Publisher
CYFIRMA
Report Period
Primarily 2025–July 2026; individual datasets cover different periods.
Scope
Cyber threats affecting Australia and New Zealand, with sector analysis of mining, manufacturing, financial services, and banking.
Sample Size
28 named incidents, 248 tracked ransomware leak-site listings, and 568 tracked dark-web mentions; these are distinct datasets, not confirmed-breach counts.
Key Statistics
  • Qilin had 34 ANZ leak-site listings, the most of any ransomware actor in the report; listings are claims, not confirmed breaches.
  • No named ANZ deposit-taking bank victim was confirmed in the tracked record.
  • Financial services accounted for 82 dark-web mentions from February through July 2026, the most of the four core sectors.
  • ASD reported approximately 400 Australian devices compromised in the BADCANDY web-shell campaign since July 2025, including 150 in October 2025.
  • ASD/ACSC responded to more than 1,200 incidents in FY 2024–25, an 11% year-over-year increase.
Recommendations
  • Mandate phishing-resistant MFA for customer- and member-facing portals and deploy credential-stuffing detection.
  • Extend third-party risk assessments to equipment, engineering, logistics, and technology suppliers.
  • Verify leak-site claims through investigation before treating them as confirmed breaches.
  • Adopt AS IEC 62443 OT security controls and maintain a current OT asset inventory.
  • Patch internet-facing critical vulnerabilities within 48 hours of applicable advice.

MITRE ATT&CK

CVE

Threat Actors

AkiraRansomware actor with named ANZ manufacturing claims and a financial-services claim.AnubisHad a single named ANZ manufacturing claim in the report.ClopHad a single named ANZ manufacturing claim in the report.DeadlockAttributed a 2026 mining-related claim; the report treats it as lower confidence because the actor was not seen elsewhere in vendor reporting.DragonForceHad named ANZ manufacturing and financial-services claims.fulcrumsecAttributed a 2026 mining-related claim; the report treats it as lower confidence because the actor was not seen elsewhere in vendor reporting.GhostEmperorNamed by the report as an alias of Salt Typhoon.INC RansomClaimed named ANZ victims in sectors discussed by the report.LynxClaimed a named ANZ mining or mineral-exploration victim.Operator PandaNamed by the report as an alias of Salt Typhoon.QilinRansomware actor with the most ANZ leak-site listings in the report and claims across mining, manufacturing, and financial services.RansomHubClaimed a named ANZ mining or mineral-exploration victim.RedMikeNamed by the report as an alias of Salt Typhoon.Salt TyphoonDescribed as PRC-linked and associated with long-duration backbone and edge-router compromise; the report names GhostEmperor, Operator Panda, and RedMike as aliases.SarcomaHad a single named ANZ manufacturing claim in the report.Space BearsHad a named ANZ financial-services claim.The GentlemenRansomware group with a named ANZ manufacturing claim; the report dates its first ANZ listing to March 2026.Volt TyphoonDescribed as PRC state-sponsored and pre-positioning in environments supporting critical infrastructure.

Malware

Vendors

Products

Countries

Industries

Related Articles