Report: Identity-Driven Attacks Dominate Australia and New Zealand Cyber Threat Landscape

Summary
CYFIRMA’s ANZ assessment finds credential- and access-driven compromise dominates across sectors, with Qilin the broadest ransomware actor. It also highlights state-linked pre-positioning, supply-chain exposure and exploitation of three vulnerabilities.
Key points
- The report tracks 28 named incidents: 6 in mining, 13 in manufacturing, 9 in financial services and none confirmed at ANZ deposit-taking banks.
- Credential stuffing, stolen credentials and initial-access-broker sales are identified as the dominant access risks across sectors.
- Qilin has the broadest cross-sector ransomware footprint, with 34 ANZ leak-site listings; the report cautions that listings are not confirmed breaches.
- The report describes Volt Typhoon and Salt Typhoon activity as sustained state-aligned pre-positioning, citing advisories that name Australia and New Zealand.
- Reported exploitation includes CVE-2023-20198 affecting Cisco IOS XE, CVE-2025-59287 affecting Microsoft WSUS, and CVE-2026-41940 affecting cPanel & WHM.
- Mining and manufacturing face supply-chain exposure through contractors, equipment providers and technology suppliers; the report says smaller suppliers can provide routes to larger targets.
- Recommendations include phishing-resistant MFA, stronger third-party risk assessment, prompt patching of internet-facing critical vulnerabilities, and IT/OT segmentation.
Article Details
- Publisher
- CYFIRMA
- Report Period
- Primarily 2025–July 2026; individual datasets cover different periods.
- Scope
- Cyber threats affecting Australia and New Zealand, with sector analysis of mining, manufacturing, financial services, and banking.
- Sample Size
- 28 named incidents, 248 tracked ransomware leak-site listings, and 568 tracked dark-web mentions; these are distinct datasets, not confirmed-breach counts.
- Key Statistics
- Qilin had 34 ANZ leak-site listings, the most of any ransomware actor in the report; listings are claims, not confirmed breaches.
- No named ANZ deposit-taking bank victim was confirmed in the tracked record.
- Financial services accounted for 82 dark-web mentions from February through July 2026, the most of the four core sectors.
- ASD reported approximately 400 Australian devices compromised in the BADCANDY web-shell campaign since July 2025, including 150 in October 2025.
- ASD/ACSC responded to more than 1,200 incidents in FY 2024–25, an 11% year-over-year increase.
- Recommendations
- Mandate phishing-resistant MFA for customer- and member-facing portals and deploy credential-stuffing detection.
- Extend third-party risk assessments to equipment, engineering, logistics, and technology suppliers.
- Verify leak-site claims through investigation before treating them as confirmed breaches.
- Adopt AS IEC 62443 OT security controls and maintain a current OT asset inventory.
- Patch internet-facing critical vulnerabilities within 48 hours of applicable advice.
MITRE ATT&CK
T1078 · Valid AccountsStolen or compromised credentials were used to obtain access across sectors.T1110 · Brute ForceCredential stuffing was reported against financial-services accounts.T1133 · External Remote ServicesThe report describes access through exploited remote-access infrastructure.T1190 · Exploit Public-Facing ApplicationThe report identifies exploitation of public-facing systems, including vulnerabilities in Microsoft WSUS and cPanel & WHM.T1195 · Supply Chain CompromiseThe report describes compromise through contractors and technology suppliers in mining and manufacturing.T1486 · Data Encrypted for ImpactRansomware activity included encryption for impact.
CVE
CVE-2023-20198pre-positioning by Volt Typhoon and Salt Typhoon, plus exploited vulnerabilities such as CVE-2023-20198, CVE-2025-59287, and CVE-2026-41940.CVE-2025-59287by Volt Typhoon and Salt Typhoon, plus exploited vulnerabilities such as CVE-2023-20198, CVE-2025-59287, and CVE-2026-41940.CVE-2026-41940Typhoon and Salt Typhoon, plus exploited vulnerabilities such as CVE-2023-20198, CVE-2025-59287, and CVE-2026-41940.
Threat Actors
AkiraRansomware actor with named ANZ manufacturing claims and a financial-services claim.AnubisHad a single named ANZ manufacturing claim in the report.ClopHad a single named ANZ manufacturing claim in the report.DeadlockAttributed a 2026 mining-related claim; the report treats it as lower confidence because the actor was not seen elsewhere in vendor reporting.DragonForceHad named ANZ manufacturing and financial-services claims.fulcrumsecAttributed a 2026 mining-related claim; the report treats it as lower confidence because the actor was not seen elsewhere in vendor reporting.GhostEmperorNamed by the report as an alias of Salt Typhoon.INC RansomClaimed named ANZ victims in sectors discussed by the report.LynxClaimed a named ANZ mining or mineral-exploration victim.Operator PandaNamed by the report as an alias of Salt Typhoon.QilinRansomware actor with the most ANZ leak-site listings in the report and claims across mining, manufacturing, and financial services.RansomHubClaimed a named ANZ mining or mineral-exploration victim.RedMikeNamed by the report as an alias of Salt Typhoon.Salt TyphoonDescribed as PRC-linked and associated with long-duration backbone and edge-router compromise; the report names GhostEmperor, Operator Panda, and RedMike as aliases.SarcomaHad a single named ANZ manufacturing claim in the report.Space BearsHad a named ANZ financial-services claim.The GentlemenRansomware group with a named ANZ manufacturing claim; the report dates its first ANZ listing to March 2026.Volt TyphoonDescribed as PRC state-sponsored and pre-positioning in environments supporting critical infrastructure.
Malware
Vendors
Cisco[Affected products / platforms] Products associated with active exploitation – Cisco IOS XE, Microsoft WSUS, cPanel & WHM.cPanel[T1190 ] Exploit Public-Facing Application – Applied to internet-facing systems such as WSUS and cPanel & WHM, described as ‘unauthenticated RCE’ and ‘active exploitation in Australia’.Microsoft[Affected products / platforms] Products associated with active exploitation – Cisco IOS XE, Microsoft WSUS, cPanel & WHM.
Products
Cisco IOS XE[Affected products / platforms] Products associated with active exploitation – Cisco IOS XE, Microsoft WSUS, cPanel & WHM.cPanel & WHM[T1190 ] Exploit Public-Facing Application – Applied to internet-facing systems such as WSUS and cPanel & WHM, described as ‘unauthenticated RCE’ and ‘active exploitation in Australia’.Microsoft WSUS[Affected products / platforms] Products associated with active exploitation – Cisco IOS XE, Microsoft WSUS, cPanel & WHM.