Cyber Threat Landscape – Australia and New Zealand

Published On : 2026-09-25
Share :
Cyber Threat Landscape – Australia and New Zealand

EXECUTIVE SUMMARY

A regional pattern with sector-specific expression

  • Identity and access, not novel exploitation, is the dominant ANZ attack surface across the sectors covered here credential stuffing is the clearest confirmed example (Financial Services, April 2025), and the broader pattern of access-driven rather than exploitation-driven compromise recurs throughout this report.
  • Banking is the most striking finding by absence: zero named ANZ deposit-taking bank victims across a large, long-running body of tracked records. Regulators are not treating that absence as reassurance a formal cyber-triggered bank-run stress test ran in the same period.
  • Mining sits uniquely at the intersection of financially motivated ransomware and state-aligned strategic interest, given Australia’s position in the global critical-minerals supply chain.
  • Ransomware operators are consistently reaching mid-market and adjacent targets equipment suppliers, financial aggregators, exploration firms while hardened, high-value cores remain comparatively untouched.

At a Glance

  • MOST ACTIVE ACTOR – Qilin 34 ANZ listings broadest reach: active in 3 of 4 core sectors
  • TOP ENTRY VECTOR – Credential-based access Stuffing, infostealers, IAB sales not novel exploitation dominant across every sector
  • MOST EXPLOITED VULN. CLASS – CWE-502 Deserialization of untrusted data 14 of 245 CISA KEV additions in 2025
  • HIGHEST DARK-WEB CHATTER – Financial Services 82 dark-web mentions, Feb–Jul 2026 highest of the four core sectors
  • NEWEST ACTIVE THREAT – TheGentlemen First ANZ listing March 2026 newest group with confirmed activity
  • NAMED INCIDENTS TRACKED – 28 named incidents across Mining (6), Banking (0 confirmed),
    Manufacturing (13), Financial Services (9)

Key takeaway:

Every sector in this report shares one root cause: identity and access, not sophisticated exploitation. Where that gap is closed as APRA is now forcing in superannuation incident volume should fall; where it isn’t, expect the pattern to keep repeating.

Regional Threat Landscape – Australia & New Zealand national indicators

  • 1,200+ ASD/ACSC incidents responded to, FY24-25 (+11% YoY)
  • 84,700+ Cybercrime reports received by ACSC, FY24-25
  • 13% of incidents affected critical infrastructure (up 2 pts YoY)
  • NZ$12.4M NCSC NZ direct financial loss, Q3 2025 (+118% QoQ)
  • 6,000 Incident reports handled by NCSC NZ annually
  • 300+ Escalated for specialist national-significance handling

State-sponsored pre-positioning: a standing condition

Volt Typhoon
PRC state-sponsored; pre-positions in IT environments underpinning communications, energy, transport, water. AU/NZ joint warning issued March 2025 calling it a “critical business risk” to CI operators.

Salt Typhoon
PRC-linked (aka GhostEmperor / Operator Panda / RedMike). Joint Five Eyes advisory, August 2025, confirmed backbone/edge router compromise since 2021+ across telecom, government, transport, lodging, military sectors — Australia and New Zealand explicitly named.

Both advisories explicitly name Australia and New Zealand as affected countries — a pattern of sustained, long-duration access operations, not opportunistic single incidents.

THREAT ACTOR LANDSCAPE

Most active ransomware groups against ANZ

Qilin’s footprint
The broadest cross-sector reach of any actor in this report Mining, Financial Services, and Manufacturing all carry named Qilin claims. Banking is the exception: no actor, Qilin included, has a confirmed incident there, which is itself the sector’s headline finding (Section 6). This makes Qilin the single most relevant actor for cross-sector threat modelling among the three sectors it does touch.

Reading this chart correctly
These are counts of leak-site listings, not confirmed breaches the underlying collection methodology has not been independently audited. Treat as relative activity, not absolute impact.

First confirmed ANZ activity, by actor

RANSOMWARE TRENDS

ANZ ransomware leak-site activity 248 tracked listings

Trend read: Activity is volatile month to month with no clean seasonal pattern, but the two highest single months on record (May 2026: 25; April 2026: 21) both fall in the most recent quarter consistent with a broader increase in ransomware’s share of Australian data breaches noted in public research, though the exact figures behind that claim originate from a single external vendor and are not reproduced here.

Major named incidents, in chronological order

DARK WEB EXPOSURE

Chatter volume by industry 568 tracked mentions, Feb–Jul 2026

Chatter by category, and the initial-access-broker economy

Observed Underground Marketplace Activity

Australia & New Zealand Underground Marketplace Observations

Analyst Observation

During the assessment period, the threat intelligence team observed multiple underground marketplace advertisements offering Australia-related datasets. The observed advertisements included telephone-record datasets, accounting and business-related databases, credential collections, and other Australia-related data offerings.

These observations indicate continued criminal interest in monetising Australia-related information within underground cybercrime communities. The advertisements are presented as observed underground marketplace activity and should not be interpreted as independently verified organisational breaches.

VULNERABILITY EXPOSURE

CISA KEV catalog trends global context for ANZ Prioritisation

KEV & PATCH MANAGEMENT

  • 24 of the 245 vulnerabilities added in 2025 are known to be exploited by ransomware groups
  • ~20.5% of the full 1,484-entry catalog has been exploited by ransomware groups at some point
  • Microsoft leads all vendors with 100 ransomware-linked KEV entries historically
  • CWE-502 (Deserialization of Untrusted Data) is the most common 2025 addition category 14 of the year’s 245 new entries, 58 historically
  • ASD/Essential Eight: patch internet-facing critical vulnerabilities within 48 hours, all others within 2 weeks ASD reporting consistently finds roughly 1 in 5 critical vulnerabilities are exploited within 48 hours of patch or mitigation advice becoming available

ANZ-specific exploited vulnerabilities on record

CVE Product ANZ-Specific Finding Status
CVE-2023-20198 Cisco IOS XE BADCANDY web-shell campaign ~400 Australian devices compromised since Jul 2025, 150 in October 2025 alone (ASD advisory) Government Advisory
CVE-2025-59287 Microsoft WSUS Unauthenticated RCE with system-level privileges; ACSC high-priority alert, Oct 2025 Government Advisory
CVE-2026-41940 cPanel & WHM ACSC confirms active exploitation in Australia; critical alert issued 1 May 2026 Government Advisory

 

Scope note:

These three are the ANZ-specific exploited-vulnerability findings independently verified via ASD/ACSC advisories for this edition. They are not sector-specific to Mining, Financial Services, Manufacturing, or Banking individually they represent broad exploitation against Australian internet-facing infrastructure generally. A dedicated sector-level KEV dataset, if supplied, would allow this section to be extended with per-industry exploitation statistics. Separately, internal threat monitoring identified malware indicators associated with financially motivated activity (Carbanak); these indicators are generic threat-monitoring data, not ANZ-specific, and are not reproduced in raw form here.

REGIONAL THREAT LANDSCAPE

Analyst synthesis

  • Multiple incidents in this report were independently corroborated across separate public sources, increasing confidence in the overall assessment beyond what any single-source finding could support.
  • Banking’s zero-confirmed-victim finding is not a narrow result it holds across a large, multi-year body of ransomware records, which is why it is treated as a genuine finding rather than a gap in visibility alone.
  • The same underlying pattern recurs in every sector covered: ransomware operators consistently reach mid-market and adjacent targets while hardened, high-value cores stay comparatively untouched. That is attacker economics, not sector-specific weakness softer targets are chosen because they are softer.

Mining: Threat Landscape

  • Australia holds globally significant rare-earth and critical-mineral reserves, placing the sector inside a live geopolitical contest China controls over 90% of global REE processing capacity.
  • Australia has moved to restrict Chinese investment in its own rare-earths sector, forcing divestment from Northern Minerals (2023-24) and committing to a national Critical Minerals Strategic Reserve.
  • The sector’s defining vulnerability is structural, not technical: public research has found a substantial share of Australian Mining Equipment, Technology and Services (METS) businesses report experiencing a cyberattack, with smaller contractors not the miners themselves the primary point of failure. The exact figure originates from a single external vendor’s dataset and is not reproduced here.

Mining: Threat Actors & Techniques

THREAT ACTORS

  • RansomHub, INC Ransom, Lynx, and Qilin have all claimed named, in-scope ANZ mining or mineral-exploration victims.
  • Two 2026 claims (a gold exploration firm and an overseas-operating gold miner) are attributed to actors “fulcrumsec” and “Deadlock” not seen elsewhere in vendor reporting; treat as lower confidence.
  • Public research assesses that criminal ransomware activity against mining may increasingly serve as cover for state-aligned operations explicitly linking the 2024 Northern Minerals leak to the timing of a forced divestment order.

ATTACK TECHNIQUES

  • Ransomware / double extortion via compromised credentials or exploited perimeter systems
  • Supply-chain compromise through equipment and services contractors the primary observed pattern
  • IT/OT convergence risk as mining digitises (autonomous haulage, remote operations) no confirmed OT-specific compromise yet, but a rising forward risk

Mining: Publicly Reported Incidents

“Corroborated” indicates independent agreement across multiple sources. “Leak-site claim” indicates a ransomware group’s own, unconfirmed statement.

Mining: Underground Intelligence & Assessment

UNDERGROUND INTELLIGENCE

  • Mining is not a top-3 sector by IAB listing volume it is reached indirectly, via contractor compromise, more than through open-market access sales.
  • Materials-category dark-web chatter: 40 mentions Feb–Jul 2026, volatile month to month.
  • An April chatter spike ties to a cluster of hacktivism/DDoS mentions, not ransomware.

ANALYST ASSESSMENT

  • The incident record understates the sector’s exposure relative to its geopolitical significance.
  • Australia’s use of foreign-investment-screening powers against Chinese mining investors creates a plausible retaliation motive that a purely incident-count view would miss.

Mining: Key Takeaways & Recommendations

  • Extend third-party risk assessment explicitly to equipment, engineering, and logistics contractors.
  • Treat ransomware intrusions following a sensitive corporate event (divestment order, funding announcement) with elevated scrutiny for state-linked motive
  • Segment IT and OT environments now, ahead of further autonomous/remote-operations adoption

Manufacturing

Manufacturing: Threat Landscape

Manufacturing: Threat Actors & Techniques

THREAT ACTORS

  • Qilin is the most prevalent actor against ANZ manufacturing six named claims spanning Windsor Door, Malibu Boats, Tommotek, Fortress Systems, and two unnamed firms (steel, 11GB; process engineering, 26GB).
  • Akira concentrates specifically on manufacturing per industry reporting’s H1 2025 ANZ data named claims include Consonic, Watkins Steel, and an unnamed process engineering firm.
  • Anubis, Clop, Sarcoma, DragonForce, INC Ransom, and TheGentlemen each have single named ANZ manufacturing claims.

ATTACK TECHNIQUES

  • Ransomware-as-a-service deployment via phishing or exploited remote-access infrastructure
  • Exploitation of internet-facing OT/engineering systems a rising general risk class
  • Supply-chain compromise via IT/technology providers public research identifies this as the dominant route into downstream manufacturing customers in the region, ahead of direct targeting of manufacturers’ own perimeters

Manufacturing: Publicly Reported Incidents

“Corroborated” indicates independent agreement across multiple sources. “Leak-site claim” indicates a ransomware group’s own, unconfirmed statement.

Manufacturing: Underground Intelligence & Assessment

UNDERGROUND INTELLIGENCE

  • Manufacturing dark-web chatter shows a clear, consistent upward trend: 0 mentions in February 2026 rising to 8 by July.
  • This is the steepest sustained trajectory of any sector tracked in this report.
  • It is directionally consistent with the real cluster of named victims in the same window.

ANALYST ASSESSMENT

  • Conventional ransomware-as-a-service targeting of mid-market industrial firms is the clearly evidenced pattern in this report.
  • That sits alongside a slower-moving but structurally significant government recognition that OT-reliant manufacturing carries the same resilience concern as energy and water utilities.

Manufacturing: Key Takeaways & Recommendations

  • Adopt AS IEC 62443 control requirements ahead of any regulatory mandate
  • Build and maintain a current OT asset inventory ASD’s foundational first step
  • Extend vendor risk management specifically to IT/technology/telecom suppliers

INDUSTRY DEEP DIVE 4 OF 4

Financial Services: Threat Landscape

Financial Services: Threat Actors & Techniques

THREAT ACTORS

  • The April 2025 superannuation credential-stuffing wave was not linked to a named group the technique requires only existing breach data, not sophisticated tooling.
  • Qilin has the most named ransomware claims against ANZ financial services firms, followed by single claims from DragonForce, Akira, INC Ransom, and Space Bears.
  • Public research identifies BFSI as the second-most-targeted sector for compromised-access sales in the tracked initial-access-broker economy, behind only retail.

ATTACK TECHNIQUES

  • Credential stuffing the defining technique behind the period’s most significant incident
  • Ransomware / double extortion against mid-tier financial services firms and aggregators
  • Initial access sales feeding into follow-on ransomware or fraud

Financial Services: Publicly Reported Incidents

“Corroborated” indicates independent agreement across multiple sources. “Leak-site claim” indicates a ransomware group’s own, unconfirmed statement.

Financial Services: Underground Intelligence & Assessment

UNDERGROUND INTELLIGENCE

  • Finance shows the highest and most consistently elevated dark-web chatter volume of any sector tracked in this report: 82 mentions Feb–Jul 2026.
  • Credit Cards and Data Breach sub-categories led every month.
  • This is directionally consistent with the sector’s position as the steadiest source of underground interest, independent of the named-incident count.

ANALYST ASSESSMENT

  • The April 2025 incident is this report’s clearest illustration of a structural, sector-wide vulnerability exposed simultaneously across multiple organisations by one technique.
  • It hit five funds with wildly different outcomes A$500K stolen vs. zero loss pointing to authentication maturity, not attacker sophistication, as the differentiator.

Financial Services: Key Takeaways & Recommendations

  • Mandate and enforce MFA across all member/customer-facing portals
  • Deploy credential-stuffing detection as a baseline control, not an advanced one
  • Extend APRA’s post-incident authentication scrutiny beyond the largest funds to mid-tier wealth management and aggregation firms

Cross-Industry Findings

Threat Actor Matrix

Sector comparison & risk rating

Ratings reflect observed evidence (incident count, chatter volume, corroboration strength) as the primary criterion, adjusted for structural/geopolitical factors where the analysis supports it not a simple incident tally.

Strategic observations

  • Attackers are following the path of least resistance to comparable payouts, not the path of maximum prestige security investment that is uneven across an ecosystem gets found and exploited at its weakest edge first.
  • Regulatory response is now anticipating scenarios, not just reacting to incidents RBNZ’s cyber-triggered bank-run stress test and APRA’s rapid post-incident authentication directive both model forward rather than wait for a confirmed catastrophic event.
  • The distinction between a claim and a confirmed breach matters practically. Mining’s disputed gold-production case (see Mining: Publicly Reported Incidents) generated real reputational response before the victim’s own investigation found no data had actually been exfiltrated.

STRATEGIC OUTLOOK

Predictions, 2026–2027

  • The accelerating growth of the KEV catalog in 2025 indicates threat actors are prioritising rapid weaponisation of newly disclosed vulnerabilities over custom exploit development. Organisations unable to patch internet-facing systems within 48 hours of a critical advisory will remain the primary entry point for opportunistic ransomware affiliates through 2026–27.
  • Ransomware-as-a-Service affiliates are expected to continue operating across multiple sectors simultaneously rather than specialising by industry, using shared access-broker supply chains to pivot between mining, financial services, and manufacturing targets. Qilin’s confirmed multi-sector footprint points to affiliate infrastructure, not sector expertise, as the primary driver of targeting breadth.
  • Mid-tier financial services and wealth-management firms are expected to face sustained credential-based targeting as regulatory authentication mandates concentrate on the largest superannuation funds. Threat actors will likely continue shifting toward less-scrutinised entities offering comparable payout potential with materially weaker control maturity.
  • Financial regulators are expected to continue treating a first confirmed banking-sector cyber incident as a systemic liquidity event rather than an isolated operational failure, consistent with current stress-testing posture. A confirmed institutional breach, when it occurs, is likely to trigger a coordinated regulatory response rather than a standard incident-disclosure cycle.
  • Initial access brokers are expected to continue monetising compromised credentials and remote-access infrastructure ahead of any single ransomware operator developing its own intrusion capability. The commercialised access economy not any one group’s tradecraft will remain the primary bottleneck shaping how quickly a new victim can be operationalised.
  • Third-party and supply-chain compromise will remain a primary route into better-defended primary targets, particularly in mining and manufacturing, where smaller equipment and technology suppliers with weaker security maturity provide indirect access to larger, harder-to-reach operators. Expect continued targeting of the supplier tier over direct attacks on hardened primary targets.

Consolidated recommendations

  • Mandate phishing-resistant MFA across all customer/member-facing portals the single highest-leverage control implied by this period’s incidents.
  • Extend third-party and contractor risk assessment beyond IT vendors to equipment, engineering, and logistics suppliers, given the demonstrated mining and manufacturing attack pattern.
  • Build verification-before-response processes for leak-site claims treat a listing as an allegation requiring forensic confirmation, not a confirmed breach.
  • Align incident-response planning to regulator-modelled scenarios (RBNZ’s cyber-triggered liquidity disruption) rather than incident-count trends alone.
  • Adopt AS IEC 62443 OT security controls ahead of formal mandate, and prioritise asset-inventory work per ASD’s CI Fortify guidance.

MITRE ATT&CK Mapping

This maps technique categories already established elsewhere in this report to standard ATT&CK identifiers it is not a validated Navigator layer. Most incidents here are leak-site claims without public technical detail; no procedure-level specificity is asserted beyond what a cited source actually reported.