Experts warn Russian hackers actively targeting Australian industries, infrastructure | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


We’re in the middle of World War 01110111 01100101 01100010

Most of us don’t know it.

Which is a problem, as we are expected to already be fighting on the front line.

The Australian Signals Directorate (ASD) has warned that Russian hackers are actively targeting critical industries and infrastructure. This includes communications networks, energy suppliers, financial services and the defence industry. But especially local councils and hospitals.

Think it’s just fearmongering?

Think again.

In 2021, hackers apparently broke into the water treatment facility of Florida’s Oldsmar district council via remote-access software. An employee said he saw his mouse suddenly start to move, open control panels and change settings.

Before his eyes, the amount of sodium hydroxide being pumped into drinking water was increased to toxic levels.

“It’s not about fearmongering. It’s about readiness,” says Lincoln Goldsmith, the director of digital security firm Semperis.

“It’s not a case of if. It’s a case of when. You almost have to assume your security has already been breached.”

Royal Australian Navy sailors plough the seas in warships to protect our fuel and fertiliser imports.

Royal Australian Air Force pilots scour the skies for spies and intruders.

Australian Army soldiers practice fighting to defend the homes of our families and friends.

Customs watches our ports and airfields for unwanted intrusions.

But the World Wide Web (www) and Internet of Things (IoT) have no borders. Only doors.

That makes you and me Australia’s new Home Guard.

It’s up to us to defend our cyber sovereignty.

And therefore ourselves.

Unseen enemies

Car manufacturer Jaguar Land Rover was attacked by Russian hackers last year.

The complex attack began through an employee’s insecure personal device.

It contained a method for remotely accessing the company’s secure servers.

Soon, they had the keys to all the car manufacturer’s secrets and advanced systems.

“They had their smart factories taken offline for a significant amount of time,” Mr Goldsmith says.

And the damage spread quickly.

“It’s often not just the victim themselves that gets impacted. It’s the entire supply chain,” he adds.

Russia is deliberately targeting nations that support Ukraine’s efforts to resist its invasion.

That includes Australia.

“They are so sophisticated. They are so crafty,” Mr Goldsmith explains.

“These state-funded organisations now have huge amounts of resources and computing power at their disposal.”

They’re targeting civilians.

“One of the main industries being targeted is healthcare,” Mr Goldsmith warns.

“If a healthcare organisation – a hospital, a clinic, a specialist – gets breached, you have human lives at risk …”

Such untrained civilian practitioners can panic.

“They think, ‘We have to act, and we have to act now. Let’s pay the ransom. Let’s get our decryption keys, and hopefully we’re good’. They’re not. They’re making things worse.”

The goal is to cause chaos, confusion and damage. The hope is this will prompt public pressure for governments to back down.”

Australia has no protective digital wall.

Just millions of gates.

Most are in civilian hands. That means home users, academia, businesses, services and government agencies.

Each is individually responsible for defending them.

“When we set something digital up, we’ve built a castle. We’ve built the stone walls, and we’re good for now,” Mr Goldsmith explains.

“But the threat actors are marauders, crusaders, pirates … whatever their motivation may be. So, now they’ve got cannons. Our walls just became weak. And they got their cannons before we could adapt. So there’s going to be a period of risk there.”

It’s a digital arms race.

“Okay, we’ve upgraded the walls, but now the attackers have got bombs. And they’ve got them before we could upgrade … that seems to be a bit of a pattern.”

Trojan gadgets

Kenyan contractors are suing Meta for being ordered to peep through their latest consumer gadget – online smart glasses.

They were supposed to be training AI. But in April, they blew the whistle that this involved watching Meta customers having sex, getting in and out of the shower, and in a multitude of other compromising situations.

So Meta fired them.

But what if one of those 1108 contractors had an out-of-date router? An old operating system?

Hackers – be they hostile governments, corporate saboteurs, terrorists, or opportunists – could access the glasses through their back door.

“We are all heavily connected now. Everything is getting thrown onto a network,” Mr Goldsmith explains.

“All of these things that we’re buying, be it cars, be it refrigerators, be it televisions or farm machinery – we’re putting it all on the network.”

These are often connected directly to data centres in Beijing, Texas or Taiwan.

“With consumer products, there is no data sovereignty,” Mr Goldsmith states.

“Essentially, what we’re doing is we are putting more and more and more of our daily lives outside our city walls. And that exposed attack surface has become scarily large.”

Much of it is nice.

But unnecessary.

One of the first cyberattacks occurred during Operation Desert Storm against Iraq in 1990. French-made desktop printers destined for dictator Saddam Hussein’s military were intercepted by US intelligence agents. Corrupted chips helped bring down the nation’s air defence network.

That printer could now be your online kettle.

The secret agent may find a weakness in your Internet of Things to access it.

And it never needed to be online in the first place.

Gadgets, routers, laptops, phones, smart speakers, smart televisions, AI-enabled dolls and PCs are usually secure when first bought.

“The proliferation of security products on the market is making direct attacks much harder,” Mr Goldsmith explains.

“So, where is the next easiest spot? Where is the next weakest link in the chain?

“That invariably sits with legacy technology.”

The older a product gets, the more time hackers have to find exploits. And the less likely these are to be patched – even if the supplier still provides them.

Eventually, they’re forgotten.

But they still work just fine.

Be alert, not alarmed

Famous Japanese beer brewing company Asahi fell victim to a cyberattack in September last year.

Hackers fed employees fake CAPTCHA (are you a human?) test pages.

This allowed them to cripple the company’s digital stock distribution and supply infrastructure.

“They weren’t able to ship out their beer,” Mr Goldsmith explains.

“Restaurants, convenience stores … they couldn’t sell their beer to someone wanting to relax at the end of their working day. Such attacks can be far-reaching.”

Digital vulnerability is a feature, not a bug.

Much of the technology behind the internet is half a century old.

Like your router.

It’s mostly the software layer on top of the device that gets updated.

Then there’s the core code upon which the entire internet is built.

“We protect Active Directory, which is a 25-year-old product, and yet 90 per cent of customers globally are still using it,” says Mr Goldsmith.

Active Directory assigns internet users and devices their identities.

It serves as an invitation list. And guard at the door.

“Essentially, it is the keys to the kingdom,” he adds.

It works.

Users rarely see the difference between one update and the next.

“We see a shortage of legacy knowledge in organisations. That person who came in, implemented it, and set it up has moved on. The next person that comes in doesn’t know it as well, so … ‘Hey, if it ain’t broke, why fix it?’

“If something goes wrong, it can bring a whole company down. Going back to Active Directory, if that goes down – you won’t even be able to enter the building because your security pass is linked to your Active Directory ID.”

Now homes, businesses and essential services alike are inviting a new stranger into their homes.

Artificial intelligence assistants.

“It’s super efficient. It’s great. It can help me. I can put in a command, and it’ll give me all the information I need because it’s connected to all of this metadata and data warehousing,” Mr Goldsmith says.

But how do you monitor a synthetic human?

All its electric “thoughts” come from proprietary digital “brains” based overseas. Even if relayed through power-hungry local data centres.

Semperis research found 74 per cent of organisations believe AI will increase attacks on their identity infrastructure. Especially upon critical identity credentials. Only 32 per cent are very confident they could regain control if AI exposed administrator-level credentials.

“But they’re still bringing AI in,” he adds.

Making matters worse, only 65 per cent fully register, authenticate and authorise imported AI identities. The remaining 35 per cent install them out of the box.

“Ask yourself: Is that convenience and efficiency worth the risk?” Mr Goldsmith concludes.

Home guard

Russian intelligence service hackers launched a co-ordinated assault on the Polish electricity grid last year.

It wasn’t hard.

They shook digital doorknobs. Poked at digital hinges. They eventually found online systems allowing remote control of more than 30 solar and wind farms that still had factory-setting usernames and passwords installed.

“What that did was basically cut the power to around half a million customers during the peak of Poland’s winter,” Mr Goldsmith explains.

“They weren’t able to heat their houses.”

In this instance, it was the IT team employed by individual companies that was the first line of defence.

In Jaguar Land Rover’s case, an individual employee was part of the breach.

Everyone has been conscripted to the defence of Australian infrastructure, data and lives.

Even if you don’t know it.

“You may be a mechanic who is sitting in a noisy workshop running Windows 10 that’s still connected to the network,” Mr Goldsmith explains.

Microsoft no longer supports Windows 10. So every new exploit a hacker finds will go unpatched.

“Chances are you can access car manufacturer and supplier systems,” Mr Goldsmith adds.

“So you can become the point through which hackers can reach these other companies.”

Government has been pushing universities and defence-related businesses to tighten security for more than a decade. Banks have been burnt. Insurance, health and telecommunications providers breached. They’ve belatedly upped their game. For now.

So attackers are looking for side entrances.

Such is the risk that the Five Eyes intelligence alliance (Australia, the United Kingdom, the United States, New Zealand and Canada) recently warned businesses, services and government agencies to audit everything accessing their computer networks.

Is it up to date? Is it secure?

Does it all really need to be accessible online anyway?

Security checks don’t need to be expensive.

Mr Goldsmith says Semperis offers its Forest Druid (attack path analysis) and Purple Knight (Active Directory security snapshot) tools for free.

But can Canberra really expect a crash repairer, a corner chemist or an employee’s child to be Australia’s frontline digital combatants?

Australia spends roughly $182 million each day to defend its sovereign territory.

The June 2025 NATO Summit in The Hague urged member states to commit 1.5 per cent of their gross domestic product (GDP) to resilience and security-related investments. That’s in addition to the 3.5 per cent spent on territorial defence.

“When you arrive off a plane in Australia, you go through your security scans, and you know you might get called for a secondary scan. Why is that? That is done to protect our environment, economy and citizens,” Mr Goldsmith says.

“Would it be too much to ask for that to exist for digital networks. For connectivity? Until then, it’s up to us.

“It’s really about understanding your current position.

“Don’t just buy and bolt on products because it’s convenient, it’s new, and it’s nice and shiny. Ask instead if it is actually going to help build a more fortified position in this digital battleground.”

Jamie Seidel is a freelance writer



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW