Understanding the Modus Operandi of Major Cyber Attacks in Australia (2020-2025)

Ajay Unni
Ajay Unni CEO,StickmanCyber
July 25, 2026 5 min read

Updated: Feb 4

Australia experienced a sharp rise in high-impact cyber-attacks over the last half-decade, ranging from crippling ransomware in logistics and essential services to unprecedented mass data breaches at major telecommunication and health-insurance providers. The research table below catalogues the most consequential events between 2020 and mid-2025, followed by an expansive analysis of attack patterns, root causes, and strategic lessons for organisations operating in the Australian threat landscape.

Toll Group Ransomware Wave 2020

Incident Summary

Toll Group, a critical logistics provider, endured two separate ransomware strikes within five months. The first incident in late January 2020 employed the Mailto strain, encrypting more than 1,000 servers and halting parcel tracking. Recovery took six weeks. In May, the newer Nephilim gang infiltrated Remote Desktop Protocol (RDP) endpoints, exfiltrated around 220 GB, and threatened leak-ware publication.

Key Technical Factors

  • Persistently exposed RDP services with weak password hygiene.
  • Insufficient network segmentation allowed lateral traversal.
  • Data exfiltration went undetected due to limited outbound traffic monitoring.

Strategic Lessons

  • RDP must be either decommissioned or protected behind MFA-enabled gateways.
  • A mature egress-filtering strategy is as vital as perimeter ingress rules.
  • Repeat victimisation underscores the need for continuous purple-team exercises to validate post-incident hardening.

Service NSW Email Account Compromise 2020

Incident Summary

Cyber criminals phished 47 Service NSW employees, gaining mailbox access that contained 3.8 M documents (730 GB). Manual analysis identified about 104,000 customers whose identity document licences, passports and birth certificates were exposed.

Key Technical Factors

  • Spear-phishing emails delivered malicious links.
  • Credentials harvested via fake Office 365 login.
  • Attackers used OWA/IMAP to exfiltrate mail archives, bypassing basic anomaly thresholds.

Strategic Lessons

  • Email remains the blunt instrument of choice. Zero-trust mail-gateway isolation plus enforced security-key MFA would have thwarted credential theft.
  • Organisations holding large identity datasets must implement data minimisation to reduce breach blast radius.

BlueScope Steel Ransomware 2020

Incident Summary

On 15 May 2020, BlueScope detected ransomware in one of its U.S. subsidiaries; the infection propagated to Australian manufacturing operations, forcing plant shutdowns and manual steel dispatch.

Key Technical Factors

  • Likely exploitation of an unpatched CVE in Citrix/remote gateway or weak RDP.
  • Thin segmentation between operational technology (OT) and IT networks amplified impact.

Strategic Lessons

  • Industrial operators must adopt IEC 62443 segment-by-design principles.
  • OT runbooks should rehearse manual fail-over to avert revenue-crippling downtime.

Parliament House & Channel Nine Incidents 2021

Incident Summary

Late March 2021 saw two synchronous cyber events: parliamentary email outages and a sabotage-style breach at Channel Nine that blocked production of the flagship Weekend Today show. Although attribution remains contested, officials cited state-based tradecraft. Smartphones and tablets at Parliament malfunctioned, hinting at a mobile device management compromise.

Strategic Lessons

  • Supply-chain and media outlets are high-value influence targets; redundancy in broadcast OT and resilient MDM policies are essential.
  • Crisis communication drills must consider simultaneous attacks on government and media, complicating public messaging.

Optus Mass Data Breach 2022

Incident Summary

An unauthenticated Optus API exposed to the internet retained a logic flaw from 2018 that disabled access checks. An attacker iteratively scraped the endpoint, acquiring personally identifiable information (PII) for 9.8 million current and former customers.

Technical Breakdown

  • Older code branch bypassed token validation when specific headers were absent.
  • No rate limiting or behavioural analytics flagged the high-volume enumeration.

Policy Aftermath

  • Federal reforms fast-tracked information sharing between banks and telcos.
  • Optus absorbed costs for document replacement and faced potential multi-billion-dollar class actions.

Medibank Extortion Breach 2022

Incident Summary

Threat actors obtained VPN credentials from a third-party IT contractor lacking MFA, installed malware, and exfiltrated approximately 520 GB of highly sensitive health data between August and October 2022. When Medibank refused a US$10 million ransom, hackers progressively leaked sensitive files.

Technical Breakdown

  • Multi-factor authentication was not enforced on all privileged VPN accounts.
  • SIEM alerts between 25 August and 13 October were not properly triaged, delaying detection.

Strategic Lessons

  • Third-party access demands least privilege and mandatory hardware-token MFA.
  • Health data attracts double extortion; zero-retention policies for legacy PII mitigate damages.

Fire Rescue Victoria Ransomware (2022–2023)

Incident Summary

The Vice Society gang struck on 15 December 2022, paralysing Fire Rescue Victoria's dispatch IT. Manual radio and pager procedures ensured emergency responses but increased crew workload. On 10 January 2023, Vice Society leaked HR files, budget sheets and applicant data on its Tor site.

Technical Observations

  • Attack exploited underfunded local government cybersecurity budgets.
  • Ransomware gangs pivoting from education to essential services escalated public safety risks.

Latitude Financial Data Breach 2023

Incident Summary

Latitude's supplier environment was phished, allowing stolen SSO credentials to grant network entry and facilitate bulk theft of historic loan application data. Approximately 7.9 million driver licence numbers and transaction statements were stolen.

Strategic Lessons

  • Even regulated financial entities suffer when supply-chain identity is weak.
  • Large historical datasets for credit assessment should be tokenised or archived offline.

Cyber-Attack Trend Patterns Exhibited

1. Authentication Weaknesses Dominate

Across incidents, stolen or absent credentials (Medibank, Latitude) and unauthenticated APIs (Optus) were decisive. Mandatory hardware-based MFA and continuous identity assurance would have prevented or limited most breaches.

2. Data Minimisation as Damage Control

Optus and Medibank held years-old dormant customer records, greatly expanding breach scope. The Privacy Act's "destroy or de-identify" clause must shift from a compliance footnote to an operational imperative.

3. Double-Extortion Ransomware

Toll, BlueScope, Fire Rescue Victoria and Medibank reveal a shift from pure encryption to data-leak coercion, forcing boards to improve exfiltration detection and incident response communications.

4. Supply-Chain Exposure

Latitude and Medibank demonstrate that third-party vendors remain the weakest link. Comprehensive third-party cyber risk management frameworks are increasingly non-negotiable.

5. Critical Infrastructure Targeting

Fire and ambulance services, steel mills and telecommunications providers illustrate adversarial interest in high-impact public services, aligning with global trends of disrupting societal functions for leverage.

Organisational Playbook Imperatives

1. Zero-Trust Baseline

Enforce least privilege, network micro-segmentation and continuous authentication.

2. API Security Lifecycle

Inventory, authenticate and rate-limit every endpoint. Adopt spec-first design with rigorous security testing.

3. Data Retention & Tokenisation

Apply strict purging schedules and tokenise historic PII to mitigate breach impact.

4. Purple-Team Drills

Simulate ransomware and API abuse scenarios and validate incident response plans quarterly.

5. Supply-Chain Governance

Embed contractual obligations for MFA, logging and breach notification within vendor agreements.

Conclusion

Between 2020 and 2025, Australia transitioned from sporadic ransomware incidents to nation-spanning data breaches that drove legislative change and redefined corporate cyber risk. The attacks chronicled here expose recurring gaps, including unguarded APIs, inadequate MFA and excessive retention of personal data. Organisations must embrace a zero-trust, data-minimalist approach, supported by board-level accountability and rigorous third-party oversight, to avoid repeating the costly lessons of the past half decade.

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Learn More About StickmanCyber
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment