AUSTRALIA Trends and Developments Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
• For critical infrastructure, the most reported incidents were compromised asset/network/infra - structure (55%, up from 12% last year), DoS/DDoS (23%) and compromised account/credentials (19%, down from 32% last year). The report for malware infection (excluding ransomware) (previ - ously, 17%) did not feature among the top reported incidents. Another key source of information relates to the notifi - able data breach (NDB) scheme under the Privacy Act 1988 (Cth), which requires notification of eligible data breaches. The Office of the Australian Information Commissioner’s latest report covers January to July 2025, which indicates there were 532 notifications received and 178 (33%) resulted from cybersecurity incidents. These incidents include: • phishing (28%); • compromised or stolen credentials (21%); • ransomware (21%); • hacking (17%); • brute-force attacks (compromised credentials) (6%); and • malware (4%). The top five sectors primarily reflect the ASD’s statis -
• Crypting: developers who create software tools that encrypt and obfuscate malware source code. • Bulletproof hosting: network providers that allow entities to host content and run operations on the internet. • Cryptocurrency laundering: decentralised crypto - currency exchanges that mix, tumble, or otherwise anonymise the source or other details of digital assets. While some of these services are arguably criminal in nature, others are painted as “cybercrime-as-a- service” with extremely broad strokes. Whether the service providers are criminal should turn on the purpose or intent of their development. Encryption, network providers, and decentralised cryptocurrency exchanges have legitimate purposes and genuine uses that are seemingly ignored by ASD and other regulators. Specific instances are often created with the primary interest of privacy, universality, and free - dom. However, their criminality appears to turn on their responsiveness to regulators’ demands or the intentions of certain users. Such behaviour is illustrated by the Australian Crimi - nal Intelligence Commission (ACIC) in its submission to the Parliamentary Joint Committee on Intelligence and Security’s review of the Surveillance Legislation Amendment (Identify and Disrupt) Bill 2020 when it stated “ACIC observation shows there is no legiti - mate reason for a law-abiding member of the com - munity to own or use an encrypted communication platform”. In the same submission, it recognised encryption and anonymising technologies as having a “valuable role in protecting the privacy and data of Australians”. ACIC later clarified it was only referring to “encrypted communication platforms which can only be used to communicate with similar devices, such as SkyECC, Encrochat, and Phantom Secure” and which it deemed had no “legitimate use before they were disrupted”. The danger of such broad and unnuanced rhetoric is that it bleeds into the legislative and regulatory approaches, leading to legitimate services being criminalised. Such action could destabilise existing cybercriminal models and offer some (temporary) measure of protection to the public. However, such
tics, being from first to fifth: • health service providers; • finance (including superannuation); • the Australian government; • education; and • legal/accounting/management services. Cybercrime-as-a-service
In the 2024-25 Report, the ASD also describes the “cybercrime ecosystem” and highlights the profes - sionalisation of certain services “that support cyber - criminal activities” and enable their crimes. The five “enable services” identified are as follows. • Initial access brokerage: initial access brokers who sell victim details to enable access to their net - work. • Ransomware development: developers who create, maintain and improve ransomware products.
27 CHAMBERS.COM
Powered by FlippingBook