Close Menu
The Politic ReviewThe Politic Review
  • News
  • U.S.
  • World
  • Politics
  • Congress
  • Business
  • Economy
  • Money
  • Tech
  • More Articles
Trending

Extra EU Border Checks Suspended at English Port After Long Delays

May 24, 2026

Trump Administration Temporarily Moves USCIS Lawyers to DOJ to Speed Denaturalization Cases

May 24, 2026

Report: Terrorist Planned to Kill First Daughter Ivanka for Revenge Against President Trump’s Elimination of Soleimani

May 24, 2026
Facebook X (Twitter) Instagram
  • Donald Trump
  • Kamala Harris
  • Elections 2024
  • Elon Musk
  • Israel War
  • Ukraine War
  • Policy
  • Immigration
Facebook X (Twitter) Instagram
The Politic ReviewThe Politic Review
Newsletter
Sunday, May 24
  • News
  • U.S.
  • World
  • Politics
  • Congress
  • Business
  • Economy
  • Money
  • Tech
  • More Articles
The Politic ReviewThe Politic Review
  • United States
  • World
  • Politics
  • Elections
  • Congress
  • Business
  • Economy
  • Money
  • Tech
Home»Tech»Australia Cybersecurity Gets Major Overhaul After Devastating 2022 Attacks
Tech

Australia Cybersecurity Gets Major Overhaul After Devastating 2022 Attacks

Press RoomBy Press RoomJuly 4, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram

An American security company called Commvault commissioned a survey last week that found Australian businesses have recovered much more quickly from cyberattacks over the past year, thanks to improved preparedness and tighter government regulations on security.

Australia’s cybersecurity wake-up call arrived in 2022 with a pair of high-profile data breaches, which illuminated major weaknesses in security and caused a great deal of damage. The first victim was a telecom company called Optus, one of the largest in Australia. Hackers stole a massive trove of customer data from the company in September 2022, including driver’s license numbers and government ID numbers.

The company admitted a “significant” number of its millions of customers were affected by the breach. Optus offered credit protection to its customers in the aftermath and provided assistance with changing identification numbers that might have been compromised.

The second attack came a month later and targeted Medibank, a private health insurance firm. Medibank’s servers were infected with ransomware, and the hackers threatened to release confidential medical records for millions of clients if they were not paid.

The perpetrators, who were identified as a Russian “ransomware for hire” group called REvil, demanded one dollar for each of the company’s 9.7 million customers. Medibank did not pay the ransom. An Interpol investigation of the crime was launched, and in January 2024, the governments of Australia, the United Kingdom, and the United States announced sanctions against the prime suspect, a 33-year-old Russian national named Aleksandr Gennadievich Ermakov.

The Optus hack was accomplished, cybersecurity experts found, through an unsecured Application Programming Interface (API), a forgotten back door hanging wide open on the Internet that allowed the attackers to stroll right into the system. Once they were inside, the thieves discovered Optus’ customer database was structured in a way that allowed them to steal it quickly and easily.

Medibank did not require its employees to use multi-factor authentication, so there was no defense in place against a hacker who chanced to find the username and password of a legitimate user. A multi-factor authentication scheme requires users to have a second form of digital identification, ranging from another password to a security code requested via a smartphone app, for the very purpose of thwarting intruders who get their hands on valid passwords.

In the case of Medibank, the hackers struck gold by finding that one of the company’s IT service desk operators saved his username and password in his Internet browser at work, as ordinary users often do.

The operator’s work computer was configured to automatically synchronize his browser data across accounts, so it duly transmitted his saved login credentials to his computer at home, which became compromised by malware.

Making matters worse, the compromised employee had administrator-level access to much of Medibank’s network. The company’s security system swiftly detected the intruder, but then failed to escalate the intrusion or trigger a security response, so the hacker was able to lurk in the system for almost two months and make off with over 500 gigabytes of sensitive data.

The double sucker punch of the Optus and Medibank hacks led to a flurry of new Australian government regulations on cybersecurity, which cracked down on all of the lapses in authentication and security response that occurred in the two high-profile cases. Companies were also required to report data breaches to the government and the public more quickly.

According to Commvault’s survey, companies in Australia and New Zealand are now responding to cyberattacks and recovering from the damage 38 percent faster than they were last year. The average recovery time is now 28 days, down from 45 days in 2024. Australia still lags behind the global average of 24 days.

“I do put that down to the fact that organisations and enterprises are getting more aware. I also put it down to the fact that the regulators are being more stringent and more strict on what their requirements are,” Commvault Asia-Pacific Vice President Martin Creighan told Reuters.

The news was not all good. Commvault’s survey found that less than a third of Australian firms were capable of responding effectively to a cyberattack, and 12 percent had no formal response plan at all.

Many industry observers grumbled that Commvault’s survey merely proved that Australian firms — and quite a few others around the world — will only take cybersecurity seriously when they are compelled to do so. 

Creighan said corporate interest in security picked up after 2022 because executives were “worried about the regulation landscape.” Cynics argue that much of that worry stems from company brass realizing they could be held personally liable for massive cyberattack damages. They also fear Australia waited much too long to get serious about security, while companies in other countries spent decades building formidable defenses and training their employees in best practices.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link

Related Articles

Tech

Carnival Cruise Line Cancels Bookings After Glitch Dramatically Cut Fares: ‘Literally a Steal’

May 23, 2026
Tech

Toyota Hybrid Explodes in Flames Near Wall Street’s Charging Bull Statue

May 23, 2026
Tech

AI Fail: Starbucks Abandons AI-Powered Inventory Tool After Only 9 Months

May 22, 2026
Tech

Elon Musk Describes His Neuralink Brain Implants as ‘Jesus-Level Technology’

May 22, 2026
Tech

Exclusive — Leading the Future Super PAC Expands House GOP Endorsements

May 22, 2026
Tech

Director Tulsi Gabbard Working Diligently to Declassify Controversial FISA Court Opinion

May 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Trump Administration Temporarily Moves USCIS Lawyers to DOJ to Speed Denaturalization Cases

May 24, 2026

Report: Terrorist Planned to Kill First Daughter Ivanka for Revenge Against President Trump’s Elimination of Soleimani

May 24, 2026

Dem Rep. Casten: Should Get Rid of Filibuster — Senate ‘Overrepresents Land at the Expense of People’

May 24, 2026

Suspected Oreshnik strike reported near Kiev (VIDEOS)

May 24, 2026
Latest News

Blackburn: ‘Let’s Be Sure’ Other Members of the Axis of Evil Don’t Prop Iran Up

May 24, 2026

Trump Announces Iran Deal ‘Largely Negotiated’, Strait of Hormuz to Be Opened

May 24, 2026

Gunshots Heard Outside White House

May 24, 2026

Subscribe to News

Get the latest politics news and updates directly to your inbox.

The Politic Review is your one-stop website for the latest politics news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Instagram Pinterest YouTube
Latest Articles

Extra EU Border Checks Suspended at English Port After Long Delays

May 24, 2026

Trump Administration Temporarily Moves USCIS Lawyers to DOJ to Speed Denaturalization Cases

May 24, 2026

Report: Terrorist Planned to Kill First Daughter Ivanka for Revenge Against President Trump’s Elimination of Soleimani

May 24, 2026

Subscribe to Updates

Get the latest politics news and updates directly to your inbox.

© 2026 Prices.com LLC. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact

Type above and press Enter to search. Press Esc to cancel.