Skip to main content

ASIO: Adversaries Are Already Inside Australia's Critical Infrastructure

STATUS: Active Compromise SEVERITY: 8/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads

Jul 29, 2026

·

Blog

·

Secure Communications

ASIO warns that foreign adversaries are already inside Australia's critical infrastructure. Attackers have reportedly compromised networks, stolen defender credentials, and positioned themselves for potential future sabotage—turning "assume breach" from a security slogan into a national security imperative.¹ ²

What This Attack Is Doing — and Why It Works

Peacetime positioning, not opportunistic cybercrime. ASIO Director-General Mike Burgess told the agency's 2026 Annual Threat Assessment that foreign adversaries had compromised a critical infrastructure provider, mapped the network, maintained access, and obtained login credentials for active users — including the IT professionals responsible for defending it.¹ This is different from a typical breach because the objective was not theft, extortion, or public disruption today. The value was quiet control: enough identity, access, and operational knowledge to sabotage essential services later, at a time of the attacker's choosing.¹

The operational risk is immediate even if the disruption is deferred. Once attackers hold valid credentials and understand the environment, they can blend into normal activity, test defender visibility, preserve dormant footholds, and identify which systems would create the greatest real-world effect if disabled or manipulated.² For energy, telecom, transport, and government operators, that post-compromise posture turns cyber access into a resilience problem: outages, delayed emergency response, loss of trusted communications, cascading service failures, and public-confidence damage become the consequence set — not simply data exposure.²

This is why the incident changes the defensive question. The old model asks whether perimeter controls can keep attackers out. This case assumes a more dangerous reality: adversaries may already be inside, using legitimate identities, waiting for the moment when disruption creates maximum pressure.¹ Google Threat Intelligence Chief Analyst John Hultquist reinforced the same point: effective attacks on critical infrastructure can require years of groundwork, meaning operators are effectively fighting tomorrow's conflict during peacetime.² ³

What Attackers Gained – And What They Can Do With It

Attacker Gain
What It Enables
Operational Consequence
Post-Compromise Risk
Active user credentials¹
Operate as legitimate users, access internal systems, and bypass controls tuned for outsiders.
Routine activity can mask malicious movement, delaying detection while defenders believe systems are functioning normally.
Attackers can return until credentials are rotated, sessions are invalidated, and trust relationships are re-verified.
IT/security staff credentials¹
Reach administrative tools, view security telemetry, alter configurations, and understand response processes.
Defenders may lose visibility or waste time chasing symptoms while privileged accounts are used to preserve access.
Cleanup is incomplete unless privileged identity, monitoring, and admin workflows are rebuilt around assumed compromise.
Network maps and system knowledge¹
Identify dependencies, high-impact nodes, access paths, and systems that connect IT operations to essential services.
Sabotage can be targeted for maximum disruption rather than random outage, increasing risk to energy, telecom, transport, and government services.
Even after malware removal, the adversary may retain intelligence needed to re-enter or strike through adjacent systems.
Persistent dormant access¹
Maintain footholds quietly until geopolitical timing, crisis conditions, or operational pressure make disruption more valuable.
The incident becomes a standing continuity risk, not a closed security event.
Resilience planning must assume multi-year dwell time, repeated access attempts, and delayed activation.

Why This Matters

Old Assumption
Current Reality
BlackBerry Response
Perimeter defense stops intrusion.
Adversaries are already inside, positioned years in advance; detection may come years after initial compromise.¹
Continuous UEM compliance monitoring detects anomalous device behavior after compromise, not only at enrollment.
Vendor trust is a one-time procurement decision.
Compromised credentials, including IT staff accounts, undermine ongoing vendor and infrastructure trust.¹
Sovereign-controlled infrastructure and key custody stay in the customer's jurisdiction; IRAP-assessed for Australian government use.
IT and OT security are separate problems.
Targeting of energy, telecom, and transport puts the devices that manage operational systems in scope.²
UEM policy enforcement and compliance monitoring extend to OT-adjacent management endpoints.

IMMEDIATE 
Hunt for existing access: rotate privileged credentials, review privileged session activity, and search for dormant footholds rather than waiting for alerts.¹
IMMEDIATE 
Deploy phishing-resistant MFA for IT and security staff; ASIO confirmed defender credentials are an active collection target.¹
SHORT-TERM 
Extend UEM compliance monitoring to critical infrastructure management devices wherever feasible, including OT-adjacent endpoints.
SHORT-TERM 
Reassess vendor jurisdiction exposure across the full infrastructure stack, not just the communications layer.
ONGOING 
Build multi-year adversary dwell time into resilience planning and detection budgets as the baseline assumption.²

BlackBerry Secure Communications Position

When a national intelligence agency says adversaries are already inside critical infrastructure and have been for years, the procurement question changes.¹ It is no longer "can this vendor prevent a breach." It is "can this vendor prove sovereign control and continuous compliance once one has already happened."

Citations:

  1. Director-General of Security Annual Threat Assessment 2026 (Australian Security Intelligence Organisation (ASIO), Mike Burgess, 2026 Annual Threat Assessment, July 8).

  2. SIO Warns Cyber Adversaries Are Already Inside Australia's Critical Infrastructure (iTWire / Google Threat Intelligence commentary, June 29, 2026).

  3. Nation-State Actors Cracked Critical Australian Infrastructure to Cripple It at a Time of Their Choosing (The Register, June 25, 2026).

Get updates about the latest in-depth knowledge for secure communications.

The New Standard

Watch the Webinar: The Case for Mission-Critical Communications

Join us for a 45-minute webinar where our experts explore the technical and operational framework to ensure mission-certified secure communications across encryption, architecture, sovereign control, independent validation, and mission orchestration.

Watch now