Australia’s Annual Cyber Threat Report 2024–25 shows a sharper threat environment, with more hotline calls, more incidents, rising financial losses, and a growing focus on state-sponsored activity against critical infrastructure, telecommunications, and logistics. The report also highlights escalating ransomware, credential theft, phishing, DDoS, and edge-device exploitation, while urging stronger resilience measures such as MFA, logging, legacy IT replacement, and preparation for post-quantum cryptography. #APT28 #FancyBear #ForestBlizzard #BlueDelta #GRU #BADBAZAAR #MOONSHINE #REDSPICE #ASDsACSC #CIFortify #ReportCyber
Keypoints
- Annual cybersecurity reports typically begin with a foreword and executive summary, then describe the year in review, the national threat landscape, major threat actors, common techniques, resilience guidance, and reporting or response programs.
- They usually combine high-level strategic context with operational data, including incident counts, losses, sector breakdowns, major trends, and recommended mitigations for individuals, businesses, and critical infrastructure operators.
- In this report, ASD’s ACSC received over 42,500 hotline calls, a 16% increase, responded to over 1,200 cyber security incidents, up 11%, and issued more than 1,700 notifications of potentially malicious activity, up 83%.
- ReportCyber received over 84,700 reports, down 3%, but the average self-reported cost per business report rose 50% to $80,850, showing that cybercrime is becoming more damaging even when report volume fluctuates.
- The Australian Protective Domain Name System blocked 334 million malicious domains, a 307% increase, underscoring the scale of malicious infrastructure targeting Australian users and organizations.
- State-sponsored cyber actors remain a major strategic concern, with repeated targeting of Australian government networks, critical infrastructure, telecommunications providers, and logistics and technology firms for espionage and pre-positioning.
- The report highlights a Russian GRU campaign by unit 26165, also known as APT28, Fancy Bear, Forest Blizzard, and BlueDelta, targeting Western logistics entities and technology companies supporting aid to Ukraine.
- PRC-affiliated actors were also linked to major telecommunications espionage activity, and PRC-linked groups were reported compromising routers and IoT devices to build a botnet exceeding 260,000 devices.
- Critical infrastructure accounted for 13% of all incidents, up 2%, and the most common CI activity types were scanning or reconnaissance (41%), DoS/DDoS (31%), and phishing (20%).
- Within CI, the top reporting sectors were financial and insurance services (32%), transport, postal and warehousing (26%), and information media and telecommunications (16%).
- Healthcare emerged as a particularly high-risk sector: ransomware incidents against healthcare doubled year over year, and malicious actors were successful in 95% of healthcare and social assistance incidents responded to by ASD’s ACSC.
- The report also describes an e-prescription-related suspected ransomware incident in which approximately 6.5TB of data and personal and health information for about 12.9 million customers were exfiltrated.
- Phishing remained the most common initial access technique at 38% of incidents, while compromise accounts (31%) and gathering victim identity information (30%) were also among the top techniques observed.
- Government reporting focused more on early-stage techniques such as phishing and account compromise, while industry reporting showed far more data-encryption incidents, public-facing application exploitation, and financial theft.
- DoS/DDoS attacks rose sharply, with ASD’s ACSC responding to more than 200 such incidents, up more than 280%, and industry reporting suggesting June 2025 may have had the most DDoS incidents on record.
- Malicious actors increasingly exploit vulnerabilities in edge devices, and ASD observed more than 120 incidents involving edge-device attacks, with 96% successful.
- The number of publicly reported common vulnerabilities and exposures increased by 28%, reinforcing the report’s warning that vulnerable devices, legacy IT, and supply-chain weaknesses continue to create opportunities for intrusion.
- Information stealers, credential theft, ransomware, and “living off the land” tradecraft remain persistent techniques, with AI likely helping attackers automate phishing, scale operations, and improve evasiveness.
- The report stresses a recurring theme of resilience through fundamentals: phishing-resistant MFA, strong unique passwords or passphrases, regular patching, backups, and strong reporting discipline.
- For organizations, the report’s four major defensive priorities are effective logging, replacement of legacy IT, stronger third-party risk management, and preparation for post-quantum cryptography.
- For critical infrastructure, ASD recommends isolating vital OT and enabling systems, being able to rebuild them, and adopting a secure-by-design and secure-by-default mindset for new technologies.
- ASD’s partnership and uplift programs are a major part of the response, including more than 133,000 Cyber Security Partnership Program partners, 8 CI uplifts covering 38 assets, and 478 high-priority taskings under CHIPs.
- The report emphasizes that cyber resilience is a shared responsibility, and that timely reporting to ASD’s ACSC can help prevent further victims and improve national threat visibility.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)