Australian critical infrastructure likely targeted by hackers from Salt Typhoon

A leading cybersecurity authority acknowledged that China’s Salt Typhoon hacking campaign has likely infiltrated critical infrastructure in Australia, marking one of the most successful, long-lasting espionage operations observed to date. Alastair MacGibbon, the Chief Strategy Officer at CyberCX and a former cybersecurity advisor to ex-prime minister Malcolm Turnbull, suggested that Salt Typhoon has compromised various sectors in Australia and New Zealand without detection, representing a concerning shift in global cybersecurity threats.

MacGibbon emphasized the unprecedented efficiency of Salt Typhoon in infiltrating Western targets, pointing out that the Chinese intelligence services have breached the communications of millions of Americans, including high-ranking officials. While there is no explicit proof of Salt Typhoon’s activity in Australia, experts believe that the hackers have likely accessed undetected sectors within the country. The hacking operation, which Microsoft named based on its ties to Chinese state-backed groups, has been ongoing since at least 2019, focusing on espionage rather than quick financial gains.

One of the most alarming aspects of Salt Typhoon is its utilization of “lawful intercept” capabilities, allowing China’s Ministry of State Security to access sensitive surveillance data intended for law enforcement and security agencies through telecommunication networks. Unlike typical ransomware attacks, nation-state actors like Salt Typhoon exploit legitimate tools within victims’ systems, making them more challenging to detect. This subtle approach to cyber espionage significantly prolongs the time it takes to identify such intrusions, posing a genuine threat to businesses and national security.

Security experts stress the critical role of cybersecurity in ensuring a business’s long-term survival, as cybersecurity risks can fundamentally impact the ability to operate effectively. A necessary shift in corporate culture is evident, with the US Securities and Exchange Commission requiring companies to address cyber threats in their disclosures. As nations like Australia perceive current cyber conflicts as ongoing, the need for vigilance and collaboration among intelligence agencies becomes increasingly crucial in mitigating cyber threats.

In response to the growing cyber threat landscape, Five Eyes agencies continuously publish joint advisories with actionable guidance for critical infrastructure entities. Recommendations include regular network monitoring for abnormal activity and the implementation of robust change management practices. Despite denials from the Chinese government regarding involvement in Salt Typhoon, the global cybersecurity community remains vigilant and proactive in addressing state-backed cyber threats affecting critical infrastructure worldwide.