Australia’s Security Intelligence Organisation (ASIO) has issued strong warnings that authoritarian states, particularly China, are increasingly willing and capable of conducting cyber-enabled sabotage against critical infrastructure. ASIO Director-General Mike Burgess highlighted the growing risk of foreign governments targeting essential services such as telecommunications, power, water, and financial systems, emphasizing that these threats are no longer hypothetical. Recent telecom outages in Australia, which have already had severe consequences, were cited as examples of the potential impact, and Burgess warned that advances in technology and the proliferation of cyber capabilities are making it easier for hostile regimes to acquire the tools needed for such attacks.
Burgess specifically identified China-linked advanced persistent threat (APT) groups, including Volt Typhoon and Salt Typhoon, as actively probing and, in some cases, gaining access to Australian critical infrastructure. These groups are reportedly positioning themselves for future sabotage and espionage operations, with Volt Typhoon targeting power, water, and transport networks, and Salt Typhoon focusing on telecom infrastructure to steal sensitive data. The warnings come amid reports that Chinese officials have tacitly admitted to cyberattacks on U.S. infrastructure, further underscoring the seriousness of the threat landscape facing Australia and its allies.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
Australia's spy chief publicly warned that authoritarian nations are prepared to conduct high-impact cyber sabotage against Australia's critical infrastructure. Reporting on the warning highlighted China-linked activity as a key concern in the threat landscape.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.