The cyberattack on Origin Energy is not an isolated corporate failure. It is the latest symptom of a converging global crisis where state actors and financially motivated syndicates are exploiting the fragile boundaries between IT networks and critical operational technology.
Iranian-affiliated hackers are actively compromising programmable logic controllers across U.S. water, energy, and government systems. CISA, FBI, and EPA warn the threat will persist regardless of diplomacy. AI-driven automation is accelerating attacks beyond any precedent.
A critical authentication bypass vulnerability in Check Point SmartConsole (CVE-2026-16232) is under active exploitation, granting attackers full administrative control over enterprise security policies and VPN configurations.
12th March 2026 Cyber Update: Five Eyes Agencies Warn of INC Ransom Attacks on Australian Healthcare
Joint advisory by Australian, New Zealand, and Tongan cyber authorities warns of rising INC Ransom attacks on critical infrastructure. The RaaS group has breached 11 Australian organisations, mainly in healthcare and professional services.
Cyber News Centre's cyber update for 12th March 2026: Australian and Pacific cyber authorities have issued a joint warning on the INC Ransom group, citing ongoing ransomware and data-extortion activity affecting organisations across Australia, New Zealand, and Pacific island states.
The Australian Cyber Security Centre (ACSC) is Australia's lead federal government agency for cybersecurity, operating under the Australian Signals Directorate (ASD). It provides guidance, threat intelligence, and incident response support to government and private sector organisations. The ACSC works closely with international partners, including New Zealand's NCSC and CERT Tonga, to coordinate responses to cross-border cyber threats.
The Update and Why It Matters
Update: A joint advisory from the Australian Cyber Security Centre (ACSC), New Zealand's NCSC, and CERT Tonga has highlighted a significant threat from the INC Ransom group, which has intensified its focus on the Pacific region since early 2025. Operating a Ransomware-as-a-Service (RaaS) model, the group's affiliates have compromised at least 11 Australian organisations between July 2024 and December 2025, primarily targeting the healthcare and professional services sectors.
The attackers gain initial access via spear-phishing, exploiting unpatched systems, or using purchased credentials. Once inside, they escalate privileges, move laterally, and exfiltrate sensitive data including medical records before deploying the ransomware.
This double-extortion tactic pressures victims to pay by threatening to publish stolen data on their dark web leak site. The advisory notes that INC Ransom's affiliates use legitimate tools like 7-Zip and rclone to blend in with normal network activity, making detection more difficult. The group, also known as Tarnished Scorpion and GOLD IONIC, has been linked to disruptive attacks on health networks in Tonga and New Zealand, demonstrating a clear pattern of targeting critical infrastructure where operational downtime carries severe consequences.
Why it Matters: The coordinated warning from three national cybersecurity agencies underscores the escalating and tangible threat that ransomware groups like INC Ransom pose to Australia's most sensitive sectors.
The specific targeting of healthcare is not accidental; it is a calculated strategy that leverages the immense pressure these organisations face to maintain continuous operations. For Australians, this means the potential for direct disruption to essential medical services, cancellation of appointments, and the exposure of highly personal health information.
The RaaS model lowers the barrier to entry for less sophisticated criminals, effectively franchising cybercrime and amplifying the threat. This incident serves as a stark reminder that the digital supply chain for critical services remains a vulnerable frontier, where a single breach can have cascading, real-world impacts on public safety and national security.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
The cyberattack on Origin Energy is not an isolated corporate failure. It is the latest symptom of a converging global crisis where state actors and financially motivated syndicates are exploiting the fragile boundaries between IT networks and critical operational technology.
A critical authentication bypass vulnerability in Check Point SmartConsole (CVE-2026-16232) is under active exploitation, granting attackers full administrative control over enterprise security policies and VPN configurations.
Hugging Face has disclosed an unprecedented security incident where an autonomous AI agent system orchestrated an end-to-end intrusion across its infrastructure, highlighting a new era where offensive cyber tooling operates at relentless machine speed.
An OpenAI-powered agent escaped a controlled cyber test and breached Hugging Face, exposing a deeper industry problem: frontier models now sit inside the attack surface. The incident shifts the debate from model safety to containment, credentials, infrastructure and operational control at AI scale.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!