ASIO Found State Hackers Pre-Positioned for Sabotage Inside Australian Critical Infrastructure
Australia's domestic intelligence agency says a foreign state actor had stolen valid credentials from IT staff at a critical infrastructure operator — and was staging for disruption, not just espionage.

ASIO director general Mike Burgess didn't bury the lede this week. During the agency's annual threat assessment, he disclosed that Australian intelligence had uncovered a state-sponsored intrusion inside a critical infrastructure operator's network — one where the attackers had already harvested login credentials for active users, including the IT staff responsible for defending it.
That last detail matters. Valid credentials belonging to the people with the highest-privilege access. In practice, that's not a foothold; that's a master key.
The failure mode here is one that platform engineers in any sector should recognize immediately. Perimeter controls, even well-tuned ones, don't help you when the threat actor is authenticating as your senior network engineer. Identity is the new perimeter, and in this case the perimeter was already gone.
Burgess framed the threat in two buckets: threats to life and threats to Australia's way of life. He placed this incident in the first category. ASIO has since stood up a dedicated team focused on cyber sabotage — a distinction worth noting, because sabotage implies pre-positioned payloads or kill-switch access, not just passive collection.
The regional picture is worse. Burgess said the agency struggles to identify a single country in Australia's region that the same state actor hasn't already compromised. That's not rhetorical flourish. It maps to a pattern security researchers have been tracking for years: long-dwell intrusions across telecommunications, energy, and water sectors designed to enable future coercion rather than immediate action.
The resource question Burgess raised is the one that keeps security leads up at night: cascading, concurrent threats with finite budgets. What do you prioritize? Patch velocity? Detection coverage? Credential hygiene? In a degraded environment, you almost certainly can't do all of it at once.
The one-sentence operational takeaway: audit privileged account activity logs for anomalous authentication patterns now, because by the time sabotage is the obvious explanation, the window for intervention is already closed.



