Overview
- ASD responded to 1,200 cyber incidents in 2024–25, an 11% increase on the previous year.
- Compromised or stolen credentials accounted for 42% of incidents affecting large organisations, government, academia and supply chains.
- Malicious activity against regulated critical infrastructure was recorded more than 190 times, roughly a 111% rise, with healthcare ransomware incidents doubling and succeeding in 95% of ASD‑responded cases.
- State‑linked actors, including China‑linked APT40, were observed exploiting home routers and smart devices to mask operations, with one concealed network exceeding 260,000 compromised devices.
- Financial impacts worsened, with average losses of $33,000 for individuals and about $202,700 per incident for large businesses, as the report warns AI is accelerating attack scale and speed.