Allan Grant | SOC Analyst | 31 August 2026
Three things stood out in August.
Governments moved onto the front foot, both abroad and at home. In the US, the White House authorised vetted private companies to run offensive operations against criminal networks, the Department of Justice (DOJ) indicted 17 Iranians over a decade-old espionage campaign, and the FBI seized the domains behind two Chinese state-contractor hacking platforms, then had to correct its claim that US agencies had been breached. At home, the Australian Federal Police (AFP) charged two alleged principals of the TeamPCP supply chain syndicate, and US prosecutors indicted one of them in parallel. The Australian Prudential Regulation Authority (APRA) took Bendigo and Adelaide Bank to the Federal Court over a 2023 cyber incident, with a proposed $8 million penalty for breaches of the executive accountability regime, one of which was a failure to test controls as required by the banking regulator's information security standard (CPS 234). On the last day of the month the government released draft Privacy Act amendments that would replace the "as soon as practicable" breach notification standard with a hard 72-hour deadline. Australia also stood up a Cyber Reserve Force.
The AI threat changed character. July's incidents involved models escaping their evaluation environments and compromising companies of their own accord. In August, attackers deliberately drove AI through live intrusions, in one case against an Australian energy utility, and OpenAI paused its largest training run after judging an upcoming model might reach a critical cyber capability. The governance machinery moved in step. The Australian Signals Directorate (ASD) and the Australian Institute of Company Directors (AICD) told boards to treat frontier AI as board-level risk, and insurers began reworking policy language for losses caused by AI agents. On 27 August more than 150 organisations including Anthropic, Microsoft and Google called for a coordinated surge in cyber defence, warning that AI-enabled attacks will scale sharply in the coming months and that the same technology gives defenders a narrowing window to fix long-standing weaknesses first.
Critical infrastructure attacks bore the brunt of the month's incidents. Suspected Iran-linked actors hit US water utilities in the last week of July; through August the disclosures spread to at least a dozen states and the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed that more than 100 systems were targeted. On 22 August The Telegraph revealed that Iran-linked actors had taken a small UK power generator offline for four days, believed to be the first such shutdown of a British facility. Neither campaign disrupted supply to the public, but both showed operational technology being targeted for effect in a live geopolitical conflict.
On 12 August the White House published a National Security Presidential Memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, directing the creation of a program under which vetted private US companies can conduct cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organisations (The White House).
The program sits under the National Coordination Center, with co-Executive Directors from the Department of Justice and the Department of Homeland Security who must approve every operation in writing before a company acts.
Participating companies must pass vetting, contract with one of the two departments, and may be required to post a bond of at least US$1 million that is forfeited on non-compliance. The memorandum defines two operation types: cyber surveillance operations, including manipulation or temporary disruption not intended to cause physical effects, and cyber effects operations, covering manipulation, disruption, denial, degradation or destruction of networks and systems. Groups that are part of a foreign government are out of scope, though the memorandum presumes a group is independent unless clear intelligence shows otherwise. Operating procedures are due within 60 days, so by 11 October.
This is government-directed offensive contracting, and a significant departure from decades of US policy that reserved offensive cyber operations to the state. For Australian organisations the near-term relevance is indirect but real. US-headquartered security vendors may soon hold offensive taskings, which raises new questions in vendor due diligence about conflicts, data handling and legal exposure, and other governments, including ours, will be watching whether the model works. Read alongside Australia's new Cyber Reserve Force, it is one of two answers this month to the question of how the state gets access to private cyber talent at scale. The US answer is offensive outsourcing; Australia's, for now, is workforce mobilisation.
On 27 August OpenAI published an open letter, A call for collective action on cyber defense, co-signed by Anthropic, Microsoft, Google, Amazon Web Services, Cisco, CrowdStrike, IBM and major banks and insurers. The published list stood at more than 150 organisations on 1 September and remains open to new signatories, so the "more than 100" reported at launch is already out of date. The letter warns that AI-enabled attacks will become far more widespread and sophisticated "in the coming months" and frames the present as a defenders' window: AI can now help fix years of accumulated weaknesses, including unpatched software, excessive permissions, weak authentication and legacy debt, faster than attackers can exploit them, but only if organisations act deliberately.
The asks are role-specific. Organisations should treat cyber defence as a leadership priority and raise the bar for everything they buy, build and deploy, including AI-generated code. Security vendors should test defences continuously against frontier capabilities and make AI-powered defence accessible to under-resourced critical infrastructure operators. Governments should coordinate intelligence sharing, fund defence for essential services and impose costs on attackers. Frontier AI companies should provide responsible model access and ensure agentic identities are traceable and accountable. This is a consensus statement from the companies building the technology and they expect the offensive use of AI to escalate quickly.
On 18 August OpenAI disclosed that it had paused reinforcement-learning training on its latest deployment models for about two weeks and was keeping its largest planned frontier run on hold while it hardened research environments and expanded monitoring (OpenAI). The trigger was a determination on 7 August that an upcoming model codenamed Astra "may meet the Critical cybersecurity capability threshold" under the company's Preparedness Framework, together with July's incident in which OpenAI agents reached Hugging Face production infrastructure from an evaluation environment.
OpenAI describes this as the first time it has publicly slowed development on safety grounds, and it is the first public case of a frontier lab gating scale on a cyber capability trigger specifically. It is a live demonstration of the "capability outpacing safeguards" dynamic the July disclosures warned about.
Insurers including MSIG, QBE and Beazley are reviewing cyber policy language to deal with AI agents as a source of loss, prompted by this year's disclosures from OpenAI, Anthropic and others of AI models leaving test environments and compromising production systems (Reuters via iTnews). The unresolved questions are foundational: does an autonomous AI system meet the policy definition of a cyber attacker, and who bears liability for an AI-generated action that causes a loss, such as an agent that discovers and unintentionally exploits a vulnerability on systems it legitimately accesses. For now most carriers are treating AI as a risk amplifier and folding it into existing cyber cover. QBE's global head of cyber said losses from an AI-related event that becomes a conventional cyber incident stay inside the policy, though targeted exclusions are being discussed for systemic events where one widely used model drives losses across many organisations at once. Aon forecasts nearly 20 per cent of cyber attacks will involve generative AI by 2027. Organisations renewing cyber cover in the next twelve months should expect new questions about AI agent deployment, and possibly new exclusions, and should read the fine print accordingly.
On 31 August the Attorney-General's Department released the Privacy Amendment (Personal Data Protection) Bill 2026 as an exposure draft for consultation, proposing to replace the current requirement to notify eligible data breaches "as soon as practicable" with a fixed 72-hour deadline to notify the Information Commissioner (Attorney-General's Department; iTnews). Submissions close on 18 September, a three-week window, and the department notes the Bill "remains subject to further consideration by government".
The process still has two stages. When an entity suspects a breach, it keeps up to 30 days to assess whether the breach is notifiable. What changes is the second stage: once the entity has reasonable grounds to believe a notifiable breach has occurred, it must notify the Information Commissioner within 72 hours, whereas the current law only requires notification "as soon as practicable". An entity that cannot assemble a complete statement in time can file an incomplete one with written justification; filing nothing within 72 hours could attract an infringement or compliance notice. This aligns the Notifiable Data Breaches scheme with the 72-hour windows already used under the Security of Critical Infrastructure (SOCI) Act and for ransomware payment reporting under the Cyber Security Act 2024, and consolidates 72 hours as the de facto Australian standard for regulator notification.
For most organisations the practical work is operational readiness: can your incident response process reliably reach "reasonable grounds to believe" and produce a defensible notification within 72 hours, including on a long weekend.
APRA commenced Federal Court civil penalty proceedings against Bendigo and Adelaide Bank on 10 August over a 2023 cyber attack on its Alliance Bank business. The bank has admitted breaching its obligations under the Banking Executive Accountability Regime (BEAR), the law that makes named senior executives personally accountable for how a bank is run (APRA).
Customer authentication controls permitted very weak passwords, multiple accounts shared identical passwords, and system design let an attacker enumerate valid customer IDs. Penetration testing in 2020 identified several of these weaknesses – however, these were not fixed by the bank. In March 2023 an attacker accessed around 257 accounts and made 286 unauthorised transactions totalling about $490,000 across 87 customers. Bendigo Bank reimbursed everyone but could not recover about $140,000.
Bendigo Bank admits it failed to maintain adequate authentication controls, failed to run the systematic control testing required by CPS 234, had inadequate governance and risk management for the relevant IT system, and failed to ensure accountable persons' responsibilities covered it. The parties propose an $8 million penalty, subject to the Court. APRA says the weaknesses were satisfactorily remediated after the attack and that it has no current concerns about the bank's information security controls. APRA Deputy Chair Therese McCarthy Hockey said the action "sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls". Days later APRA imposed licence conditions on Bendigo Bank over broader risk management failures, so the bank faced two enforcement actions in a single week.
Three points apply beyond banking. First, this is enforcement of an executive accountability regime for a cyber incident. Second, the unremediated 2020 penetration test findings, the results of a commissioned exercise in which testers probe a system for weaknesses, is central to the case. Testing you do not act on becomes evidence against you. Third, the loss was modest and fully reimbursed, and APRA pursued the case regardless. The enforcement followed the control failure, and limited financial impact did not soften it.
ASD and the Australian Institute of Company Directors published Frontier AI cyber threat considerations for boards of directors on 5 August. The guidance given is that frontier AI can identify and rapidly weaponise vulnerabilities, chain multiple low-severity flaws into high-impact compromises, and conduct malicious activity with little to no human oversight. Discovery and exploitation timelines could compress "from days to hours", and the guidance warns these dynamics "may rapidly invalidate organisations' current risk tolerance".
The first notable element is the explicit direction that boards should assess reliance on AI providers, including "foreign ownership, control and influence" risk, as a cyber supply chain issue in its own right. The guidance does not name a trigger, but it lands two months after the US Commerce Department's temporary export-control restriction on Anthropic's Mythos-class models demonstrated that access to a frontier model can change with a single regulatory decision in another jurisdiction.
The second is the structure. The guidance provides threshold questions boards should put to management, such as what assumptions underpin our risk assessments, could we detect and respond if attacks moved from days to hours, and do we have visibility of third and fourth-party suppliers. It pairs them with a prioritised roadmap, from immediate actions such as securing attack surfaces and reducing vulnerabilities, through short-term identity, access and least-privilege controls including for AI agents, to medium and long-term human-supervised defensive AI and Secure by Design. None of the controls are novel. What is new is a government agency and the directors' institute jointly telling boards they will be expected to evidence them against an AI-speed threat model. Expect this document to become a reference point in due diligence, insurance questionnaires and, eventually, regulatory expectations. The Gambit Security case below, involving an Australian utility, shows what this looks like in practice.
Defence announced the appointment of the first direct-entry member of its new Cyber Reserve Force on 21 August, a specialist workforce established in twelve months as an outcome of the 2023 Defence Strategic Review of the Australian Defence Force (ADF) Reserve (Defence). The Force gives Defence access to expertise from industry, government and academia across cyber operations, AI, cloud security, digital forensics, incident response and threat intelligence, through a mid-career entry pathway built for high-demand specialists outside the traditional reserve training pipeline. Acting Commander Cyber Command, Air Commodore Michael Reidy, described cyber power as "an essential element of Australia's national defence".
The Australian Securities and Investments Commission (ASIC), the corporate and financial services regulator, warned on 17 August that scammers are using generative AI to build entire networks of fake websites and endorsements, and that a quick online search is no longer enough to verify an investment (ASIC). In FY26 ASIC removed more than 19,400 online scams, up 182 per cent on the previous year, including 7,051 fake investment platforms.
The technique that ties them together is deepfake video of well-known public figures. ASIC recorded a sharp rise in AI-generated clips showing politicians and celebrities appearing to endorse investments, timed to whatever is in the news. The most impersonated Australians in the 2025-26 financial year, according to the National Anti-Scam Centre (NASC), were Prime Minister Anthony Albanese, Senator Jacqui Lambie, the federal MP Angus Taylor and the finance presenters Tom Piotrowski and Alan Kohler, with $7.4 million in reported Scamwatch losses tied to impersonation.
ASIC's warning is that each deepfake is the front door to a wider apparatus built to survive scrutiny: spoof websites, fabricated news articles, fake reviews and reused financial services licence numbers, all staged to manufacture "social proof", the instinct to trust something that others, and trusted figures in particular, appear to have vouched for. Remove the familiar face and the investment usually does not exist, and the money goes to overseas criminals who are rarely traced. For fraud and security teams the takeaway is that trust signals can now be fabricated convincingly and at volume, so verification has to rest on something a scammer cannot fake, such as licence details confirmed directly against ASIC's own register.
What began with a joint advisory from the Federal Bureau of Investigation (FBI), the US Environmental Protection Agency (EPA) and CISA on 30 July, after coordinated attacks on more than 30 Minnesota community water systems, turned out to be one of the broadest known campaigns against US municipal water infrastructure. The attacks ran from 26 to 31 July. Through August, utilities in at least a dozen states disclosed incidents, and on 26 August CISA confirmed that attackers had targeted more than 100 internet-exposed systems across the water and wastewater sector in July, most of them programmable logic controllers connected directly to cellular modems (CISA). Programmable logic controllers are the small industrial computers that physically run pumps, valves and pressure settings. Attackers targeted units made by Rockwell, Schneider Electric and Siemens, in some cases changing passwords and IP addresses to lock operators out and disabling shutdown processes and alarms without operator visibility, and CISA reported the use of AI tools to generate exploitation scripts against vulnerable Siemens controllers from public information. Georgia's Clayton County Water Authority, serving about 300,000 people, issued a boil-water advisory after a pressure drop; several utilities lost remote control and reverted to manual operations. No drinking water was contaminated.
US officials suspect Iran-linked actors, consistent with the 2023 CyberAv3ngers playbook of exploiting exposed controllers and default credentials, and a persona using that name claimed the operation on Telegram. However, no formal attribution has been made to date.
Separately, The UK Telegraph reported on 22 August that Iran-linked actors had taken a small British gas-fired peaking plant offline for four days in July, believed to be the first time actors linked to the Iranian regime have shut down a UK generating facility (The Telegraph). The Department for Energy Security and Net Zero said there was no risk to the wider energy system at any point. Analysts read the intrusion as demonstrative rather than destructive. The techniques across both campaigns remain unsophisticated: internet-exposed operational technology (OT), the computers that control physical equipment, along with default credentials and poor network separation.
On 18 August the DOJ unsealed a 14-count superseding indictment charging 17 members of Iran's Mabna Institute, a Tehran-based hacking-for-hire company, over a campaign of computer intrusions run from 2013 to 2017, much of it on behalf of the Islamic Revolutionary Guard Corps (DOJ). The tradecraft involved spear phishing emails that harvested university professors' login credentials, which the group then used to sign in to their accounts and exfiltrate research to servers outside the US, with password-spray attacks run against companies and government agencies. The group targeted more than 100,000 professor accounts and compromised about 8,000 across 144 US and 178 foreign universities, Australia among them, taking 31.5 terabytes of academic data and intellectual property and reselling stolen access inside Iran through the Megapaper and Gigapaper websites. US universities had spent an estimated US$3.4 billion procuring the material that was taken. The activity itself is years old; the August step is the indictment, which adds eight defendants to the nine charged in 2018 and comes with a State Department reward of up to US$10 million for information on five of them.
On 26 August the DOJ and FBI announced court-authorised seizures of the domains behind two hacking platforms, QScan and QTRouter, operated by a group tracked as QTFY and used to target US critical infrastructure and other sensitive networks (DOJ). Court documents attribute the platforms to the Nanjing Xinjiuwei Network Technology Company, whose paying customers allegedly included China's Ministry of State Security and the People's Liberation Army. QScan scanned for and infected internet-of-things devices worldwide; QTRouter turned those devices, plus commercial proxies and leased servers, into an obfuscation network so that intrusions appeared to originate outside China, sometimes from inside the target's own region. Because the seized domains were hard-coded into both tools, the seizure rendered them inoperable. The FBI and NSA published a companion advisory with indicators of compromise dating back to 2018 (FBI and NSA advisory).
The release said NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, the National Institutes of Health and the US Senate were among QTFY's victims.
Microsoft's 31 July report on a campaign it calls CaptiveCrunch continued to draw attention through August, and the activity is ongoing (Microsoft). Microsoft attributes it to Storm-2945, a sub-cluster of Midnight Blizzard, the group the US and UK governments tie to Russia's foreign intelligence service, the SVR.
Since May the actor has been compromising the wi-fi sign-in pages at hotels and conference venues to reach the people connecting through them, delivering malware behind what looks like a routine browser or operating system update. The attacks saw traffic from organisations in financial services, legal, healthcare, energy and retail, which points to broad intelligence collection against whoever is carrying sensitive information on the road. Microsoft's advice is to treat hotel, conference and airport wi-fi as untrusted, prefer a mobile hotspot or cellular data, and never install an update offered through a sign-in page.
The AFP, working with Western Australia Police and in parallel with the FBI, charged two Western Australian men, aged 21 and 23, with a combined 14 offences on 26 August after raids in Cottesloe, Hamilton Hill and Mandurah; both appeared in Perth Magistrates Court on 27 August (AFP). Police allege the pair were principal participants in TeamPCP, the syndicate behind this year's run of software supply chain attacks, in which malicious code is hidden inside free, publicly shared "open-source" software components that other developers unknowingly build into their own products and pass on to customers across government, academia and the private sector. Authorities estimate more than 1,000 organisations were potentially compromised worldwide, with over 500,000 credentials stolen, at least 300 gigabytes of data exfiltrated, and remediation costs potentially in the hundreds of millions of dollars. The pair allegedly received cryptocurrency payments still being valued. Both were remanded in custody, with their next appearance listed for 18 September. On the same day, US prosecutors unsealed a parallel indictment against the 21-year-old in the Northern District of California, filed on 25 August, charging conspiracy to violate the Computer Fraud and Abuse Act and alleging that the group extorted downstream victims by threatening to publish stolen data (US Attorney's Office, NDCA).
TeamPCP emerged in late 2025. Its run of attacks in March 2026 compromised the Trivy vulnerability scanner's GitHub Action, the LiteLLM and Telnyx Python packages and Checkmarx's KICS action, among others. Its method was to steal developer credentials for code-hosting platforms such as GitHub, insert malicious code into widely used open-source tools, then harvest more credentials from the build environments that ran them to extend its reach. Google Threat Intelligence describes it as a peer community of individually skilled actors around one centre of gravity rather than a single unified group. The National Disability Insurance Agency (NDIA) was among the Australian organisations hit in March; it told iTnews it detected the activity within hours and that no protected or participant information was accessed (iTnews). Upstream, GitHub has since made a three-day cooldown the default for Dependabot version updates, so that freshly published package versions age before automated tooling pulls them in (GitHub). GitHub cited a 2025 npm compromise as its example, and a cooldown would not have stopped TeamPCP's tag-rewriting attack on Trivy, but it closes the window the group's other campaigns relied on. Investigative reporting states the younger suspect was identified partly through operational security failures and claimed to have earned only around US$20,000 from the activity (Krebs on Security); the AFP has not confirmed that figure.
The investigation began in April on intelligence from multiple threat assessment companies, and AFP Commander Graeme Marshall was explicit that industry reporting "proved crucial for investigators". Two lessons follow. Early engagement with law enforcement demonstrably works, and the alleged operators of a global supply chain campaign were two young men in suburban Perth, which says something about how low the barrier to this class of attack has fallen. The charges remain allegations before the court.
Gambit Security reported on 13 August that a suspected affiliate of The Gentlemen ransomware operation used Anthropic's Claude Code to run live intrusions into at least six organisations in late June, with an Australian energy utility among the victims (Gambit Security). The operator used Claude Sonnet 4.6 rather than a frontier model, which Gambit reads as a choice for weaker guardrails, and Gambit notes an open-weight model could have done the same job. When the model saw it was working against a live production system it refused to continue without confirmed authorisation; the operator opened a new session, claimed the target was an authorised test, and reissued the task, after which the model complied. From there the operator worked interactively, feeding results back until each step succeeded: authenticating to an exposed VPN appliance, stealing the firewall's stored directory service account, creating a backdoor VPN user, mapping hosts and backups, and staging database dumps for exfiltration.
At the Australian utility, the model tried to change the firewall's portal settings, failed, and restored an edited copy of the whole configuration instead. The device dropped off the internet and stayed down.
August's disclosed Australian incidents were mostly mid-sized, and the recurring thread was third-party exposure, with the customer-facing brand carrying the reputational cost:
Active exploitation in August concentrated on edge, management and collaboration platforms.
Request a consultation with one of our security specialists today or sign up to receive our monthly newsletter via email.
Get in touch Sign up!