Last Month, Australia’s Digital Walls Came Tumbling Down.

It started with a notification. “Suspicious activity detected.”

The message lit up phones across Australia as multiple pension funds fell victim to a coordinated cyberattack. By sunrise, the damage was clear: Cyber Criminals had stolen half a million dollars from just four accounts at Australian Super alone.

But this was just the beginning. As superannuation fund managers scrambled to contain the breach, Western Sydney University was about to drop its own bombshell. Ten thousand students had their personal information exposed through the university’s single sign-on system. Student IDs, enrollment details, and demographic data – were all compromised.

You never think it’ll happen to your school,” says Tom Chen, a third-year engineering student. “Then suddenly, you’re wondering if your entire identity is up for grabs on some dark web forum.”

The final blow came from an unexpected quarter. The Fullerton Hotel Sydney, one of the city’s luxury landmarks, admitted it had fallen victim to a ransomware attack on March 24. The attack exposed a massive 148 gigabytes of data, including guests’ passports and driver’s license information.

Three cyber attacks. One week. Millions of Australians are left wondering: who’s next?

For regular Australians, the message was clear: In our connected world, no one is truly safe. Not your retirement savings. Not your university records. Not even your hotel stay.

As one Australian Super member put it, “I used to worry about losing my wallet. Now I have to worry about losing my entire life savings to someone sitting behind a computer screen halfway across the world.”

So, what is the takeaway for Australian organisations from these attacks?

Firstly, these weren’t random hits on the easiest targets. The attackers chose three pillars of modern life: Our money, our education, and our travel data. They knew exactly what they were doing. It’s not just the “easy targets” with under-resourced cyber security capabilities, nor is it just the multi-national household names. No organisation is safe. If you have data, best believe there’s a cyber criminal out there that wants it.

Every organisation, no matter its size or the complexity of its IT Infrastructure, has a responsibility to take every precaution necessary to protect their customers from a data breach. More than ever before, the Australian public are aware of the threats against their data. Treating cybersecurity measures as a compliance check-box isn’t going to cut it with your customers if savvy cyber criminals find a workaround.

What do cyber criminals actually want? It isn’t just cards. They are looking to steal something that cannot be cancelled, PII (personal identifying information). This is information they can use to commit identity theft, such as full name, date of birth, addresses, and identity numbers. If PII is stolen or thought to be stolen, or organisations are subjected to a ransomware attack, they have an obligation under legislation to report the incident to the Office of the Australian Information Commission (OAIC). There are exemptions for small businesses, but the definition of a small business is quite narrow (turnover of $3 million or less). In any case, no matter how small your organisation, you don’t want to be the reason a customer’s identity is stolen.

The recent spate of attacks hopefully has served as a wake-up call. But ultimately, it wasn’t just about the money or the data lost. It was about something more fundamental: trust. Trust in the digital systems we’ve built our lives around. Trust that’s now been shaken to its core yet again.

As Australia continues to transform itself as a digital economy and with digitised government services, the question of when the next attack will occur persists.

Don’t risk your organisation becoming the next headline. Stratica is one of Australia’s leading cyber security firms, with particular expertise in Payment Card Industry Data Security Standards (PCI DSS) Guidelines. We’re one of a few Qualified Security Assessor (QSA) firms accredited by the PCI Security Standards Council, and the only QSA firm based in Australia that is also an accredited Payments Forensic Investigator (PFI).