Supply chain
β Supply Chain
The Australian Defence Department Third-Party Breach (November 2018)
Primary Source βIncident Details
Australia’s Defence department was badly exposed to China’s hackers. The hackers are understood to have used procurement interfaces and email contact between contractors and department officials as a back door. The Australian defence department left itself badly exposed to cyber attacks due to the poor security practices of its contractors, according to a highly classified review by former federal police chief Mick Keelty. In the 18 months since the review was completed, top military officials have scrambled to harden cyber security across the extended Defence network, after intelligence agencies indicated state-sponsored hackers mainly from China were penetrating the department using holes in its IT systems.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- not disclosed
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2018-11-01 Breach occurred
- 2018-11-29 Publicly disclosed