Supply chain β›“ Supply Chain

The Australian Defence Department Third-Party Breach (November 2018)

πŸ“… 2018-11-01 🏒 not disclosed
Primary Source β†—

Incident Details

Australia’s Defence department was badly exposed to China’s hackers. The hackers are understood to have used procurement interfaces and email contact between contractors and department officials as a back door. The Australian defence department left itself badly exposed to cyber attacks due to the poor security practices of its contractors, according to a highly classified review by former federal police chief Mick Keelty. In the 18 months since the review was completed, top military officials have scrambled to harden cyber security across the extended Defence network, after intelligence agencies indicated state-sponsored hackers mainly from China were penetrating the department using holes in its IT systems.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
not disclosed
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2018-11-01 Breach occurred
  2. 2018-11-29 Publicly disclosed