• 07 3184 7575
  • September 7, 2026
  • 0 Comments

We recently reviewed new research from Nozomi Networks Labs examining operational technology (OT) and internet-connected environments across 2025. The findings are particularly relevant for Australian organisations operating critical systems — especially in healthcare and manufacturing.

According to the report, healthcare services was the most targeted industry in Australia for OT and connected environments in 2025, followed by manufacturing. At the same time, Australia ranked among the countries generating the highest number of security alerts per organisation — rising to third place in the second half of the year.

These results reflect a broader pattern: sustained attacker interest in environments that support essential services.

Australia’s Rising Alert Volume

The report tracks activity across OT and IoT environments, including industrial control systems and connected devices used in sectors such as energy, transport, and healthcare.

Australia’s ranking for alerts per organisation increased from fourth place in the first half of 2025 to third in the second half. The UK ranked first, followed by Germany.

The volume of alerts suggests that Australian organisations operating critical infrastructure are facing persistent probing, scanning, and access attempts — not necessarily immediate disruption, but preparation.

Australian security agencies have also warned about threats crossing traditional boundaries between IT and operational systems. The report highlights ongoing interest in telecommunications, energy, water, and transport networks, often involving reconnaissance and access preparation rather than direct attacks.

This shift toward reconnaissance indicates that attackers are mapping environments carefully before taking action.

The Most Common Techniques in Australia

The most frequently detected threat techniques in Australia were:

  • Default Credentials
  • Valid Accounts

Together, these accounted for more than one-third of alerts.

In practical terms, this means attackers are still exploiting unchanged factory passwords or using compromised legitimate login credentials.

Remote System Discovery and Network Service Scanning followed as common techniques — activities typically associated with attackers mapping networks and identifying remotely accessible services.

Notably, these same credential-based techniques were also prevalent in the previous reporting period. Despite growing sophistication in tooling, attackers continue to succeed with relatively simple access methods.

Wireless Exposure in Industrial Environments

The report also highlights a concerning trend in wireless security across OT environments.

Across the dataset observed:

  • 68% of wireless networks operated without Management Frame Protection
  • Only 2% used enterprise-grade authentication such as 802.1X
  • Around 98% relied on pre-shared key authentication

Pre-shared keys reduce accountability and may remain unchanged for extended periods. Once compromised, they can be reused without clear traceability.

Wireless connectivity is increasingly present in industrial settings — sometimes deployed without formal design processes or without operators fully understanding the exposure it creates.

In OT environments, unmanaged wireless access can become a quiet entry point.

Sector-Specific Targeting in Australia

Globally, transportation ranked as the most targeted industry in 2025. In Australia, however, healthcare services ranked first, followed by manufacturing.

The public sector also experienced a noticeable increase in targeting between the first and second halves of the year. The report links this spike to rising geopolitical tensions and increased nation-state and hacktivist activity.

For public sector organisations, much of the detected activity fell under Discovery tactics — consistent with adversaries exploring and preparing rather than immediately disrupting operations.

Threat Actor Activity

Scattered Spider was identified as the most active threat actor in the second half of 2025, accounting for 42.9% of actor-related alerts.

Other active groups included:

  • Kimsuky (associated with North Korea)
  • APT29 (associated with Russia)
  • CURIUM (associated with Iran)
  • Mustard Tempest (non-nation-state affiliated)

Nozomi also reports increased use of generative AI by threat actors, particularly in campaigns targeting English-speaking countries. Globally, 70% of ransomware activity targeted English-speaking nations, with the US, UK, and Canada most frequently affected.

The report suggests that geopolitical tensions involving China, Iran, and Russia will continue to shape activity trends into 2026.

Chris Grove, Director of Cybersecurity Strategy at Nozomi Networks, commented:

“Critical infrastructure has never faced a more dangerous threat landscape, and the scale and severity of attacks against it will only increase. Operators must establish clear asset visibility, leverage AI-driven security systems to detect anomalies and threats, prioritise risk-based vulnerability management, and enable intelligence sharing to keep up with evolving tactics.”

A CSB Perspective

At CSB, several themes stand out from this report.

First, many alerts are still driven by basic credential weaknesses. This reinforces the importance of strong password management, credential rotation, and identity monitoring — especially in OT environments.

Second, reconnaissance activity should not be ignored. Discovery and scanning are early-stage behaviours that often precede more serious compromise. Detecting and responding early can significantly reduce risk.

Third, wireless exposure in industrial settings is often underestimated. Asset visibility must include not only wired devices but also all wireless communication channels.

Organisations operating in healthcare, manufacturing, utilities, or public services should consider:

  • Reviewing default credential policies
  • Auditing OT and IoT asset inventories
  • Strengthening identity and access controls
  • Segmenting operational environments from IT networks
  • Monitoring for discovery and scanning behaviours
  • Reviewing wireless authentication methods

The report reinforces that OT security is no longer separate from enterprise cybersecurity. The boundary between IT and operational systems continues to narrow.

Understanding the threat landscape is the first step. The next is validating whether current controls are aligned with today’s risk environment.

Previous Post
Okta SSO Vishing Campaign Linked to ShinyHunters: What Organisations Should Understand