[Blog](/blog)

Show links

Resources

[Blog](/blog)

[Breaches](/breaches)

[eBooks, reports, & more](/resources)

[Events](/events)

[News](/news)

[Cybersecurity](/category/cybersecurity)

Show links

Categories

[Attack Surface Management](/category/attack-surface-management)

[Company News](/category/company-news)

[Compliance and Regulations](/category/compliance-and-regulations)

[Cybersecurity](/category/cybersecurity)

[Data Breaches](/category/data-breaches)

[DevOps](/category/devops)

[Human Cyber Risk](/category/human-cyber-risk)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

[Third-Party Risk Management](/category/third-party-risk-management)

[Vendor Risk Management](/category/vendor-risk-management)

[Australia and the Risk of a Russian Cyber Attack: Are You Ready?](/blog/how-australian-businesses-can-prepare-for-a-russian-cyberattack)

Publish date

June 26, 2025

{x} minute read

# Australia and the Risk of a Russian Cyber Attack: Are You Ready?

[Get a demo](/contact-sales)

[Free trial](/demo)

[Download the PDF guide](#)

[Free trial](/demo)

Written by

[Edward Kost](/team/edward-kost)

Senior Cybersecurity Writer

Edward is a cyber writer with a mechanical engineering background. His work has been referenced by academic institutions and government bodies.

Reviewed by

[Kaushik Sen](/team/kaushik-sen)

Chief Marketing Officer

Kaushik has a background in software engineering, enterprise solution architecture, and data analytics. He brings a unique, data-driven perspective to cybersecurity education.

Table of contents

Free resource

###

[Download now](#)

Given Russia's reputation for highly-sophisticated [cyberattacks](https://www.upguard.com/blog/cyber-attack), the country's invasion of Ukraine has sparked justified fears of an imminent global cyberwar.

While, for the time being, Putin’s cyber efforts against Ukraine are surprisingly restrained, this may not be the case for other countries. Russia appears to be mounting a cyberattack offensive against nations that have voiced their disapproval of Ukraine’s invasion through economic sanctions - a dampened fulfillment of Putin’s ominous threat of punishing [any country that interferes with his efforts](https://www.nytimes.com/live/2022/04/28/world/ukraine-russia-war-news). 

> “Whoever tries to impede us, let alone create threats for our country and its people, must know that the Russian response will be immediate and lead to the consequences you have never seen in history.”\
> ‍\
> *Vladimir Putin\
> President of Russia*

The most recent evidence of this [cyber threat](https://www.upguard.com/blog/cyber-threat) being exercised occurred on Tuesday, 1 March. Just days after joining the economic sanction responses of its Western allies, Toyota was forced to [halt all plant operations in Japan](https://www.forbes.com/sites/peterlyon/2022/02/28/russia-is-suspect-in-cyberattack-that-will-force-toyota-to-shut-down-plants-in-japan) following a suspected [supply chain attack](https://www.upguard.com/blog/supply-chain-attack). While Russia hasn’t officially claimed responsibility, its involvement can be inferred from the sinister remarks of Mikhail Yurlevich Galuzin, the Russian ambassador to Japan.

[Learn how to comply with CPS 230 >](https://www.upguard.com/blog/apra-cps-230-compliance-guide)

> “Should Japan impose sanctions on Russia, there would be consequences.”\
> ‍\
> *MIkhail Yurlevich Galuzin\
> Russian Ambassador to Japan*

[Since Australia has also implemented economic sanctions](https://www.reuters.com/world/asia-pacific/australia-imposes-more-sanctions-russia-criticises-chinas-response-2022-02-25/) against Russia, Australian critical infrastructures and businesses are at a heightened risk of being added to Russia’s cyberattack firing line.

In recognition of this, the Australian Cyber Security Center (ACSC) has issued an urgent advisory for Australian businesses to elevate their [security posture](https://www.upguard.com/blog/security-posture).

The following roadmap can help you achieve a standard of [cyber resilience](https://www.upguard.com/blog/cyber-resilience) with the highest potential of defending against nation-state attacks.

## Implement an Essential Eight Framework

According to the ACSC, [the Essential Eight](https://www.upguard.com/blog/essential-eight-tprm) ensures Australian businesses meet the minimum recommended [cybersecurity](https://www.upguard.com/blog/cyber-security) standard. This framework strengthens the cyber resilience of an IT network through eight strategies:

* Application control;
* Patch applications;
* Configure Microsoft Office macro settings;
* User application hardening;
* Restrict administrative privileges;
* Patch operating systems;
* Multi-factor authentication; and
* Regular backups.

[*Learn more about the Essential Eight.*](https://www.upguard.com/blog/essential-eight)

## Detect and Address Supply Chain Security Risks

Since January 14, 2022, Russia has launched a series of cyberattacks targeting Ukrainian government websites. Many of these attacks are believed to have been facilitated by a [vulnerability](https://www.upguard.com/blog/vulnerability) in [OctoberCMS](https://www.upguard.com/security-report/october-cms), a content management solution used by the Ukrainian government.

The vulnerability tracked as [CVE-2021-32648](https://nvd.nist.gov/vuln/detail/CVE-2021-32648) is being used as an [attack vector](https://www.upguard.com/blog/attack-vector) for a destructive new family of malware called [WhisperGate](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/).

[*Learn more about CVE-2021-32648.*](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/)

Thanks to its malevolent efficiency, the supply chain attack is a well-worn tactic in Russia’s cyberattack arsenal. Instead of confronting fortified walls around common entry points, it’s much simpler, instead, to slip through the backdoor by compromising a third-party vendor in a victim’s supply chain.

Supply chain security risks can be instantly discovered with an [attack surface monitoring solution](https://www.upguard.com/product/vendorrisk).

The most comprehensive evaluation of the third-party threat landscape is achieved by combining attack surface monitoring with security questionnaires. Security questionnaires surface commonly overlooked third-party risks buried inside a supplier’s ecosystem.  

UpGuard offers a library of security questionnaires that map to popular cybersecurity frameworks, including the Essential Eight.

[*Click here to try UpGuard for free for 7 days.*](https://bit.ly/3sGxloe)

## Familiarise Yourself with Russia’s Latest Malware Campaigns

Get familiar with the [malware](https://www.upguard.com/blog/malware) campaigns Russia is currently deploying. Each item in the list below links to a resource detailing mitigation strategies. 

* [WhisperGate ](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/)
* [HermeticWiper](https://www.cisa.gov/uscert/ncas/alerts/aa22-057a)
* [HermeticWizard](https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/)
* [IsaacWiper](https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/)
* [Conti Ransomware](https://www.cyber.gov.au/acsc/view-all-content/advisories/ransomware-profile-conti)

Conti ransomware is a particularly dangerous strain of [ransomware](https://www.upguard.com/blog/ransomware) due to the speed with which it encrypts data and spreads to other systems. Fortunately, the Conti source was [recently leaked](https://www.bleepingcomputer.com/news/security/conti-ransomware-source-code-leaked-by-ukrainian-researcher/) by a Ukranian researcher. This invaluable intelligence could help security teams predict and intercept the Conti ransomware attack pathway.

* For more information about the lifecycle of Russia's latest destructive malware campaigns, [refer to this resource by Microsoft](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/).
* For more details about Tactics, Techniques, and Procedures (TTPS) that could be associated with Russia’s malware campaigns, [refer to this resource by the ACSC](https://www.cyber.gov.au/acsc/view-all-content/advisories/2022-02-australian-organisations-should-urgently-adopt-enhanced-cyber-security-posture#:~:text=Tactics%2C%20Techniques%2C%20and%20Procedures%20\(TTPs\)).
* For more information about how Australian businesses can improve their cyber resilience, visit [Cyber.gov.au](https://www.cyber.gov.au/).

## Detect and Shut Down all Data Leaks

[Data leaks](https://www.upguard.com/blog/data-breach-vs-data-leak) are overlooked exposures of [sensitive data](https://www.upguard.com/blog/sensitive-data) that make data breaches easier for cybercriminals. These leaks could be caused by software vulnerabilities or misconfigurations facilitating unauthorized access to sensitive resources - such as the significant [Microsoft Power Apps data leak in 2021](https://www.upguard.com/breaches/power-apps).

Like supply chain attacks, data leaks allow cybercriminals to circumvent formidable security controls by exploiting a backend vulnerability. Because of this convenience, data leak exploitation should be regarded as a probably tactic in Russia’s bag of cyberattack tricks and urgently addressed.

## Speed is Critical

Australian businesses need to act fast. Russia’s probable cyber attack on Japan demonstrates how quickly the nation can punish those that have joined the chorus of economic sanctions.

To learn how UpGuard can help you accelerate the improvement of your security posture, [get in touch with us now](https://bit.ly/3sGxloe)!

Free resource

###

[Download now](#)

## Related posts

Learn more about the latest issues in cybersecurity.

Cybersecurity

#### [Left Unsupervised: 10 Times Access Outlived Its Authorization](/blog/10-times-access-outlived-authorization)

Access granted once shouldn’t mean access forever. Read more on how unmonitored access caused 10 of these real-life breaches and what they taught us.

[](/team/revashni-moodley)

[Revashni Moodley](#)

August 25, 2026

Cybersecurity

#### [Surviving a LockBit Ransomware Attack: The ROI of Visibility](/blog/surviving-a-lockbit-ransomware-attack)

Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

June 1, 2026

Cybersecurity

#### [Top 10 Security Events of 2025](/blog/top-security-events-of-2025)

Recap the ten most impactful events that reshaped the cybersecurity industry this year and the critical lessons each had to teach us. Read more here.

[](/team/revashni-moodley)

[Revashni Moodley](#)

January 7, 2026

Cybersecurity

#### [Risk Automations: The Shift From Catch-Up to Command](/blog/risk-automations-shift-catch-up-to-command)

Connect intelligence to system execution with Risk Automations, your new resolution layer for risk. Reduce remediation from hours to seconds - read more.

[](/team/revashni-moodley)

[Revashni Moodley](#)

December 1, 2025

Cybersecurity

#### [Shai-Hulud's True Lesson for CISOs: A Crisis of Communication](/blog/shai-hulud-lesson-for-cisos)

Shai-Hulud was driven by a communication crisis between security and engineering. Get a CISO's perspective on how to finally bridge this gap.

[](/team/phil-ross)

[Phil Ross](#)

September 3, 2026

Cybersecurity

#### [UpGuard’s Updated Cyber Risk Ratings](/blog/cyber-risk-ratings-2024)

Discover UpGuard's updates to its cyber risk ratings, including enhanced risk categorization and an improved scoring algorithm.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

July 4, 2025

[All posts](/blog)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](/contact-sales)

[Free trial](/demo)
