← All news

breach

ASIO Phoned a Foreign Spy at Home to Call Off the Op

2026-06-25

Australia's spy chief Mike Burgess used his annual threat assessment to tell two stories. One should worry anyone running a network. The other is the most entertaining thing said from an intelligence podium in a while.

The intrusion nobody is naming

ASIO confirmed that nation-state hackers got inside an Australian critical infrastructure provider and made off with credentials belonging to active users, including the IT staff defending the network. They were not planting digital dynamite. They were drawing the map, keeping access warm, ready to pull the plug whenever it suited them.

Burgess would not name the country. He did say the scale of the activity is hard to overstate, and that ASIO struggles to find a single nation in the region that has not been compromised by the same apparatus. So: pick one.

The spy who answered her own phone

Now the better story. A foreign intelligence officer, posing online as a consultant, approached an Australian security clearance holder. She paid him to write a couple of reports on Pacific relations, harmless enough, then dangled more money for inside information on AUKUS.

The official got suspicious. He reported the approach, handed the cash he had been paid over to ASIO, and let officers borrow his phone. They rang the handler at home. She picked up expecting her mark, got ASIO instead, received a brisk lecture on Australian espionage law, and hung up.

Burgess suspects she may not have told her bosses the operation collapsed, so he took the opportunity to confirm it from the podium. He also mentioned, almost in passing, that ASIO is now hiring. Offensive hackers welcome.

The bit worth sitting with

The recruitment story is the one that gets the laughs, but the credential theft is the one that should stick. Even the people guarding the infrastructure network had their logins lifted. That is how these intrusions tend to work now. Nobody is breaking down the firewall. They are walking through the front door with someone else's keys.

The front door, in almost every modern intrusion, is a person. Sometimes the person is targeted directly with a recruitment pitch, the way that clearance holder was. Sometimes it is a phishing email, or a fake login page, or a phone call from a fake helpdesk. The mechanism varies. The principle does not.

What is interesting about Burgess's two stories sitting side by side is how clearly they show the same playbook at different volumes. One operator tried to buy access to AUKUS material with consulting fees. Another, presumably better-funded crew, lifted the credentials of the people running a piece of national infrastructure. Different budgets, different ambitions, same target: a human with access.

One of those stories had a happy ending because the human in question paid attention, got uneasy, and picked up the phone. The other one is still unfolding, somewhere inside a network, with the defenders' own logins.

ASIO Phoned a Foreign Spy at Home to Call Off the Op | RiskSense