Email at your own risk: Major Australian brands and institutions vulnerable to hacks

From a Chinese state-sponsored cyber attack on Australiaâs Parliament and the three biggest political parties to a ransomware attack that caused chaos at Victorian hospitals, cyber crime has proved to be a major â and often underestimated â threat.
Last week, the nation was shocked by news the Australian National University (ANU) had been compromised by a brazen email hack.
ANU vice-chancellor Brian Schmidt said the hack was not âa smash and grabâ but âa diamond heistâ, describing it as âshocking in its sophisticationâ.
Now experts have revealed that 86 of Australiaâs 100 biggest companies and only one of the nationâs top 10 universities are not even using one of the most basic forms of email protection.
With the number of attacks rising â a cyber crime is reported every 10 minutes across the nation, the Australian Cyber Security Centre announced on Monday â Australians are being warned to be cautious about how they use email.
Why email canât be trusted
Email has enjoyed extraordinary longevity as a tool for digital communication, despite many attempts to replace it.
It can be exploited by even the most novice cybercriminals, said Ryan Kalember, an executive vice president at global cybersecurity firm Proofpoint.
âYou canât necessarily trust email as a communication mechanism,â he said.
The fraudsters have capitalised on that.ââ
However, major organisations â from ASX100 companies to educational institutions, well-known consumer brands and even government â have failed to heed the warnings, Mr Kalember said.
Proofpoint researchers found that only a handful of Australiaâs major firms and universities were using one of the most basic email authentication tools â DMARC â to prevent against âidentity deceptionâ â fraudulent emails purporting to be from a trusted source.
Cyber attacks generally use one of the following three methods:
- Phishing email: An email designed to look legitimate to snare the receiver in a scam, typically tricking them into providing information or be directed elsewhere on the internet where credentials will be taken
- Malware: Refers to a range of viruses and custom software designed to get around IT controls, and give someone access to damage a system
- Ransomware: When attackers want to get into a system to either make data unreadable by turning it into code, or lock it up and refuse to give it back unless a ransom is paid.
âMost people donât realise that the email in their inbox, thereâs no technical reason that they should believe that itâs from who it says itâs from,â Mr Kalember said.
âThere are obviously ways to make that more apparent and provide some technical basis for trusting email, but very few Australian organisations do that.â
Proofpoint looked at the ASX100, and found that only 14 of Australiaâs top 100 publicly listed companies were authenticating their email.
This included âsome of the biggest retail brands out thereâ, Mr Kalember said.
Weâre continuing to see everything from the telcos to the retail brands abused to target ordinary Australians.ââ
Of Australiaâs top 10 universities, only Monash University is âactually authenticating their emailâ, Mr Kalember said.
âThe email can come from a universityâs own domain and look exactly like it was sent legitimately, with whatever link the attacker wants. And it wonât be blocked. It will just get delivered,â he said.
âAnd that is counter to everything weâve tried to teach people. But all the classic advice we give people is completely undermined if the email can look exactly like itâs supposed to.ââ
The problem is exacerbated by the fact that for many students, university is the first time they are âreally having to depend on email to do anything important,â Mr Kalember said.
That makes them perfect targets.ââ
The global losses reported due to âidentity deceptionâ emails continue to skyrocket, tallying more than $38 billion over the past financial year.
The ANU email hack
ANU revealed last week that a single email was responsible for the cyber hack that compromised its systems.
The attack occurred in November, and began after a staff member was sent an email infected with a virus.
The email only had to be previewed â no link was clicked and the message didnât have to be opened â for the hackers to access ANUâs network.
While ANU is withholding technical information about the attack, Darren Hopkins, a cyber security industry veteran of two decades, said the community needed âabsolute clarificationâ over how it happened.
I donât know how any of us are going to do business if we canât open our emails,ââ he said.
âThe way weâre being attacked now is designed to make it really difficult for us to detect it.â
On average, in cases heâs seen, hackers spend about four to six weeks undetected in a network, while about $700,000 is lost. $10.8 million was once swiped in one transaction, Mr Hopkins said.
Cyber crime is estimated to cost the global economy $2 trillion, while $600 billion is spent on protection.
Mr Hopkins said people should check theyâve activated existing security settings on their computer and email.
He urged people to also think about how they deal with information, saying anything unnecessary should be deleted.
âWhat do we leave in our mailboxes when we probably shouldnât?â he said.
âHow do we save things when we shouldnât even keep them?â
-with AAPÂ
Want to see more stories from The New Daily in your Google search results?
- Click here to set The New Daily as a preferred source.
- Tick the box next to "The New Daily". That's it.








