IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Ransomware surges 600% as AI lowers cybercrime cost

Ransomware surges 600% as AI lowers cybercrime cost

Wed, 30th Sep 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

Ensign InfoSecurity has reported that ransomware activity in Australasia rose by more than 600%, with organised crime accounting for 52% of observed threat activity in the region.

The findings point to mounting pressure on businesses in manufacturing, healthcare, and professional services, which were among the most affected sectors in Australasia.

Manufacturing and industrial companies were frequent targets, alongside the public sector, business and professional services, and healthcare. Ransom remained the leading observed effect, while organised criminal groups accounted for the largest share of threat activity, ahead of state-sponsored groups at 36% and hacktivists at 12%.

Australia also recorded the highest observed price in Asia-Pacific for stolen identity packages known as Fullz, according to the report. The highest observed listing in Australasia rose from USD $60 in 2023 to USD $280 in 2026, an increase of about 367%.

The rise suggests cybercriminals are placing greater value on identity records and related data linked to Australian organisations and individuals. Ensign, which operates in Australia through Vectra Corporation, said this reflects the attractiveness of a digitally mature and relatively wealthy economy.

Charles Spencer, General Manager, Australia and New Zealand, Vectra Corporation, linked that appeal to the profile of likely victims in the region.

"Stronger cyber maturity does not remove the incentive to attack. The region has mature, highly digitalised and well-insured organisations, connected through extensive outsourcing and cloud infrastructure. That makes sectors like health, manufacturing and professional services particularly valuable to threat actors," said Charles Spencer, General Manager, Australia and New Zealand, Vectra Corporation.

Access routes

Attackers are shifting to indirect entry methods as companies strengthen perimeter defences, the report found. Sales of initial access rose fivefold, while supply-chain compromise and insider access became more important entry points.

Trusted relationships are also becoming a larger source of exposure, with attackers using suppliers, contractors, and insiders to gain entry into better-defended organisations. The pattern is particularly significant for manufacturers, many of which operate through extended supplier networks, outsourced services, and shared digital platforms.

Spencer said companies need to look beyond their own systems when assessing cyber risk.

"Attacks do not always need to breach a well-defended organisation directly. A supplier, contractor or compromised insider can provide a trusted pathway into multiple organisations. As threat actors increasingly combine financial, intelligence and disruptive motives, organisations need to understand where they sit within a wider ecosystem, not just how secure their own perimeters appear," said Spencer.

AI assessment

The report also examined how frontier artificial intelligence could reduce the cost of cyberattacks. Ensign tested 10 generally available AI models across eight stages of a simulated enterprise attack in an isolated cyber range designed to resemble a university network protected by widely used security controls.

The models were assessed over 160 runs after a broader review of more than 150 models. The exercise measured whether the systems could carry out tasks across a full attack chain, including breaching a portal, compromising a database, moving through a network, stealing credentials, moving laterally between systems, attempting to bypass detection tools, and establishing persistence.

According to the assessment, several leading models were able to execute multiple stages of a realistic cyberattack. All tested models were able to steal credentials and move laterally between systems to some degree, while none were able to evade detection tools with confidence.

Ensign said one Eastern model, Z.AI's GLM-5.2, produced offensive performance comparable to GPT-5.6 Sol at about one-fifth of the operating cost. It also found that open-source Eastern models delivered higher offensive output per dollar than their Western counterparts.

The convergence in model performance means price may become a bigger factor for threat actors than technical differences between systems, Ensign said. That, in turn, could lower barriers to entry for cybercrime by making sophisticated tools cheaper and easier to use at scale.

For businesses in manufacturing and other exposed sectors, the findings add to concerns about a regional threat environment already shaped by ransomware, criminal marketplaces, and supply-chain vulnerabilities. The report suggests attackers are finding more ways to reuse access, automate reconnaissance, and expand attacks across connected organisations.

"Frontier AI is fundamentally changing the speed, scale and economics of cyberattacks. If it can automate reconnaissance, identify vulnerabilities and help threat actors repeat those steps at a lower cost, it gives attackers more opportunities to find a way in. For organisations, the findings reinforce the need to strengthen cybersecurity foundations including the regular scanning and patching of critical internet-facing assets, and continuously testing and validating defences against the latest AI models. With frontier AI capabilities advancing on a roughly two-month cycle, security controls will need to evolve just as quickly," said Spencer.