SYDNEY, 30 September 2026 – The seventh edition of Ensign InfoSecurity’s 2026 Cyber Threat Landscape Reportreveals that ransomware activity increased by more than 600% across Australasia, with organised crime accounting for 52% of observed threat activity, the highest concentration across Asia-Pacific. Business & Professional Services, Healthcare and Manufacturing & Industrial also emerged as newly observed most-affected industry groups.

Ensign InfoSecurity (“Ensign”) operates in Australia through Vectra Corporation (“Vectra”), its wholly owned Australian subsidiary.

Regional trends show an intensifying threat landscape across Australasia

The report found that organised crime was responsible for the largest share of observed threat activity in Australasia, followed by state-sponsored groups at 36% and hacktivists at 12%.

Ransom remained the leading observed effect across the region. Business and Professional Services, Healthcare, and Manufacturing and Industrial were among the most targeted industry groups, with healthcare facing distinct targeting by financially motivated ransomware groups.

The report also found that Australia recorded the highest observed Fullz listing across the Asia-Pacific region. The highest observed Fullz listing in Australasia increased from USD60 in 2023 to USD280 in 2026, representing an increase of approximately 367%. The growing premium reflects the country’s position as one of Asia Pacific’s resource-rich and high-value digital economies, where high-quality identities, financial information and enterprise data command greater value for cybercriminals.

“Stronger cyber maturity does not remove the incentive to attack. The region has mature, highly digitalised and well-insured organisations, connected through extensive outsourcing and cloud infrastructure. That makes sectors like health, manufacturing and professional services particularly valuable to threat actors,” said Charles Spencer, General Manager, Australia and New Zealand, Vectra Corporation.

Beyond the rise in ransomware and organised crime, the report shows attackers are increasingly looking for alternative pathways into organisations as cyber defences strengthen.

Additional Australasia findings include:

●      Sale of initial access increased fivefold, highlighting growing demand for ready-made access into organisations.

●      Supply-chain compromise and insider access are increasingly important initial-access pathways, as attackers seek routes around stronger organisational defences.

●      Trusted relationships are becoming a key source of exposure, with attackers looking beyond well-defended organisations to their wider ecosystems.

“Attacks do not always need to breach a well-defended organisation directly. A supplier, contractor or compromised insider can provide a trusted pathway into multiple organisations. As threat actors increasingly combine financial, intelligence and disruptive motives, organisations need to understand where they sit within a wider ecosystem, not just how secure their own perimeters appear,” added Charles.

Frontier AI is changing the economics of cyberattacks

The report also found that frontier artificial intelligence (AI) models are reducing the cost and technical expertise required to conduct sophisticated cyberattacks, making it easier for threat actors to scale and repeat their activity.

As part of its new AI Cyber Range Assessment, Ensign tested 10 generally available frontier AI models across eight stages of a simulated enterprise cyberattack. The models completed 160 test runs in an isolated cyber range designed to replicate a typical university network protected by commonly used security controls. Ensign’s assessment found that performance is converging among the leading Eastern and Western models tested, suggesting that cost, rather than capability, may increasingly become the deciding factor for threat actors.

The assessment (refer to Annex A and B) found that:

●      Leading frontier AI models were capable of executing multiple stages of a realistic cyberattack chain

●      Z.AI’s GLM-5.2 delivered offensive performance comparable to GPT-5.6 Sol at approximately one-fifth of the operating cost

●      Open-source Eastern models consistently delivered higher offensive capability per dollar

●               All of the models were able to steal credentials and move laterally between systems, some of them consistently

●      None of the models confidently evaded detection tools, with even the leading models achieving only partial success

“Frontier AI is fundamentally changing the speed, scale and economics of cyberattacks. If it can automate reconnaissance, identify vulnerabilities and help threat actors repeat those steps at a lower cost, it gives attackers more opportunities to find a way in. For organisations, the findings reinforce the need to strengthen cybersecurity foundations including the regular scanning and patching of critical internet-facing assets, and continuously testing and validating defences against the latest AI models. With frontier AI capabilities advancing on a roughly two-month cycle, security controls will need to evolve just as quickly,” said Charles.

Have a press release to share? Contact our team today.

Have an article or a piece you would like to contribute? Get in touch with the editorial team.