Published Jul 24, 2026 by Xiph
When we picture a serious cyber attack, we picture theft. A database of customer records spilled onto a forum, a ransomware note demanding payment, the slow public unravelling of an Optus or a Medibank. That mental model is so dominant it shapes how most Australian businesses think about risk: protect the data, and you’ve protected yourself.
But some of the most dangerous intrusions on record steal nothing at all — no records, no ransom note, no money. Their entire purpose is to get inside a network that matters — a power grid, a water utility, a telecommunications backbone — and wait. The campaign tracked as Volt Typhoon is the clearest example we have, and it should change how every business connected to critical infrastructure thinks about who might already be inside.
The intrusion that steals nothing
Volt Typhoon is a state-sponsored group widely attributed to China. It was first detailed publicly by Microsoft in May 2023, then laid out in unsparing detail in February 2024, when the US Cybersecurity and Infrastructure Security Agency (CISA) led a joint advisory co-signed by the FBI, the NSA and the cyber agencies of every Five Eyes partner — including the Australian Signals Directorate’s Australian Cyber Security Centre.
What the advisory described was not espionage in the usual sense. The actors had burrowed into networks across energy, water, communications and transportation, in some cases holding that access for as long as five years — not to read emails or copy blueprints, but to pre-position. The goal was quiet, durable footholds they could use to disrupt or destroy those services in a future crisis or conflict.
It helps to separate two very different goals.
-
Espionage is about knowing. The aim is to quietly extract information — intellectual property, negotiating positions, personal data — and leave without being noticed.
-
Pre-positioning is about doing. The aim is the access itself: the ability to flip a switch at the moment of maximum leverage. Nothing has to happen today. The value is the standing option to cause harm tomorrow.
It is closer to someone copying your keys and learning your routine, then waiting for the night that suits them. Ransomware is loud, immediate and financial; this is the opposite — silent, patient and strategic.
Why it is so hard to see
Most defences are built to spot malware — hostile code that doesn’t belong, which an antivirus engine or endpoint tool can flag. Volt Typhoon’s signature technique is designed precisely to defeat that approach. It is called living off the land, and it means doing the work with tools that are already there.
Rather than smuggling in custom malware, the actors use the legitimate administrative utilities already built into the systems they compromise — PowerShell, Windows Management Instrumentation, native networking commands — with valid credentials stolen along the way. To a monitoring system, it looks like an administrator doing ordinary administrative things. There is no malicious file to detect because, in a sense, there isn’t one.
They also hide at the soft edge of a network. Volt Typhoon was found routing its activity through compromised small-office and home-office routers — much of it end-of-life gear no longer receiving updates — to blend in with normal regional traffic; in January 2024 the US Department of Justice disrupted one such network of hijacked devices. The lesson is uncomfortable: the intrusion that matters most may raise no alerts at all, which is why it can sit undisturbed for years. As we argued in our piece on zero-days, prevention alone is never enough — you have to assume something has already slipped through, and go looking for it.
Why this is an Australian problem, not an overseas headline
Volt Typhoon’s confirmed victims were largely in the United States and on Guam, and the loudest coverage was about the US grid — but don’t file it under “overseas.”
Three things make it ours. First, Australia’s own cyber agency didn’t just read the advisory — the ASD’s ACSC co-authored it, which is how Canberra signals that a threat is shared, not foreign. Second, our utilities, telcos and transport operators run the same vendors, routers and edge appliances as everyone else, so we inherit the same weaknesses on the same day. Third, and most importantly, the strategic logic points straight at us: pre-positioning is about leverage in a future confrontation, and as a Five Eyes member and AUKUS partner in the Indo-Pacific, Australia sits squarely inside the scenarios this access is built for. Our security agencies have said as much repeatedly, warning that state actors are targeting — and quietly embedding in — the networks that keep the country running.

The part most small businesses get wrong
Here is the assumption that gets businesses into trouble: we’re not critical infrastructure, so this isn’t about us. The local utility is critical infrastructure. The national carrier is critical infrastructure. A twelve-person managed IT provider, a niche software vendor, a maintenance contractor — surely not.
That assumption is increasingly wrong, for two reasons: one strategic, one legal.
The strategic reason is the whole point of Volt Typhoon’s method: attackers go through the soft edge because the centre is hard. A major energy company may have a mature security team; its small contractor with a remote-access account into the same network very often does not. In a pre-positioning campaign, the under-defended supplier isn’t a footnote — it is the door.
The legal reason is Australia’s Security of Critical Infrastructure Act (the SOCI Act). Passed in 2018 and substantially expanded in 2021 and 2022, it now reaches across eleven sectors and around twenty-two asset classes — energy, water, communications, health, food and grocery, data storage and processing, transport and more — and it doesn’t only regulate the obvious giants. Its Critical Infrastructure Risk Management Program obligation requires responsible entities to identify and manage material risks across four hazard domains — cyber and information security, personnel, physical security and supply chain — with an annual report signed off by the board.
Read that last domain again: the law requires the regulated entity to manage the risk its suppliers represent. In practice, that duty flows downhill — provide software, IT services, data handling or maintenance to a regulated operator, and their legal obligation becomes your commercial reality. The Act also sets hard deadlines for those in scope: a critical incident must be reported to the ACSC within twelve hours, and other significant incidents within seventy-two, with the cyber side of a risk program aligned to a recognised framework such as the ASD’s Essential Eight. Reforms in late 2024 widened the government’s powers and tightened those expectations further.
Whether you sit inside the SOCI regime or one step removed as a supplier to someone who does, the practical question is the same — and many businesses are caught out by the answer.
What this means for your business
You cannot personally deter a nation-state, but you can make sure you are neither the easy door nor the unprepared supplier. A few priorities matter most.
-
Find out whether you’re in scope — directly or by association. This is the question most businesses get wrong. Whether you’re a responsible entity under the SOCI Act, or a vendor whose largest client is, your obligations and your exposure may be far greater than you assume. A cyber security risk audit is the fastest way to a clear answer.
-
Assume you’re a target for who you serve, not how big you are. A small supplier with privileged access to a critical network is a high-value foothold. Size is not cover.
-
Hunt for what blends in. Signature-based antivirus will not catch living-off-the-land activity. Invest in logging and behavioural detection that flags the unusual use of normal tools, and learn the indicators of compromise that betray an intruder already inside — the kind of anomaly AI-assisted defences are increasingly good at flagging.
-
Harden the edge. Replace end-of-life routers and VPN appliances, patch the rest promptly, and lock down remote access — this is the precise category of gear Volt Typhoon exploited. Our system hardening and network security guides are a sound starting point.
-
Segment and minimise privilege. Network segmentation and least-privilege access mean a single compromised account or contractor doesn’t hand over the entire environment.
-
Rehearse your reporting and response. Twelve hours is not long to recognise, escalate and report a serious incident. An incident response plan you have actually practised — ideally with virtual CISO guidance and a tested business continuity plan — beats a scramble.
-
Push security down your own chain. If your suppliers can reach your systems, hold them to standards too. The obligation that lands on you should land on them.
A final word
The hardest thing about pre-positioning is that there is nothing to see — no stolen data, no ransom note, no outage, until the day someone decides there should be one, at a time of their choosing rather than yours. That is what makes it a board-level risk rather than an IT footnote, and why waiting for evidence is the wrong strategy: the evidence, by design, arrives only when it is too late to matter.
The good news is that shutting these intruders out is the same disciplined work that defends you against everything else: know your environment, harden the edge, watch for what blends in, and rehearse your response. At Xiph Cyber we help Australian organisations and their suppliers work out where they sit, what the SOCI Act asks of them, and how to close the gaps first. To get ahead of the threat rather than react to it, explore our cyber security consulting services, or get in touch at enquiries@xiphcyber.com.
Posted in: Security