Overview
- A targeted phishing campaign on March 6 compromised the WhatsApp accounts of an unnamed federal parliamentarian and three staffers by tricking them into handing over registration verification codes.
- Attackers used the codes to link devices and impersonate users so messages and contacts appeared to come from the victims, a method that does not require malware on the phones.
- The Department of Parliamentary Services temporarily blocked WhatsApp on parliamentary desktop browsers, notified the Australian Signals Directorate, and lifted the block after containment steps were taken.
- Officials told a Senate estimates hearing there is evidence suggesting a foreign state actor was behind the campaign while warning that firm attribution to a specific state is very difficult.
- DPS reported a sustained high threat level to parliamentary systems—including 46 malware detections, about 20,000 phishing attempts and roughly 1,458 cyber alerts—fueling political criticism and a review of communications rules for MPs and staff.