October Recap: Cyber Awareness Month
October has been one of the busiest months in cybersecurity this year.
From vendor compromises to accidental data exposure, every story reminded us how layered the threat landscape has become and how essential awareness still is.
F5 Breach
F5 confirmed that attackers maintained long-term access to its internal systems, stealing source code and vulnerability research for its BIG-IP product line. This kind of technology controls traffic management across most of the Fortune 500. The intrusion lasted over a year before detection.
No customer systems were altered, but the stolen data includes blueprints and unreleased vulnerability information, giving attackers a roadmap for future exploits.
Emergency directives from global agencies followed within days, urging immediate patching. The real concern is how stolen research can be repurposed long after the headlines fade.
Another Month, Another Qantas Leak
Qantas customer data appeared on dark web forums after a failed ransom campaign run by the group Scattered Lapsus$ Hunters. The breach started through an offshore call centre using Salesforce software, where attackers used social engineering to gain access credentials.

Screenshot of Scattered Lapsus$ Hunters ransom post on the dark web
The exposed data includes names, contacts, frequent flyer details, and addresses for up to 5.7 million customers. Third party breaches have become the defining risk of 2025. Most incidents now start with a vendor, contractor, or offshore partner. When so many networks are linked, the source of each breach feels almost predictable.
The government has warned against accessing the leaked data because a court injunction now makes it illegal for anyone to view or download it. Those affected have also been urged not to search for their records, as hackers often use fake “leak” pages laced with malicious files to exploit that curiosity.
Flood victims’ data uploaded to ChatGPT
A former contractor for the NSW Reconstruction Authority uploaded a spreadsheet containing the personal details of flood victims to ChatGPT while looking for analysis help. The file included over 12,000 entries, including names, contact details and some health information from the Northern Rivers Resilient Homes Program.
The incident wasn’t necessarily malicious, but it’s an example of how fast sensitive data can leave a controlled environment once it enters an AI platform. It also raises questions about how many organisations still lack clear boundaries for generative-AI use.
Governance now needs to extend beyond policy to technical controls that prevent this kind of mistake from happening again.
Across the region
Australia committed $83.5 million to strengthen cyber capacity across the Indo-Pacific, funding joint programs through 2028. The goal is to build regional resilience and improve coordination as cyber-crime grows more global.
Between 2024-2025, cyber crimes have cost the Australian economy over $12.5 billion.
As online scams and transnational attacks keep expanding, shared defence is becoming as important as national strategy. Cooperation will define how well countries handle global threats over the next few years.
National snapshot
The ASD’s Annual Cyber Threat Report 2024–25 recorded an 83% rise in malicious activity notifications and an 11% increase in incidents handled.
Identity theft remained the most reported cybercrime, while ransomware kept its lead across sectors such as health, logistics, and finance.
The report shows that even with new protections, attacks in 2025 are becoming faster, smarter and harder to contain. With this, awareness and practice still matter more than protective technology alone.
As we get closer to 2026…
As Cyber Awareness Month ends, the focus is now consistency. Your business should be building their habits, updates and culture that hold through the rest of the year and into next.



