TLDR: Australia is experiencing a significant rise in AI adoption, which is unfortunately paralleled by a surge in phishing risks and data leaks. New reports highlight a substantial increase in employees falling victim to phishing attacks and a growing number of AI-powered cyber incidents, posing critical challenges for organizational security.
Australia is currently facing a dual challenge: the rapid integration of Artificial Intelligence (AI) into workplaces and a concerning escalation in cyber threats, including phishing attacks and data breaches. Recent findings from Netskope Threat Labs indicate a sharp increase in Australian workers clicking on phishing links, alongside the expanding usage and associated risks of generative AI (genAI) applications in the workplace.
The Netskope report, based on anonymized data from June 2024 to June 2025, reveals that an average of 1.2% of Australian employees clicked on a phishing link each month over the past year. This represents a staggering 140% increase compared to the previous period. Phishing attempts frequently involved impersonations of major tech companies like Microsoft and Google, accounting for nearly one in five successful clicks.
This surge in cyber vulnerability coincides with a broader adoption of AI technologies. By mid-2025, approximately 29% of organizations were utilizing AI models, and 23% were employing large language model (LLM) interfaces. However, this rapid adoption introduces new security concerns, particularly the direct integration of genAI systems with enterprise datasets. The report warns that permission levels within these AI tools must be meticulously monitored and restricted to prevent the exposure of sensitive data. Furthermore, LLM interfaces with inadequate default security configurations can lead to significant vulnerabilities if not properly managed by internal security teams.
Data commonly transferred to these platforms includes regulated data (54%), intellectual property (28%), and even highly sensitive information like passwords or encryption keys (9%). Such transfers could create further exposure for organizations if not adequately secured. The report also noted that 0.2% of Australian workers encounter malicious code, infected documents, or malware each month, adding another layer of concern for organizational IT security.
Beyond phishing, Australia is grappling with a rising wave of AI-driven cyberattacks, encompassing deepfake phishing, advanced malware development, and sophisticated supply chain compromises. Cyble’s mid-year analysis for 2025 documented over 70 major cyber incidents in Australia, reflecting a 13% rise over the same period in 2024. These incidents span various sectors, including energy, IT, telecom, construction, and healthcare.
Experts emphasize that traditional cybersecurity defenses are struggling to keep pace with these increasingly sophisticated, AI-driven tactics. Joerg Schmitz, Cyber Risk Quantification and Analytics Leader for APAC at Aon, highlighted the critical need for businesses to re-evaluate their third-party risk management. “Organisations must start treating their vendors as part of their own attack surface. The most lucrative attacks are those that can be scaled across multiple targets through a single compromised supplier. This is a wake-up call for Australian businesses to reassess how they manage third-party risk,” Schmitz stated.
Also Read:
- Australian Job Market Outlook: AI’s Impact on Vulnerable and Resilient Sectors by 2050
- South Korea Bolsters Cyber Defenses Against Advanced AI Threats
As AI continues to evolve, threat groups are leveraging it for improved reconnaissance, more convincing social engineering, and more difficult-to-detect malware. The report from Aon stresses that these developments demand greater attention to both technological and organizational measures, with AI-driven threats and supply chain challenges expected to remain central concerns for Australian businesses into the next year.


