Free Person Using Macbook Air Stock Photo

Your Biggest Cyber Risk Isn’t a Chinese EV.

Meta’s smart glasses and Chinese EVs are making headlines for surveillance risk around the world. However, hacking doesn’t need to be sophisticated. The ASD (Australian Signals Directorate) says the most common way into Australian networks is as simple as logging into a personal device through a saved browser password with no MFA (Multi Factor Authentication).

A case study shows how one fake note taking app led to a full network compromise, with no advanced hacking skills required. We discuss why MFA matters and how Relevate can help with data and cybersecurity solutions.

Your Biggest Cyber Risk Is Not a Chinese EV, It’s a Password

Recent news has been all about hacking and breaches in technology. Meta’s smart glasses have been in the news over staff reviewing private footage of customers. Governments are also debating whether Chinese made electric vehicles are sending data back to China. AI is being blamed for breaches. It’s easy to surmise that the danger is foreign, sophisticated and happening at a nation state level, but the ASD thinks otherwise.

Check out the ABC Four corners investigation – Asleep At The Wheel into Chinese EV’s. Credit to ABC.

According to the ASD, most Australian businesses are getting breached right now not through facial recognition, surveillance hardware or foreign nations. The breaches are simply through a browser with saved passwords and one missing tick box that nobody set up.

A Notes App Was All It Took to Get Inside the Network

This is an actual case study where an employee downloaded a normal note taking app onto her personal laptop. But the app was malware. Once installed, it started copying every password saved in the browser, including work logins and the data was published on the dark web for sale. When someone buys the list, the employee and the company are breached. Not because the hackers hacked into the network. They logged in, because there was no MFA sitting behind it.One Missing MFA Setting Turned a Stolen Password into Free Access

There’s no zero day exploit here, no custom malware built to defeat enterprise defences, no state sponsored infrastructure. Just someone downloading an app that looked harmless. If MFA had been set up for that login, the stolen password would have been worthless. The attacker would have had all the details but no way to actually log in. One missing setting turned a routine malware infection into a full blown network compromise.

This Is the Most Common Way In

It can be easy to treat this as a one-off, a scare story, but the ASD is clear that this exact pattern has been the single most common way into Australian networks for a couple of years. Compare that with the current trending news. Company boards and IT teams spend real energy discussing headline-grabbing threats like large-scale state-sponsored hacking, while the attack pattern actually breaching businesses week to week gets a fraction of that attention. Not because it’s less damaging. Because it’s less interesting to talk about.

Your IT Policy May Not Cover Personal Laptops

Such breaches start on a personal device. We all use personal devices for office work, running our own choice of apps. The work laptop is managed and audited by the IT team, but personal devices most of the time aren’t. You can have a tight, well enforced policy for every company owned device and still have zero visibility into what’s installed on the laptop an employee uses to check webmail at 9pm. The breach just needs one login that isn’t protected by anything except a password.

MFA and Dark Web Credentials Close the Gap

The fix is quite simple. MFA turned on everywhere it matters, and credentials checked against known dark web leaks, so a password already circulating gets flagged and changed. This won’t stop a large-scale, state-sponsored intrusion, but it stops the attack that actually gets most businesses breached. This is the solution Relevate offers with data and cybersecurity, and it’s why we always try to fix the weak points instead of talking about headline events.

FAQs

What is MFA and why does it stop this kind of attack?
Multi Factor Authentication requires a second proof of identity beyond a password, usually a code from an app or a prompt on your phone.

Why does a personal device create risk if it’s not connected to the network?
The device doesn’t need to be connected to your network directly. It just needs to store a saved password that also unlocks a work login.

What is dark web credential monitoring?
A service that checks whether your organisation’s usernames and passwords have appeared in known data leaks or dark web marketplaces, so you can force a reset before anyone uses them.

Is this more common than sophisticated hacking?
Yes, according to the ASD. This pattern has been the most common way into Australian networks for a couple of years.

Newsletter

Keep up to date — get updates with latest topics