Menu
Browse

Cyber Threat Actor: 23-year-old man

Actor Type Location Known Incidents
 Icon
Criminal
Australia
0 incidents
Profile

The threat actor is identified in open sources as a 23‑year‑old man residing in Australia, with his known alias simply reflecting his age. He was employed as an IT support worker for a third‑party contractor that provided services to the Australian National Maritime Museum in Sydney. Using that position, he gained internal access to the museum’s account payable system, where he altered the financial details of contracted companies to substitute his own information. After modifying the records, he proceeded to make several purchases using the compromised data, an activity that the Australian Federal Police later linked to a total of approximately ninety thousand dollars in redirected funds. The intrusion was detected when the museum noticed inconsistencies in the financial information supplied for its vendors, prompting an independent forensic review that involved the AFP. Investigators executed a search warrant at his home in Macquarie Park, seizing electronic devices for further analysis. He was subsequently charged with five counts of dishonestly obtaining property by deception under the Crimes Act 1900 (NSW), four counts of dishonestly obtaining or dealing in personal financial information under the Criminal Code Act 1995 (Cth), and two counts of unauthorised access and modification with intent to commit a serious computer offence under the same Commonwealth legislation.

The incident represents a financially motivated attack targeting the cultural heritage sector, specifically a national museum located in Sydney, Australia. The actor’s objective, as alleged by the AFP, was greed, demonstrated by the redirection of museum funds and the execution of fraudulent purchases. His tactics, techniques and procedures consisted of exploiting legitimate contractor credentials to achieve initial access, then performing unauthorized modification of financial records within the account payable system, followed by the use of the altered data to conduct illicit transactions. No malware families, custom tooling, or external command‑and‑control infrastructure are described in the reporting; the operation relied solely on the abuse of privileged access and the manipulation of existing financial workflows. No state nexus, criminal consortium, or broader affiliation is indicated in the public sources; the individual appears to have acted alone. The Australian National Maritime Museum case stands as the sole publicly reported operation attributed to this actor, illustrating how an insider position can be leveraged for financial gain without the need for sophisticated malware or complex infrastructure.

Incidents
Attributed incidents available to members
0 incidents
Sources
Sources available to members
1 source