HomeAUPolitician's WhatsApp Compromised Amid Surge in Cyber Attack Attempts

Politician’s WhatsApp Compromised Amid Surge in Cyber Attack Attempts


Politician’s WhatsApp Compromised Amid Surge in Cyber Attack Attempts

In Brief

  • A Senate estimates hearing has revealed that a parliamentarian’s WhatsApp account was compromised in March.
  • The hacking led to WhatsApp being briefly blocked in parliament.

Earlier this year, the Department of Parliamentary Services (DPS) took the step of temporarily disabling desktop access to WhatsApp within Parliament House. This action followed an incident where a “foreign state actor” successfully hacked the account of a parliamentarian, as revealed during a Senate estimates hearing.

During the hearing on Monday, it was disclosed that the compromised parliamentarian, whose identity was not revealed, reported the breach to the department. The hack affected the WhatsApp accounts of the parliamentarian and three of their staff members, impacting both personal and DPS-managed devices on March 6.

Mike Webb, who serves as the Chief Information Officer at DPS, explained that the accounts fell victim to phishing—a cyber-scam tactic designed to trick individuals into divulging personal information.

“The goal was to gain control of the accounts, and that was indeed achieved,” Webb stated at the hearing.

Hackers managed to intercept verification codes required to access WhatsApp via a web browser, enabling them to breach the accounts.

In response to the hacking, the DPS contacted the Australian Signals Directorate and temporarily blocked the messaging service from the parliamentary computing network over the coming weekend on desktop devices.

Webb told the hearing evidence suggesta “a foreign state actor” was behind the hacking.

“There’s lots of public reporting of state-sponsored WhatsApp phishing campaigns targeting government officials,” Webb said, adding that multiple countries, such as Germany and the United States, have issued warnings on this type of attack.

“So this is targeting our parliamentarians, but it is a genuine global issue.”

Nicola Hinder, deputy secretary and chief operating officer at DPS, confirmed that the department had detected 46 cases of malware and around 20,000 phishing attempts targeting parliamentarian and DPS devices this financial year.

Liberal senator James McGrath then asked if those numbers were “quite low”, and Hinder said the number of attempts was “cyclical”.

“We’ve indicated before that we’ve had high numbers, without talking about it too much,” Hinder said.

“I think there are times when we have much higher attempts, and times when obviously attention is diverted elsewhere.”


For the latest from SBS News, download our app and subscribe to our newsletter.