Insider Threat: Australian media reporting of July 2026

In July 2026, Australian media reported multiple instances of insider threat behaviour.  From our observations, reports of insider threat incidents in Australia appear to be increasing.  The reason Pentagram Advisory is pointing these reports out is to highlight that insider threat is a reality across almost all facets of human activity.  It is a daily occurrence.  It is not exotic.  It can happen to you, or to the workplace you are part of, or to a supplier you rely on.

But first, let’s be clear about what insider threat is.

The insider threat comes from the actions of a trusted insider, that is a person who has been accepted into an organisation, and so has become trusted.  The organisation has chosen to invest trust in the person.  The person becomes an insider threat when they use the legitimate access they have been granted to the organisation’s people, information, assets and operations to cause harm to the organisation that has invested trust in them.

That harm can be caused intentionally or unintentionally, but the harm caused, the consequences of their behaviour, can be the same: minimal to catastrophic harm.

Insider threat is fundamentally about trust.  Organisations deliberately invest trust in people so they can perform their roles.  Insider threat arises when that trust is abused, misplaced or inadvertently creates opportunities for harm.

Royal Australian Navy

The first media report is about a senior Royal Australian Navy officer.  The officer’s rank is not disclosed, other than to say they are at ‘star’ rank.  In the Royal Australian Navy that means being a commodore or an admiral.

The officer is facing a court martial after being subjected to a pre-trial hearing.  The officer will reportedly face eight charges under the Defence Force Discipline Act 1982, rather than civil charges in an open court.

The allegations of the officer’s apparent misconduct have not been disclosed, but reportedly relate to the management of naval sustainment contracts with at least two major defence suppliers connected with the Henderson shipyard in Western Australia.

On the scant details that are available, this is an alleged case of insider threat.  The reporting indicates that the officer has used their role and influence to benefit either themselves or a supplier, or both.

The salient points in this case are the alleged misuse of authority or influence by a very senior person and, perhaps, more importantly, the officer has been part of Defence’s security culture for decades (by virtue of their rank) and so has been subject to numerous Commonwealth security clearance reviews and would have been educated about probity when dealing with suppliers.  Despite this history of the most intense security education, it appears that the officer has still chosen to behave in a way that does not align with the security obligations and culture of the Australian Defence Force.

Artificial Intelligence

The second report: OpenAI admitted that two of its AI systems – GPT 5.6 and another unnamed system – that were undergoing test and evaluation escaped the testing environment they were confined to.  Both systems reportedly had some focus on ‘hacking’.  Somehow the AI systems managed to find access to the internet and thereby escaped into the wild.

Once at liberty on the open internet the AI systems gained unauthorised access to another AI company named Hugging Face.  Reports indicate that the AI systems seemed to have attacked Hugging Face as the best available source of information to answer a question the systems were pursuing.

OpenAI said “We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities.”

This is the first reported instance of an AI system acting in this way.  There is much debate now about how AI has the potential to act as an insider threat within an organisation.  This example shows that powerful AI can act in ways not programmed or anticipated.  This is a cornerstone example of AI and a new insider threat species – it is not human.  This report is a wake-up call to all enterprises employing AI that they must treat and manage their AI in alignment with their insider threat programs, that is they need to treat AI as they would a human source of harm.

United States Secret Service

A member of US Vice-President JD Vance’s security team has been suspended and is under investigation for allegedly leaking sensitive information, the U.S. Secret Service (USSS) has said.

The specifics of what was leaked have not been released, but the Secret Service said their agent faced a “potential criminal inquiry”, involving allegations of “compromising operational and information security”.  “Any conduct that potentially threatens the safety of a protectee will not be tolerated,” Secret Service spokesperson Anthony Guglielmi said.

The White House declined to comment on the investigation.

Guglielmi did not say what information had been leaked.  But earlier in July, U.S. television network MS NOW published a story citing anonymous sources alleging that some among Vance’s security team were frustrated by his family’s travel.  According to CNN, the agent’s suspension was tied to that report.

In this report we see an employee of U.S. Secret Service allegedly leaking information to the media about Vice-President Vance.  The Secret Service is charged to protect the lives of the president, vice-president and others 24 / 7 / 365.  And we know that these office holders (and their families) are under constant threat of violence and assassination.

Like the Australian Defence Force, the Secret Service will undertake in-depth vetting of candidate officers and have a strong security culture and ongoing suitability monitoring program.  The Secret Service will have a very capable insider threat program.  But people change, and they are motivated to behave differently in response to various drivers in their private and work life.  The reality is that every event in a person’s life may ultimately be manifest in workplace behaviour.  The ‘whole person’ comes to work, not just the workplace mask that most of us put on when we arrive at the workplace.

Origin Energy

The next report is about the electricity provider Origin Energy, Australia’s largest energy retailer.

Media reporting states that a ‘hacker’ contacted the media to explain that they obtained the IT access credentials of a recently dismissed Origin employee and used these to access a billing system enabling them to steal customer data of about two million Origin clients.

In contacting the media to report the hack, the hacker said their actions were “revenge” for Origin’s offshoring of Australian jobs to “underpaid” Asian workers.  The hacker reportedly said they had access to Origin’s data for about three weeks undetected by Origin’s IT team.

Subsequent media reporting suggested the manner of the hack suggested an offshore hacking entity.  However, based on the reports this hack looks personal.  The fact the hacker was able to obtain credentials of a recently departed employee (and there is no suggestion in the reporting, as at 27 July 2026, the former employee was involved) would suggest that investigators must consider the insider threat in its investigation even if the case presents as an external cyber attack.

This case demonstrates why organisations should not treat cyber security and personnel security as separate disciplines.  Many cyber incidents begin with a people problem.

Origin’s obligations under the Security of Critical Infrastructure Act 2018 (SOCI Act) include having a Critical Infrastructure Risk Management Program (CIRMP) which includes addressing the hazards of personnel security.  Origin should have an insider threat program.  Even if this security event is proven to be perpetrated from an outsider, there will be lessons from the case about insider threat mitigation.  For example, was an IT person in Origin complicit in helping the hacker gain and maintain access, or was the hacker able to enter because of substandard offboarding process which failed to extinguish the former employee’s IT access?

Although these incidents involve very different organisations and circumstances, they share a common feature: trusted access. Whether the actor is a senior executive, a security-cleared officer, a recently departed employee, or an autonomous AI system, the harm arises because trusted access is exploited in a way that the organisation did not anticipate or could not prevent.

Conclusion

The diversity and significance of these four reports makes clear that the insider threat is pervasive and can happen in even the most secure workforces and workplaces.  However, the Royal Australian Navy and U.S. Secret Service are not typical workplaces – they have workforces that are vetted and monitored far more than almost any private sector entity.  This indicates that the private sector organisations face an even greater risk of insider threat because they are not as well prepared to manage insider threat.  The AI example is chilling and should be a signal to entities to ensure their insider threat program includes the behaviour of AI systems as well as the behaviour of people.

Pentagram Advisory can advise on mitigating insider threat.  Through our Trusted Workforce Program, Insider Threat Program, and related supply chain and personnel security eLearning offerings and advisory services we can shed light on how to mitigate the risk of insider threat.

0
0
Your Cart
Your cart is emptyReturn to Shop