Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Australian Information Security Association (AISA)

Australian Information Security Association (AISA) Vendor Cyber Rating & Cyber Score

aisa.org.au

The Australian Information Security Association (AISA) is Australia's cyber security peak body. Formed in 1999, AISA is focused on individual membership. AISA aims to foster and promote the development of the information security industry and encourage the professional development of our members. We have continued to grow our membership base in excess of 13,500+ members and extend our geographical reach across Australia. AISA caters to all domains within the information security field with focus groups, presentations at meetings and networking opportunities. AISA welcomes as members all individuals with a professional interest in information security. Our broad membership base consists of information security professionals from all


AISA A.I CyberSecurity Scoring

AISA
Company Information
Website:http://www.aisa.org.au/
Employees number:199
Number of followers:39,453
NAICS:541514
Industry Type:Computer and Network Security
Homepage:aisa.org.au
AISA Risk Score (AI oriented)
Between 650 and 699
logo
AISAComputer and Network Security
Updated:
20/03/2026
694/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
AISA Global Score (TPRM)
xxxx
logo
AISAComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

AISA
AISAWeak
Current Score
694B (WEAK)
01000
1 incidents
-62 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
698Before Incident
MAY 2026
696Before Incident
APRIL 2026
696Before Incident
MARCH 2026
693Before Incident
FEBRUARY 2026
693Before Incident
JANUARY 2026
753Before Incident
Breach
06 Jan 2026AISA
CRRC MA, K3G and Australian NBN: Dozens of Major Data Breaches Linked to Single Threat Actor

Zestix/Sentap Initial Access Broker Campaign

691After Incident
CRITICAL-62
CRRTESAUS1767704662
Cybersecurity Alert: Threat Actor Zestix/Sentap Exploits Stolen Credentials in Major Data Breaches A threat actor known as Zestix—also linked to the online persona Sentap—has been identified as an initial access broker (IAB) behind multiple high-profile data breaches, according to cybersecurity firm Hudson Rock. Active since late 2024–early 2025, Zestix’s operations trace back to Sentap’s activities dating to 2021, with both personas leveraging stolen credentials to infiltrate enterprise networks. ### Attack Method & Victim Profile Zestix/Sentap targets organizations across aerospace, government infrastructure, legal, robotics, and defense sectors, exploiting credentials harvested from information stealers like RedLine, Lumma, and Vidar. These credentials—some freshly stolen, others lingering in logs for years—were used to breach file-transfer services such as ShareFile, OwnCloud, and Nextcloud, often due to missing multi-factor authentication (MFA). The actor has successfully compromised systems roughly 50 times, exfiltrating data for sale on Russian-language hacker forums or auctioning access to the networks themselves. ### Notable Breaches & Financial Impact Zestix has claimed responsibility for large-scale breaches, including: - Iberia (Spanish flag carrier) – 77 GB of data, listed for $150,000 - Pickett & Associates (engineering firm for energy orgs) - Intecro Robotics (aerospace/defense equipment) - Maida Health (Brazilian military police contractor) - CRRC MA (rolling stock manufacturer) - Pan-Pacific Mechanical (1.04 TB), Bradley R. Tyer & Associates (1.02 TB), and The Providence Group (1 TB) Under the Sentap alias, the actor’s victim list expands further, though Hudson Rock could not confirm all breaches stemmed from infostealer infections. ### Broader Infostealer Threat The incident underscores the persistent risk of information stealers, which Hudson Rock warns have exposed credentials for thousands of organizations using ShareFile, OwnCloud, and Nextcloud, including Deloitte, Honeywell, KPMG, Samsung, and Walmart. These attacks thrive on malware-as-a-service (MaaS), enabling even unskilled actors to deploy stealers that exfiltrate data in minutes before self-deleting, leaving minimal forensic traces. The commodification of cybercrime—where stolen credentials fuel credential stuffing, identity theft, and fraud—continues to drive large-scale breaches, with no immediate solution in sight.
INCIDENT DETAILS -
TYPE
Data BreachInitial Access Broker (IAB) ActivityRansomware
MOTIVATION
Financial gainData exfiltration and saleInitial access brokerage
IMPACT
Data Compromised: 77 GB (Iberia), 1.04 TB (Pan-Pacific Mechanical), 1.02 TB (Bradley R. Tyer & Associates), 1 TB (The Providence Group), 306 GB (Australian NBN), 275 GB (UrbanX.io), and othersShareFileOwnCloudNextcloudEnterprise networksOperational Impact: Unauthorized access to sensitive file repositories, data exfiltration, and potential ransomware deploymentBrand Reputation Impact: High (public disclosure of breaches, data sales on dark web)Identity Theft Risk: High (PII exposure)
DATA BREACH
CredentialsSensitive filesPersonally Identifiable Information (PII)Sensitivity Of Data: High (corporate, military, healthcare, and infrastructure data)
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident
AUGUST 2025
753Before Incident
JULY 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for AISA ?
?
What was AISA's A.I Rankiteo Cyber Score in May 2026 ?
?
What was AISA's A.I Rankiteo Cyber Score in April 2026 ?
?
What was AISA's A.I Rankiteo Cyber Score in March 2026 ?
?
What was AISA's A.I Rankiteo Cyber Score in February 2026 ?
?
What was AISA's A.I Rankiteo Cyber Score in January 2026 ?
?
What was AISA's A.I Rankiteo Cyber Score in December 2025 ?
?
What was AISA's A.I Rankiteo Cyber Score in November 2025 ?
?
What was AISA's A.I Rankiteo Cyber Score in October 2025 ?
?
What was AISA's A.I Rankiteo Cyber Score in September 2025 ?
?
What was AISA's A.I Rankiteo Cyber Score in August 2025 ?
?
What was AISA's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on AISA's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with AISA ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view AISA's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Australian Information Security Association (AISA) Cyber Scoring History | Rankiteo