AISA A.I CyberSecurity Scoring
AISA
Company Information
Website:http://www.aisa.org.au/
Employees number:199
Number of followers:39,453
NAICS:541514
Industry Type:Computer and Network Security
Homepage:aisa.org.au
AISA Risk Score (AI oriented)
Between 650 and 699
AISAComputer and Network Security
Updated:
20/03/2026
20/03/2026
694/1000
Weak
B
AISA Global Score (TPRM)
xxxx
AISAComputer and Network Security
Score locked

AISAWeak
Current Score
694B (WEAK)
01000
1 incidents
-62 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
698
MAY 2026
696
APRIL 2026
696
MARCH 2026
693
FEBRUARY 2026
693
JANUARY 2026
753
Breach
06 Jan 2026 • AISA
CRRC MA, K3G and Australian NBN: Dozens of Major Data Breaches Linked to Single Threat Actor
Zestix/Sentap Initial Access Broker Campaign
691
CRITICAL-62
CRRTESAUS1767704662
Cybersecurity Alert: Threat Actor Zestix/Sentap Exploits Stolen Credentials in Major Data Breaches
A threat actor known as Zestix—also linked to the online persona Sentap—has been identified as an initial access broker (IAB) behind multiple high-profile data breaches, according to cybersecurity firm Hudson Rock. Active since late 2024–early 2025, Zestix’s operations trace back to Sentap’s activities dating to 2021, with both personas leveraging stolen credentials to infiltrate enterprise networks.
### Attack Method & Victim Profile
Zestix/Sentap targets organizations across aerospace, government infrastructure, legal, robotics, and defense sectors, exploiting credentials harvested from information stealers like RedLine, Lumma, and Vidar. These credentials—some freshly stolen, others lingering in logs for years—were used to breach file-transfer services such as ShareFile, OwnCloud, and Nextcloud, often due to missing multi-factor authentication (MFA). The actor has successfully compromised systems roughly 50 times, exfiltrating data for sale on Russian-language hacker forums or auctioning access to the networks themselves.
### Notable Breaches & Financial Impact
Zestix has claimed responsibility for large-scale breaches, including:
- Iberia (Spanish flag carrier) – 77 GB of data, listed for $150,000
- Pickett & Associates (engineering firm for energy orgs)
- Intecro Robotics (aerospace/defense equipment)
- Maida Health (Brazilian military police contractor)
- CRRC MA (rolling stock manufacturer)
- Pan-Pacific Mechanical (1.04 TB), Bradley R. Tyer & Associates (1.02 TB), and The Providence Group (1 TB)
Under the Sentap alias, the actor’s victim list expands further, though Hudson Rock could not confirm all breaches stemmed from infostealer infections.
### Broader Infostealer Threat
The incident underscores the persistent risk of information stealers, which Hudson Rock warns have exposed credentials for thousands of organizations using ShareFile, OwnCloud, and Nextcloud, including Deloitte, Honeywell, KPMG, Samsung, and Walmart. These attacks thrive on malware-as-a-service (MaaS), enabling even unskilled actors to deploy stealers that exfiltrate data in minutes before self-deleting, leaving minimal forensic traces.
The commodification of cybercrime—where stolen credentials fuel credential stuffing, identity theft, and fraud—continues to drive large-scale breaches, with no immediate solution in sight.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
AUGUST 2025
753
JULY 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for AISA ??
What was AISA's A.I Rankiteo Cyber Score in May 2026 ??
What was AISA's A.I Rankiteo Cyber Score in April 2026 ??
What was AISA's A.I Rankiteo Cyber Score in March 2026 ??
What was AISA's A.I Rankiteo Cyber Score in February 2026 ??
What was AISA's A.I Rankiteo Cyber Score in January 2026 ??
What was AISA's A.I Rankiteo Cyber Score in December 2025 ??
What was AISA's A.I Rankiteo Cyber Score in November 2025 ??
What was AISA's A.I Rankiteo Cyber Score in October 2025 ??
What was AISA's A.I Rankiteo Cyber Score in September 2025 ??
What was AISA's A.I Rankiteo Cyber Score in August 2025 ??
What was AISA's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on AISA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with AISA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view AISA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?