Hackers to face 25 years in jail for cyber attacks on Australia's national infrastructure
The proposals aim to update current laws to account for cyber threats like ransomware


Hackers could face up to 25 years in jail if found guilty of cyber offences against Australia’s critical infrastructure, under proposed changes introduced by the government today.
The government tabled the Crimes Legislation Amendment (Ransomware Action Plan) Bill 2022 in a bid to modernise criminal offences and procedures to respond to the threat of ransomware. It has several proposals that update the Criminal Code Act 1995, the Crimes Act 1914, and the Proceeds of Crime Act 2002.
One proposal is to set a maximum jail term of 25 years for hackers who target critical infrastructure assets. The government said it wanted to ensure that any computer offence against Australia’s infrastructure carries an appropriate penalty and deters would-be offenders.
Australian law enforcement will also be given clear legal authority to investigate and prosecute ransomware crimes and offences that occur in foreign countries, where the crime affects a person in Australia. Law enforcement will also be given the power to seize cryptocurrencies and other digital assets associated with cyber crime.
A new offence will also be created for those who buy or sell ransomware, with the government eager to crack down on the ransomware-as-a-service business model in particular.
The bill also makes adjustments to the law governing unauthorised access to, or the modification of, restricted data and unauthorised impairment of data held on a computer disk. In this case the maximum jail term will increase from two years to five years.
“Although a positive step in the fight against cybercriminals, this deterrent will by no means be the end of ransomware in Australia,” said Camellia Chan, CEO and Founder of X-PHY. “It is imperative that organisations do not rest on their laurels despite tougher punishments for criminals. New ransomware gangs and threat actors who are willing to risk the consequences are sure to emerge.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“Indeed, the devastating attack last year on the Colonial Pipeline in the US proves no organisation is too large to be targeted. Efforts to improve cyber security and bolster defences should be more strong than ever.”
This legislation implements key aspects of the government’s Ransomware Action Plan that was announced on 13 October 2021. The plan set out the government’s strategic approach to tackle the threat posed by ransomware and make it easier to clamp down on cryptocurrency transactions associated with ransomware crimes.
RELATED RESOURCE
The best defence against ransomware
How ransomware is evolving and how to defend against it
Australia’s proposals to update the current legislation may be watched by other nations across the globe, many of which lack formal charges against ransomware.
In the UK, the Computer Misuse Act, last updated in 2015, has faced repeated calls to be brought in line with current threats, including from a coalition of businesses and cyber security groups.
The US has the Computer Fraud and Abuse Act (CFAA), which was introduced in 1986 to address hacking. It was most recently amended in 2008 to cover a broad range of conduct far beyond its original intent.
Australia's new bill shadows attempts made by an opposition legislator in June last year, who introduced the Ransomware Payments Bill 2021. That bill would have required victims who make ransomware payments to notify the Australian Cyber Security Centre (ACSC) of key details of the attack, the attacker, and the payment.
Labour MP Tim Watts said it would provide a fuller picture of ransomware attacks in Australia and the scale of the threat. However, the bill did not proceed from the House of Representatives and was formally removed on 14 February 2022.
Other countries have taken steps against ransomware as its use skyrocketed during the pandemic, including the US, which gave it a similar status as terrorism in June 2021. Last November, the Justice Department charged a Ukrainian national with conducting ransomware attacks against multiple victims and also announced the seizure of $6.1 million in funds traceable to alleged ransom payments.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
The unseen risk in Microsoft 365: disaster recovery
Businesses that assume they’re covered for data backup could come unstuck in a time of crisis
-
Anthropic CEO Dario Amodei's prediction about AI in software development is nowhere nearly to becoming a reality
News In March, Anthropic CEO Dario Amodei claimed up to 90% of code would be written by AI within six months – his prediction hasn't quite come to fruition.
-
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward
News The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack
News The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities
News The attack on IT systems supplier Miljödata has impacted public sector services across the country
-
A notorious hacker group is ramping up cloud-based ransomware attacks
News The Storm-0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpoint-based attacks and toward cloud-based ransomware.
-
Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain – and it uses OpenAI’s gpt-oss-20b model
News Using OpenAI's gpt-oss:20b model, ‘PromptLock’ generates malicious Lua scripts via the Ollama API.
-
Data I/O shuts down systems in wake of ransomware attack
News Regulatory filings by Data I/O suggest the costs of dealing with the attack could be significant
-
Average ransom payment doubles in a single quarter
News Targeted social engineering and data exfiltration have become the biggest tactics as three major ransomware groups dominate
-
BlackSuit ransomware gang taken down in latest law enforcement sting – but members have already formed a new group
News The notorious gang has seen its servers taken down and bitcoin seized, but may have morphed into a new group called Chaos