Australia’s former cyber security chief has warned that artificial intelligence is rapidly lowering the barriers to sophisticated hacking, creating the most serious threat he has encountered in nearly 25 years working in the field.
Alastair MacGibbon, who led the Australian Cyber Security Centre and served as the country’s first eSafety Commissioner, said recent advances by AI companies had marked a dramatic shift in the balance between attackers and defenders.
Speaking to the 7NEWS podcast The Issue, Mr MacGibbon said he regarded his efforts to improve cyber security, privacy and data protection as an “abject failure” — a remark he described as partly tongue-in-cheek.
“I’ve spent 24 years trying to convince people to do better in terms of cyber security, cyber safety, privacy, what we’re doing with data, how much we’re collecting, how we need to protect it,” he said.
“And all of those dials are turned in the wrong direction.”
AI hacking threat has advanced at unprecedented speed
Mr MacGibbon said his concern had intensified after Anthropic and OpenAI acknowledged that their systems had developed the ability to carry out hacking tasks at a level comparable with, or beyond, human operators in some circumstances.
He said cyber security had traditionally benefited from the limits of human attackers, who often lacked the time and patience required to search through complex software for small vulnerabilities.
AI systems, however, could perform that work at speed and for minimal cost.
“AI is doing that now in a matter of minutes and it’s burning tokens that cost less than my cup of coffee in the morning,” he said.
Mr MacGibbon described the development as a “wake up moment”, saying the ability to conduct cyber attacks had been opened to a much wider group of people.
“The AI attack vector in a handful of weeks has advanced and democratised the ability of people who want to hack in a way that we’ve never seen before,” he said.
His warning comes as both major AI companies have reported security incidents during testing in which models reached systems beyond their intended environments. The episodes have fuelled concerns about how quickly increasingly autonomous AI agents can identify vulnerabilities, use digital tools and act without close human supervision.
Mr MacGibbon rose to prominence as an Australian Federal Police officer after establishing the force’s High Tech Crime Centre. He later advised the prime minister on cyber security before leading the Australian Cyber Security Centre.
He subsequently founded CyberCX, which became one of Australia’s largest cyber security companies, and spent seven years building the business before recently leaving the firm.
He said the growing number of internet-connected devices had also expanded the potential attack surface, from home security systems and robot vacuum cleaners to modern vehicles.
Cars were particularly concerning, he said, because they contained microphones, cameras and other connected systems capable of collecting information and communicating with manufacturers.
“They are just a big listening device platform,” Mr MacGibbon said, arguing that the crucial issue was not necessarily where a vehicle had been built, but where its technology was controlled.
He said the growing presence of Chinese-made vehicles in Australia raised questions about the remote control of connected systems and the potential consequences during a period of heightened international tension.
“Imagine if someone, the manufacturer, who doesn’t have to hack the vehicle, sends commands to change what that vehicle does,” he said.
“It doesn’t start or it doesn’t stop, or its steering changes, or its lights don’t work.”
Chinese-made vehicles now account for a substantial share of Australia’s new car market, while the country has also recorded rapid growth in electric vehicle sales.
Mr MacGibbon said the possibility of hostile actors exploiting connected infrastructure should be taken seriously, particularly if Australia became involved in a conflict or a near-conflict situation.
“If we ended up in a conflict or near conflict situation and you were a Chinese strategist and you had these levers at your disposal, then you’d have to actively consider using them,” he said.
Now between jobs, Mr MacGibbon said he had not decided what he would do next. But after decades spent warning about the dangers posed by digital technology, he said the latest advances in AI represented the most intimidating challenge yet.
