The Australian Signals Directorate issued a targeted alert to university chief information security officers on Monday after investigators linked three credential-theft incidents to counterfeit research-grant portals that mimic Australian Research Council and National Health and Medical Research Council login flows closely enough to capture multi-factor authentication approvals before redirecting academics to legitimate sites. The advisory, distributed through the Australian Cyber Security Centre, asks research administration teams to pause outbound grant links until domain allowlists are refreshed ahead of September submission cut-offs.
What broke
According to people briefed on the incidents, attackers registered domains one or two characters off official grant-management URLs and emailed deans and project officers with “final compliance” notices. Victims who clicked through saw pages that cloned ARC and NHMRC branding closely enough to pass casual inspection, then prompted for institutional single sign-on followed by push-based MFA. Reverse-proxy kits forwarded session cookies to operators offshore while victims completed real grant forms on authentic sites, unaware their approvals had already been mirrored.
Two Group of Eight universities and one regional institution reported compromised researcher accounts used to download ethics and budget attachments—not to alter submitted applications, which still require back-end validation. ASD said it has not attributed the activity to a named state actor but noted tooling overlaps with campaigns previously aimed at defence subcontractors.
What ASD confirmed
An ACSC spokesperson said the alert is classified as targeted rather than economy-wide because grant-season phishing historically spikes in late September when discovery and linkage rounds close. ASD recommends hardware security keys for accounts with access to export-controlled data, DNS monitoring for typosquat domains, and mandatory callback verification for any email that changes bank details on external grant acquittals.
The Department of Education’s research-security unit echoed the guidance in a parallel note to vice-chancellors, reminding them that foreign interference guidelines treat compromised grant credentials as reportable incidents even when no classified material is involved. Universities must document remediation steps for audit teams reviewing Commonwealth compliance frameworks.
Who has the file
State police cybercrime units received referral packages from at least one affected campus, though ASD retains lead technical analysis on infrastructure attribution. Telstra and Optus security teams were asked to flag SMS forwarding changes on staff mobiles tied to compromised accounts—a common precursor when attackers pivot from web sessions to SIM-assisted recovery flows.
Research office managers told InfoHandle they are reverting to bookmarked grant URLs only, disabling link-clicking in procurement inboxes, and scheduling after-hours MFA enrollment drives for casual academic staff who still rely on SMS one-time codes.
What is still unknown
Investigators have not said whether stolen attachments included unpublished clinical trial data or export-controlled engineering schematics. It is unclear how many typosquat domains remain active; ACSC typically withholds indicators until takedown partners act. No university has publicly quantified downtime for affected labs, and insurance carriers are still reviewing whether cyber policies cover grant-administration fraud absent wire transfers.
What campuses should do this week
CISOs should publish plain-language warnings to faculty lists—not only IT tickets—and test proxy detection rules against known reverse-proxy fingerprints ASD included in the private advisory annex. Research services teams must verify any urgent “portal migration” email through published ARC and NHMRC help-desk numbers, not reply threads.
For academics racing deadlines, the practical rule is blunt: if MFA fired twice for one login, assume interception and call the research office before uploading budget spreadsheets. Grant seasons already stress departments; fake portals turn authentication fatigue into a breach vector ASD says will keep circulating until hardware keys are the default for anyone touching Commonwealth-funded data.
Near-term checkpoints
ARC’s systems team plans to publish a domain verification page researchers can check before entering credentials; NHMRC said it will extend help-desk hours through the linkage window. ASD promised updated indicators if new portals appear after takedowns. Until then, treat every grant link in email as hostile until proven otherwise—a harsh workflow, but cheaper than rebuilding compromised ethics records mid-review.
