Skip to main content

Cybercrime That Hits Home: What Frontline Investigations Are Teaching Us

Michael Newman shares what frontline intelligence is revealing about scams, identity crime and AI-enabled threats, and why disrupting cybercrime increasingly depends on collaboration across government, law enforcement and industry.

Behind every scam, identity theft case or cyber incident is a person dealing with the consequences.

Financial loss is often only part of the damage. Victims can also experience embarrassment, emotional trauma, damaged relationships and a lasting loss of confidence.

For Michael Newman, Chief Inspector, Operations Manager, State Intelligence Group, Crime Command, Queensland Police Service, understanding that human impact is essential to understanding the cyber threat landscape itself.

Ahead of Government Cyber Security Showcase Federal 2026, Public Sector Network spoke with Michael about the cybercrime trends causing the greatest harm, the growing use of AI and social engineering, how law enforcement is shifting towards disruption, and why collaboration across jurisdictions and sectors is critical.

Michael will continue the conversation on 22 October in Canberra as part of the panel “Cybercrime That Hits Home – What Frontline Investigations Are Teaching Us About Australia’s Cyber Threat Landscape.”

He will be joined by Sandra Booth, Assistant Commissioner Cyber and Special Investigations, Australian Federal Police, and Sarah Polhill, Chief Information Officer, ACCC for a discussion focused on emerging threats, citizen harm and lessons government can take from frontline investigations.

Government Cyber Security Showcase Federal overview | Register for the event

Interview with Michael Newman

Public Sector Network: From your perspective in the State Intelligence Group and Crime Command, what cybercrime trends are having the most direct impact on Australians right now?

Michael Newman:
Mostly what we're seeing at the moment, and this has been the case for a while now, is that cyber-enabled fraud, scams and identity crime continue to cause the greatest harm due to the scale, accessibility and impact they actually have on victims.

Criminal groups are increasingly operating as transnational enterprises and they're using technology to target thousands of victims simultaneously.

We're starting to see a convergence between traditional organised crime and cyber-enabled offending, particularly in and around fraud, money laundering and illicit financial flows.

That volume of offending means that prevention and disruption are very much as important as investigation and prosecution.


Public Sector Network: Scams and identity theft continue to evolve quickly. What tactics are offenders using that government leaders and service providers need to better understand?

Michael Newman:
Offenders are increasingly exploiting trust rather than technical vulnerabilities.

The way into a person's system, or the way into obtaining a person's details, is by obtaining their trust rather than hacking so much nowadays.

Artificial intelligence is enabling much more convincing impersonation, social engineering and fraud at a scale we haven't seen for quite some time.

They're going to use multiple channels simultaneously, including SMS, email, social media, dating platforms and phone calls.

One trend we're starting to see at the moment is offenders impersonating police officers, telling people they've arrested a suspect and getting details from those people before telling them to go to a local police station where they can make a statement.

They add that element of truth to it, but there's no police officer expecting them at the police station. They've harvested all their details during a seemingly innocuous conversation with a police officer.


Public Sector Network: You mentioned that AI is increasingly being used by offenders. Are law enforcement agencies also using AI to combat these threats?

Michael Newman:
Absolutely.

But we're probably newer to the AI space than we should be.

As with investigating any crime, we're still bound by rules, obligations and the like that criminals don't find themselves quite as fettered by.

We need to be mindful of how we use AI. We need to be very careful that we still maintain the human in the loop, particularly from an intelligence perspective.

As we know, AI can hallucinate. AI can give us false positives and false negatives.

We need to verify everything that AI tells us, particularly when we're using it to sort through data, offences and occurrences.


Public Sector Network: Your upcoming session highlights that behind every cyber incident, scam or identity theft case are real people experiencing harm. What are frontline investigations teaching us about the human impact of cybercrime?

Michael Newman:
The one thing I really want to highlight is that behind every report is a real victim.

They quite often experience embarrassment, financial stress and emotional trauma.

Just because they've been the victim of a cybercrime, people think it's almost victimless, that it's not a real crime. It absolutely is.

There is research out there that shows the impact of these crimes can be as psychologically impactful as a physically violent crime.

The losses frequently extend beyond financial loss. They can include damaged relationships, mental health consequences and loss of confidence.

Older Australians, vulnerable people and small businesses can suffer life-changing consequences at the hands of these offenders.


Public Sector Network: How are law enforcement agencies using intelligence to identify, disrupt and prevent cybercriminal activity before it causes further harm?

Michael Newman:
One of the things we're doing, and I'm going to use a spaghetti and meatballs terminology that was introduced to me by Maurits Rieters, the head of the European Cybercrime Coordination Centre, is looking for the meatballs rather than following every spaghetti noodle.

Instead of following every single case, we're aiming for the intersecting nodes.

We're looking for the criminal networks, the infrastructure and the financial flows rather than just following individual offences, so that we can focus more on disruption as well as investigation.

We're also working much more collaboratively with each other than we ever have, across Australia, Australasia and the world, with data sharing and intelligence collaboration to identify common methodologies and repeat offenders.

More than 90 per cent of our offenders or threat actors for this type of crime are offshore, which limits jurisdictionally based agencies such as Queensland Police, and even the AFP, from arresting people here in Australia.

But that doesn't mean we shouldn't act. We work with our international law enforcement partners to achieve the best outcomes we possibly can.


Public Sector Network: Cybercrime often cuts across jurisdictions, agencies and sectors. What does effective collaboration look like between police, federal agencies, regulators and service providers when responding to these threats?

Michael Newman:
At the end of the day, police are never going to be able to arrest their way out of this.

No single agency can address cybercrime. No single organisation or government can actually do this.

We need to work together and form effective partnerships so that we have timely information sharing, clear governance arrangements and shared objectives.

Police, government agencies, non-government agencies, industry and academia all need to work together to solve this problem.

Some of the best examples I've seen include the National Cyber-Forensics and Training Alliance in the United States.

It's a not-for-profit organisation, but they bring together law enforcement from around the world, private industry, banking institutions and a range of other organisations to work on cyber issues and investigations.

It provides a different level of support to police and investigators to try to solve these issues rather than everybody trying to do it alone.


Public Sector Network: What lessons from real investigations should government agencies apply to improve cyber awareness, reporting pathways, organisational resilience and public trust?

Michael Newman:
At the end of the day, prevention is significantly more effective than responding after victimisation occurs.

We need a lot of messaging around strong identity assurance, fraud controls and staff awareness. They are critical safeguards.

People clicking on a link, we see it all too often. It is that human factor in cybercrime that allows a lot of this to occur.

A lot of the hacking wouldn't occur without somebody clicking on a link they shouldn't have or accidentally releasing information or details that they shouldn't have.

Organisations should be prioritising resilience and recovery planning as much as they are prevention.

Building public trust requires transparency, responsiveness and visible action when incidents do occur.

We need to be telling people when these things happen. We need to give them confidence that we're reacting and responding appropriately.


Public Sector Network: What value do events like Government Innovation Week provide in helping agencies share frontline experiences, build awareness and strengthen collective responses to emerging cyber threats?

Michael Newman:
For me, it's about bringing experts together into the same room where you can actually start to talk face to face.

A shared problem is exactly that, something where you can learn from others.

Others in the room may have had the types of experiences or problems that you're facing, and they can work with you to help deal with them.

You can make those networks and contacts across governments and government agencies that you're not going to be able to make sitting in your own office.

They create opportunities to share lessons learned across different sectors where you face common threats.

The biggest thing for me is that collaboration before a crisis occurs. You know who to turn to in the time of crisis.

Cybercrime That Hits Home

Michael's interview reflects the focus of his upcoming panel at Government Cyber Security Showcase Federal 2026:

Cybercrime That Hits Home – What Frontline Investigations Are Teaching Us About Australia’s Cyber Threat Landscape

Taking place from 10:00 AM to 10:30 AM on Thursday, 22 October, the panel brings together perspectives from policing, federal law enforcement and government to examine what cybercrime looks like when viewed from the frontline.

The discussion will explore:

  • emerging cybercrime, scam and identity theft trends affecting Australians
  • how AI and social engineering are changing offender tactics
  • the growing convergence between organised crime and cyber-enabled offending
  • how intelligence can support earlier disruption
  • collaboration between law enforcement, government and other sectors
  • lessons agencies can apply to awareness, reporting, resilience and public trust

For Michael, one of the most important lessons is that the scale of cybercrime means investigation alone cannot be the answer.

Prevention matters. Disruption matters. Resilience matters. And the relationships between agencies, jurisdictions and sectors need to be established before an incident occurs.

From individual incidents to collective resilience

Michael's session forms part of the wider Government Cyber Security Showcase Federal 2026, bringing together leaders from cyber security, national security, intelligence, critical infrastructure and digital government.

Across the day, the program will examine a threat environment shaped by AI-enabled attacks, identity exploitation, cybercrime, critical infrastructure targeting, supply chain risk and increasingly sophisticated state-sponsored activity. The wider agenda also explores how agencies can strengthen operational continuity, incident response and public trust as government becomes more digitally connected.

For government leaders, Michael's perspective adds an important dimension to that conversation.

Cyber security is not only about systems, vulnerabilities and technical controls. It is also about the people harmed when those controls fail, the tactics criminals use to exploit trust, and the collective response required to reduce that harm.

As Michael puts it, no single organisation can address cybercrime alone.

Bringing agencies together to compare frontline experiences and establish relationships before a crisis is therefore not separate from cyber resilience. It is part of it.

Government Cyber Security Showcase Federal 2026 takes place on Thursday, 22 October 2026 in Canberra, with registration free for government attendees.

Government Cyber Security Showcase Federal overview | Register for the event

Published by

James Ireland Marketing Manager, Marketing