Optus, Australia’s second-largest telecoms provider, disclosed a cyber attack that exposed personal information of current and former customers. The company later said up to 9.8 million people were affected, roughly a third of Australia’s population.
What happened
- Exposed data included names, dates of birth, phone numbers, and email addresses, and for some customers addresses and identity document numbers.
- Optus said around 2.1 million customers had at least one identity document number compromised.
- Reports said the data was accessed through an internet-facing API that did not require authentication.
- A purported attacker demanded a ransom and leaked some records before withdrawing the demand.
Why it mattered
The breach prompted the Australian government to raise maximum penalties for serious privacy breaches and sparked debate about how long companies should keep identity data. Optus’s chief executive publicly apologised, and the company offered affected customers identity protection services and help with replacing some identity documents.
Lessons for organisations
Organisations should inventory and test all internet-facing APIs for authentication, and apply data minimisation and retention limits so that former customers’ identity data is not kept longer than needed. Regular external attack surface reviews help find forgotten test or legacy interfaces.
Sources: TechCrunch, Al Jazeera
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.