Australian telecom Optus suffers a cyberattack, potentially giving the hacker access to data on up to 9.8M customers, per the CEO; the police are investigating
Australian telecoms company says mass breach could have exposed birth dates, phone numbers and other personal data
Wall Street JournalAlice Uribe
Context & Ripple Effects
The incident quickly escalated from a reported intrusion to an apparent release of 10,000 customer records and a ransom demand in the related coverage, sharpening the stakes for Optus and the police investigation. It also put fresh pressure on Optus's prior opposition to stronger customer privacy rights, documented in its earlier resistance to privacy-law changes.
First-order effects
Up to 9.8 million Optus customers face exposure of personal details, while Australian police investigate the attack and Optus must manage the alleged ransom demand after the apparent release of 10,000 records.
Optus and parent Singtel immediately inherit breach-response and remediation costs; experts later estimated the worst-affected cohort could cost Singtel $420M to $560M.
Second-order effects
Australia's proposed post-Optus privacy changes would let telcos share customer IDs with banks for breach monitoring, extending incident response from the carrier to financial institutions.
Third-order effects
The breach points toward a stricter privacy regime in which telecoms' retention and handling of identity data face greater scrutiny, particularly where providers have opposed expanded customer rights.
The trend: Major telecom breaches are pushing privacy policy toward coordinated, cross-industry monitoring of compromised identity data.
“We are devastated to discover that we have been subject to a cyberattack that has resulted in the disclosure of our customers' personal information to someone who shouldn't see it” https://www.optus.com.au/...
Disturbing- the massive Optus data breach may be due to human error which allowed criminals to steal personal details of potentially millions of customers. If companies are holding highly sensitive personal data they must be held accountable for ensuring it is safe from hackers. …
wow — “Information which may have been exposed includes customers' names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers.l https://twitter.com/...
Optus didn't answer my question this morning on the media call about how customer data — especially ID numbers — were stored. Here's the response they've now sent through: https://twitter.com/...
I'm not concerned by the Optus data leak. Rental applications these days pretty much demand everything up to and including genetic sequencing and those things are secured by perhaps the least competent people on earth. All that info is already leaked.
This 🧵 💯 👇🏼 If the risk was acceptable then it's Optus at fault. If appropriate security controls were “too difficult” to implement then it's Optus at fault. The more that gets revealed about the Optus breach, the more it points to entrenched culture shortcomings! https://twitter…
So Optus created an unauthenticated API to the customer database and then exposed it to a test system. But they so no human error was involved and blamed it on a sophisticated attack. A breakdown...