As the Optus hacker appears to release data of 10,000 customers, Optus CEO Kelly Bayer Rosmarin says the Australian police are investigating a ransom demand
Australian mobile-phone company Optus said authorities are investigating an online ransom demand following a major data hack …
BloombergAngus Whitley
Context & Ripple Effects
The ransom demand escalates the initial Optus breach, which the company said may have exposed data from up to 9.8 million customers. It also sharpens scrutiny of Optus’s prior resistance to stronger customer-data rights, documented in its privacy-law lobbying record.
The apparent posting of data makes the incident more than a containment problem: Australian police are now investigating an extortion attempt while affected customers face the immediate consequences of exposure.
First-order effects
Optus must manage an active extortion incident alongside the original breach response, while Australian police investigate the ransom demand.
The 10,000 customers whose data appears to have been released face a more immediate risk profile than customers whose information was only potentially accessed.
Second-order effects
The escalation strengthens the basis for the projected breach costs facing Optus parent Singtel, which were later estimated for the worst-affected customers in post-breach cost analysis.
Australian policymakers gain a concrete case for the later proposal allowing telcos to share customer IDs with banks during breaches, linking telecom security failures to fraud monitoring.
Third-order effects
If major breaches repeatedly progress from unauthorized access to public data extortion, telecom privacy obligations will be judged by the usefulness of customer protections after a breach, not solely by prevention controls.
The Optus episode and the later Medibank data posting point to a broader Australian market in which stolen customer records create regulatory and financial exposure across consumer-facing institutions.
The trend: Large consumer-data breaches are becoming extortion events that push telecoms, banks, and regulators toward coordinated post-breach protection measures.
Minister for Cyber Security @ClareONeilMP says Australia is “probably a decade behind” in privacy protections, and the government “has to be involved when the stakes are this high” following Optus' cyber security breach. Watch her full interview with Laura Tingle below. #abc730 h…
Victims of Optus data hack are now receiving text messages from hackers demanding $2000AUD be paid into a CBA bank account, with threats their data will be sold for “fraudulent activity within 2 days.” @9NewsAUS https://twitter.com/...
The biggest reason not to load the data though is that the leaked 10.2k records represents only a tiny portion of the total corpus of records. 99.x% of people people impacted by the breach would get back “not pwned” (at least not in Optus), and that's misleading and confusing.
At this stage, I don't intend to load any Optus data into @haveibeenpwned. Let me explain the reasoning: It looks like Optus has proactively reached out to impacted customers so in terms of answering “Have I Been Pwned?”, disclosure and notification has already happened.
Just speculating here, but providing a CBA bank account — in Australia, easy for authorities to nail! — seems a little too basic and unwise for even a moderately savvy “hacker”. Also a reminder that it's easy to randomly generate numbers for text spam. https://twitter.com/...
I hate to agree, but yes, the gvt should issue new passports for Optus data breach victims whose leaked data included passport details. And charge the cost to Optus. But DFAT won't like this, because there's already a massive passport backlog https://twitter.com/...
I am incredibly concerned this morning about reports that personal information from the Optus data breach, including Medicare numbers, are now being offered for free and for ransom. Medicare numbers were never advised to form part of compromised information from the breach.
Key point in this Optus saga is why did this private (phone) company have the passport/ licence details of millions Australians in the first place? (Hint: Internationally & democratically inappropriate surveillance state legislative requirements slipped through in recent years). …
Following the Optus data breach, Services Australia have just informed me that myGov accounts cannot be accessed with just a Medicare number. For more info: https://servicesaustralia.gov.au/ ...
All South Australians impacted by the @Optus data theft issue will receive a new drivers licence free of charge at any Service SA centre. All we need is evidence you're a Optus customer. https://twitter.com/...