• Latest
  • Trending
  • All
  • News
  • Business
  • Politics
  • Science
  • World
  • Lifestyle
  • Tech
Optus: How a massive data breach has exposed Australia

Optus: How a massive data breach has exposed Australia

September 29, 2022
The WhatsApp messages that complicate Johnson’s defence

The WhatsApp messages that complicate Johnson’s defence

March 22, 2023
Gwyneth Paltrow in court as ski crash trial starts

Gwyneth Paltrow in court as ski crash trial starts

March 22, 2023
Casey report: Rape victim says no chance of reforming ‘vile’ Met Police

Casey report: Rape victim says no chance of reforming ‘vile’ Met Police

March 22, 2023
Progestogen-only pill breast cancer risk revealed

Progestogen-only pill breast cancer risk revealed

March 22, 2023
Putin: China plan could end war, but Ukraine and West not ready for peace

Putin: China plan could end war, but Ukraine and West not ready for peace

March 21, 2023
Nursing union accepts Scottish government pay offer

Nursing union accepts Scottish government pay offer

March 21, 2023
Investor fears appear to ease as UK and US share prices rise

Investor fears appear to ease as UK and US share prices rise

March 21, 2023
Ruth Perry: Ofsted urged to pause inspections after teacher death

Ruth Perry: Ofsted urged to pause inspections after teacher death

March 21, 2023
Sri Lanka: $2.9bn IMF bailout for struggling economy

Sri Lanka: $2.9bn IMF bailout for struggling economy

March 21, 2023
Hampshire shark: Appeal for head to be returned

Hampshire shark: Appeal for head to be returned

March 21, 2023
SNP leadership: SNP in ‘tremendous mess’, interim chief says

SNP leadership: SNP in ‘tremendous mess’, interim chief says

March 20, 2023
Credit Suisse bank: UBS is in talks to take over its troubled rival

Credit Suisse bank: UBS is in talks to take over its troubled rival

March 20, 2023
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, March 22, 2023
  • Login
BBC News
  • Home
  • War in Ukraine
  • Coronavirus
  • Climate
  • News
    • All
    • Business
    • Politics
    • Science
    • World
    The WhatsApp messages that complicate Johnson’s defence

    The WhatsApp messages that complicate Johnson’s defence

    Gwyneth Paltrow in court as ski crash trial starts

    Gwyneth Paltrow in court as ski crash trial starts

    Casey report: Rape victim says no chance of reforming ‘vile’ Met Police

    Casey report: Rape victim says no chance of reforming ‘vile’ Met Police

    Progestogen-only pill breast cancer risk revealed

    Progestogen-only pill breast cancer risk revealed

    Nursing union accepts Scottish government pay offer

    Nursing union accepts Scottish government pay offer

    Investor fears appear to ease as UK and US share prices rise

    Investor fears appear to ease as UK and US share prices rise

    Ruth Perry: Ofsted urged to pause inspections after teacher death

    Ruth Perry: Ofsted urged to pause inspections after teacher death

    Sri Lanka: $2.9bn IMF bailout for struggling economy

    Sri Lanka: $2.9bn IMF bailout for struggling economy

    Hampshire shark: Appeal for head to be returned

    Hampshire shark: Appeal for head to be returned

    SNP leadership: SNP in ‘tremendous mess’, interim chief says

    SNP leadership: SNP in ‘tremendous mess’, interim chief says

    Trending Tags

    • Donald Trump
    • Future of News
    • Climate Change
    • Market Stories
    • Election Results
    • Flat Earth
  • Tech
    • All
    • Apps
    • Gear
    • Mobile
    • Startup

    Rap group call out publication for using their image in place of ‘gang’

    Meet the woman who’s making consumer boycotts great again

    New campaign wants you to raise funds for abuse victims by ditching the razor

    Twitter tweaks video again, adding view counts for some users

    A beginner’s guide to the legendary Tim Tam biscuit, now available in America

    India is bringing free Wi-Fi to more than 1,000 villages this year

    Betterment moves beyond robo-advising with human financial planners

    People are handing out badges at Tube stations to tackle loneliness

    Trump’s H-1B Visa Bill spooks India’s IT companies

    Oil spill off India’s southern coast leaves fisherman stranded, marine life impacted

    Trending Tags

    • Flat Earth
    • Sillicon Valley
    • Mr. Robot
    • MotoGP 2017
    • Golden Globes
    • Future of News
  • Entertainment
    • All
    • Gaming
    • Movie
    • Music
    • Sports

    Meet the woman who’s making consumer boycotts great again

    New campaign wants you to raise funds for abuse victims by ditching the razor

    Twitter tweaks video again, adding view counts for some users

    A beginner’s guide to the legendary Tim Tam biscuit, now available in America

    People are handing out badges at Tube stations to tackle loneliness

    Trump’s H-1B Visa Bill spooks India’s IT companies

    Magical fish basically has the power to conjure its own Patronus

    This Filipino guy channels his inner Miss Universe by strutting in six-inch heels and speedos

    Oil spill off India’s southern coast leaves fisherman stranded, marine life impacted

    You can now play Bill Gates’ first PC game and run over donkeys on your iPhone, Apple Watch

  • Lifestyle
    • All
    • Fashion
    • Food
    • Health
    • Travel

    Rap group call out publication for using their image in place of ‘gang’

    Meet the woman who’s making consumer boycotts great again

    New campaign wants you to raise funds for abuse victims by ditching the razor

    Twitter tweaks video again, adding view counts for some users

    India is bringing free Wi-Fi to more than 1,000 villages this year

    Betterment moves beyond robo-advising with human financial planners

    People are handing out badges at Tube stations to tackle loneliness

    Trump’s H-1B Visa Bill spooks India’s IT companies

    Magical fish basically has the power to conjure its own Patronus

    This Filipino guy channels his inner Miss Universe by strutting in six-inch heels and speedos

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
No Result
View All Result
BBC News
No Result
View All Result
Home News

Optus: How a massive data breach has exposed Australia

by BBC News
September 29, 2022
in News
0
Optus: How a massive data breach has exposed Australia
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

By Tiffanie Turnbull

BBC News, Sydney

The front of an Optus storeImage source, Optus

Image caption,

Optus is the country’s second-largest telecommunications company

Last week, Australian telecommunications giant Optus revealed about 10 million customers – about 40% of the population – had personal data stolen in what it calls a cyber-attack.

Some experts say it may be the worst data breach in Australia’s history.

But this week has seen more dramatic and messy developments – including ransom threats, tense public exchanges and scrutiny over whether this constituted a “hack” at all.

It’s also ignited critical questions about how Australia handles data and privacy.

The alarm was sounded last Thursday

Optus – a subsidiary of Singapore Telecommunications Ltd – went public with the breach about 24 hours after it noticed suspicious activity on its network.

Australia’s second biggest telecoms provider said current and former customers’ data was stolen – including names, birthdates, home addresses, phone and email contacts, and passport and driving licence numbers. It stressed that payment details and account passwords were not compromised.

Those whose passport or licence numbers were taken – roughly 2.8 million people – are at a “quite significant” risk of identity theft and fraud, the government has since said.

Optus said it was investigating the breach and had notified police, financial institutions, and government regulators. The breach appears to have originated overseas, local media reported.

In an emotional apology, Optus chief executive Kelly Bayer Rosmarin called it a “sophisticated attack”, saying the company has very strong cybersecurity.

Image source, ABC News

Image caption,

Optus chief executive Kelly Bayer Rosmarin said she was “devastated” by the breach

“Obviously, I am angry that there are people out there that want to do this to our customers, and I’m disappointed that we couldn’t have prevented it,” she said on Friday.

Then a ransom threat was made

Early on Saturday, an internet user published data samples on an online forum and demanded a ransom of $1m (A$1.5m; £938,000) in cryptocurrency from Optus.

The company had a week to pay or the other stolen data would be sold off in batches, the person said.

Investigators are yet to verify the user’s claims, but some experts quickly said the sample data – which contained about 100 records – appeared legitimate.

Sydney-based tech reporter Jeremy Kirk contacted the purported hacker and said the person gave him a detailed explanation of how they stole the data.

The user contradicted Optus’s claims the breach was “sophisticated”, saying they puled the data from a freely accessible software interface.

“No authenticate needed… All open to internet for any one to use,” they said in a message, according to Kirk.

As data circulates, revelations of more stolen details

In another escalation on Tuesday, the person claiming to be the hacker released 10,000 customer records and reiterated the ransom deadline.

But just hours later, the user apologised – saying it had been a “mistake” – and deleted the previously posted data sets.

“Too many eyes. We will not sale [sic] data to anyone,” they posted. “Deepest apology to Optus for this. Hope all goes well from this.”

That sparked speculation about whether Optus had paid the ransom – which the company denies – or whether the user had been spooked by the police investigation.

Adding to the problem, others on the forum had copied the now-deleted data sets, and continued to distribute them.

It also emerged some customers’ Medicare details – government identification numbers that could provide access to medical records – had also been stolen, something Optus did not previously disclose.

Late on Wednesday, the company said this had affected almost 37,000 Medicare cards.

‘Possibly Australia’s most serious breach’

Optus has been inundated with messages from angry customers since last week.

People have been warned to watch out for signs of identity theft and for opportunistic scammers, who are said to be already cashing in on the confusion.

A class-action lawsuit could soon be filed against the company. “This is potentially the most serious privacy breach in Australian history, both in terms of the number of affected people and the nature of the information disclosed,” said Ben Zocco from Slater and Gordon Lawyers.

The government has called the breach “unprecedented” and blamed Optus, saying it “effectively left the window open” for sensitive data to be stolen.

In an ABC television interview on Monday, Cyber Security Minister Clare O’Neil was asked: “You certainly don’t seem to be buying the line from Optus that this was a sophisticated attack?”

“Well, it wasn’t. So no,” Ms O’Neil replied. The moment drew lots of attention online.

Ms Bayer Rosmarin told News Corp Australia on Tuesday: “We have multiple layers of protection. So it is not the case of having some sort of completely exposed APIs [software interfaces] sitting out there.

“I think most customers understand that we are not the villains,” she said, adding Optus could not say more while the investigation was ongoing.

The company has faced calls to cover the costs of replacement passport and driving licences, as people scramble to protect themselves.

‘A decade behind on cyber-security’

The breach highlights how much Australia lags other parts of the world on privacy and cyber issues, Ms O’Neil says.

“We are probably a decade behind… where we ought to be,” she told the ABC.

Both sides of politics have traded blame on the issue. Opposition MPs have said the Labor government is “asleep at the wheel”, but the government points out it was only elected in May after a decade of conservative rule.

Ms O’Neil pointed to two areas needing urgent reform.

She argues the government should be able to better penalise companies like Optus. In some countries, the company would have faced hundreds of millions of dollars in penalties but Australia’s fine is capped at about $2m, she said.

She also wants to expand cyber-security laws that were introduced last year to include telecommunications companies.

“At the time, the telecommunications sector said: “Don’t worry about us – we’re really good at cybersecurity. We’ll do it without being regulated. I would say that this incident really calls that assertion into question.”

Security experts have also suggested reforming data retention laws so telecommunication companies don’t have to keep sensitive information for so long. Ex-customers should also have the right to request companies delete their data, experts say.

Optus says it is required to keep identity data for six years under the current rules.

Other industry figures have argued consumers should be able to take companies that lose control of their information to court, instead of the industry regulator.

Read More

Share196Tweet123Share49
BBC News

BBC News

  • Trending
  • Comments
  • Latest
Support Ukraine’s Children – Donate To Ukraine Crisis

Support Ukraine’s Children – Donate To Ukraine Crisis

September 5, 2022
Women’s football & diversity: ‘We don’t want anyone feeling it’s not their game’

Women’s football & diversity: ‘We don’t want anyone feeling it’s not their game’

October 13, 2022
Bangladesh fuel prices: ‘I might start begging in the street’

Bangladesh fuel prices: ‘I might start begging in the street’

August 14, 2022

Rap group call out publication for using their image in place of ‘gang’

0

Meet the woman who’s making consumer boycotts great again

0

New campaign wants you to raise funds for abuse victims by ditching the razor

0
The WhatsApp messages that complicate Johnson’s defence

The WhatsApp messages that complicate Johnson’s defence

March 22, 2023
Gwyneth Paltrow in court as ski crash trial starts

Gwyneth Paltrow in court as ski crash trial starts

March 22, 2023
Casey report: Rape victim says no chance of reforming ‘vile’ Met Police

Casey report: Rape victim says no chance of reforming ‘vile’ Met Police

March 22, 2023
BBC News

Copyright © 2022 BBC News | Global

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

No Result
View All Result
  • Home
  • News
    • Politics
    • Business
    • World
    • Science
  • Entertainment
    • Gaming
    • Music
    • Movie
    • Sports
  • Tech
    • Apps
    • Gear
    • Mobile
    • Startup
  • Lifestyle
    • Food
    • Fashion
    • Health
    • Travel

Copyright © 2022 BBC News | Global

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In