Site navigation

Optus Cyber-attack | What You Need to Know

David Paul

,

Optus cyber-attack
The Australian telecommunications giant has been hit by a major attack, with potentially millions of customers affected.

Major Australian telecoms company, Optus, has revealed details of a massive cyber-attack that hit its systems this week.

It is believed that the hackers gained access to the details of millions of current and previous customers in what could be the largest attack of its kind in Australia.

Customer names, dates of birth, phone numbers and email addresses have supposedly been leaked.

Optus has more than ten million customers and provide a variety of services. It is currently Australia’s second-largest telecoms company.

The firm said the attack has been stopped, but not before other details such as driver’s licences and passport numbers were hacked.

However, payment data and account passwords were not compromised, Optus added.

Optus’ services, including mobile and home internet, have also not been affected, and messages and voice calls have not been compromised. The company has stated that their services remain safe to use and operate as per normal.


What does Optus say?

“Following a cyber-attack, Optus is investigating the possible unauthorised access of current and former customers’ information,” the company said in a statement.

The company added that, once the attack had been discovered, they moved to combat it. It is working with the Australian Cyber Security Centre to mitigate any risks to customers.

Optus also added that the Australian Federal Police, the Office of the Australian Information Commissioner, and key regulators have been notified.

Those at “heightened risk” would also be informed Optus added, but all customers should check their accounts.

Kelly Bayer Rosmarin, Optus CEO, commented: “We are devastated to discover that we have been subject to a cyber-attack that has resulted in the disclosure of our customers’ personal information to someone who shouldn’t see it.

“As soon as we knew, we took action to block the attack and began an immediate investigation. While not everyone maybe affected and our investigation is not yet complete, we want all of our customers to be aware of what has happened as soon as possible so that they can increase their vigilance. We are very sorry and understand customers will be concerned.

“Please be assured that we are working hard, and engaging with all the relevant authorities and organisations, to help safeguard our customers as much as possible.”


Authorities have been notified

Optus disclosed that the Office of the Australian Information Commissioner (OAIC) had been contacted and made aware of their data breach.

The OAIC said it would engage with the company “to ensure compliance with the requirements of the Notifiable Data Breaches (NDB) scheme in accordance with our usual process.”

Under the scheme, organisations covered by the Privacy Act 1988 have an obligation to notify affected individuals and the OAIC as quickly as possible if they experience a data breach if it could result in harm to individuals is a breach of personal information.

The NDB scheme ensures individuals are informed and can take steps to protect themselves from any further risk. Following a breach, individuals need to be alert to any suspicious or unexpected activity on their personal accounts or devices.


Recommended


Commenting on the Optus breach, Hugh Raynor, Senior Cybersecurity Consultant at SureCloud, said: “This attack on Optus appears to be via a vulnerability or misconfiguration in its perimeter infrastructure, specifically one of its firewalls.

“We don’t know much more than that at the moment, but it does appear to be a slightly different attack vector to a lot of attacks these days that focus on social engineering, such as the recent events with Uber and Revolut.

“These attacks appear to be data gathering exercises. It’s very difficult for a cybercriminal to get into an organisation and steal funds or payment data. It’s much easier to get in and steal user data instead. Attackers can then either sell that data or use it to launch further cyber-attacks on the individuals via phishing or malware laden emails, or even commit identity fraud.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

David Paul

Staff Writer, DIGIT

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences