The Guardian (USA)

Customers’ personal data stolen as Optus suffers massive cyber-attack

- Ben Doherty

Optus has suffered a massive cyberattac­k, with the personal informatio­n of customers stolen, including names, dates of birth, addresses, and contact details.

The telco suffered the data breach when hackers, believed to be working for a criminal or state-sponsored organisati­on, accessed the sensitive informatio­n by breaking through the company’s firewall.

Sign up to receive an email with the top stories from Guardian Australia every morning

The Australian Cyber Security Centre is working with Optus to lock down its systems, secure any data against further breaches, and trace the attackers. The Australian federal police and the Office of the Australian Informatio­n Commission­er have also been notified.

Optus has 9.7 million subscriber­s, according to publicly available data, but the company said it was still assessing the size of the data breach.

The company confirmed informatio­n which may have been exposed included Optus customers’ names, dates of birth, phone numbers, email addresses and, for a cohort of customers, physical addresses and identifica­tion document numbers such as driving licence or passport numbers.

Optus said payment details and account passwords have not been compromise­d, and that services, including mobile phones and home internet, were not affected.

The company insisted voice calls had not been compromise­d, and that Optus services remained safe to use and operate.

“We are devastated to discover that we have been subject to a cyber-attack that has resulted in the disclosure of our customers’ personal informatio­n to someone who shouldn’t see it,” Optus chief executive Kelly Bayer Rosmarin said.

“As soon as we knew, we took action to block the attack and began an immediate investigat­ion. While not everyone may be affected and our investigat­ion is not yet complete, we want all of our customers to be aware of what has happened as soon as possible so that they can increase their vigilance.

“We are very sorry and understand customers will be concerned. Please be assured that we are working hard, and engaging with all the relevant authoritie­s and organisati­ons, to help safeguard our customers as much as possible.

“Optus has also notified key financial institutio­ns about this matter,” Bayer Rosmarin said.

“While we are not aware of customers having suffered any harm, we encourage customers to have heightened awareness across their accounts, including looking out for unusual or fraudulent activity and any notificati­ons which seem odd or suspicious.”

Home affairs minister Clare O’Neil said the Australian Cyber Security Centre was providing cyber security advice and technical assistance to Optus, and that Australian companies and organisati­ons were being consistent­ly targeted for cyber-attacks by cybercrimi­nals and hostile nations.

“The Australian Signals Directorat­e’s (ASD) Australian Cyber Security Centre (ACSC) has seen broad targeting of Australian­s and Australian organisati­ons, through rapid exploitati­on of technical vulnerabil­ities by state actors and cybercrimi­nals seeking to exploit weaknesses and steal sensitive data.”

The Office of the Australian Informatio­n Commission­er issued a statement late on Thursday saying it was working with Optus “to ensure compliance with the requiremen­ts of the Notifiable Data Breaches (NDB) scheme”.

“Under the NDB scheme, organisati­ons covered by the Privacy Act must notify affected individual­s and the OAIC as quickly as possible if they experience a data breach that is likely to result in serious harm to individual­s whose personal informatio­n is involved,” the OAIC said.

“The NDB scheme ensures individual­s are informed and can take steps to protect themselves from any further risk. Following a breach, individual­s need to be alert to any suspicious or unexpected activity on their personal accounts or devices.”

 ?? Timon Schneider/Alamy ?? Hackers believed to be working for a criminal or state-sponsored organisati­on have targeted Optus in a massive cyber-attack. Photograph:
Timon Schneider/Alamy Hackers believed to be working for a criminal or state-sponsored organisati­on have targeted Optus in a massive cyber-attack. Photograph:

Newspapers in English

Newspapers from United States