Live data from Hacker News

9M Australians affected by Optus data breach

optus.com.au

41–50 of 104 posts

Re: 9M Australians affected by Optus data breach

#41
post #9

FYI optics is Australia's second largest telecommunications provider. This would be the worst known databreach in Australian history. It is interesting that compared to identity theft announcements from many US corporations they are direct, apologize and state the authorities they are working with. I imagine there's less fear of the legal consequences of not having a tight response as the culture isn't as litigious.

The recent update to Cyber Security legislation in Australia specifically states that any major breach must be reported to the Australian Cyber Security Centre within 24 hours of becoming aware of it. "MAJOR" being subjective, but this easily qualifies.

There are significant penalties for not disclosing within this time period, which is why I think we are seeing this reported before Optus has a clearer plan of how to deal with it.

As a customer of Optus and cyber security trained professional, I'm very frustrated, to say the least.

Re: 9M Australians affected by Optus data breach

#43

> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers. Payment detail and account passwords have not been compromised. Geez, ID document numbers is such a big thing. Now hackers can basically call most institution and impersonate victims. this is qu…

Yup. It's massive.

Re: 9M Australians affected by Optus data breach

#45
OP here.

Some more information here (not my preferred source, but oh well): https://www.news.com.au/technology/online/hacking/up-to-9-mi...

It seems around 2.8m have had 'all' data stolen (including ID, address, etc), and around 7m 'just' names, DoB and numbers/e-mail addresses.

Apparently Optus is working on sending personalised details to customers.

What a monumental stuff up.

Re: 9M Australians affected by Optus data breach

#46
post #8

"Payment detail and account passwords have not been compromised." No, just your identity is. If you're Australian, you or someone you know will be in this. What a total fuck up.

And why, oh why, are past customers in there. I'm a current one, but even 'not being with them' doesn't necessarily exclude you from this.

Re: 9M Australians affected by Optus data breach

#47
Glad I dumped them 2 years ago. I hated their imposed "non direct debit fee" if you elected to pay manually instead of direct debit.

I hated their mandatory text messages that couldn't be blocked, such as upcoming bill reminders. Spam my email as much as you want, but stay out of my text messages!

Re: 9M Australians affected by Optus data breach

#48
post #47

Glad I dumped them 2 years ago. I hated their imposed "non direct debit fee" if you elected to pay manually instead of direct debit. I hated their mandatory text messages that couldn't be blocked, such as upcoming bill reminders. Spam my email as much as you want, but stay out of my text messages!

Former customers are also included in the breach, just in case you thought you were safe not being a customer anymore.

Re: 9M Australians affected by Optus data breach

#49
post #24

> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers. Payment detail and account passwords have not been compromised. Geez, ID document numbers is such a big thing. Now hackers can basically call most institution and impersonate victims. this is qu…

It shows why we need to rapidly embrace the idea that knowledge of an ID document number and its associated personal details is insufficient proof of identity.

this brings up a very important question - how does one verify one's identity with a business? Esp. online, without having to meet in person at some sort of branch/store?

Re: 9M Australians affected by Optus data breach

#50
post #35

It's long past time for countries to embrace the digital id the way Estonia (and a few others) have. For comparison, visit https://www.telia.ee/en and you're prompted for your smart card or associated Smart ID (which is mobile app you can bootstrap from your smart card). No more need to do a 100 point check (and then hold that information indefinitely), it's been done. Even if you don't like the Estonian system it's…

I'm an Australian living in Sweden who loves BankID but I don't trust the Aus Govt to provide a similar service.
Post reply on HN