Live data from Hacker News

9M Australians affected by Optus data breach

optus.com.au

61–70 of 104 posts

Re: 9M Australians affected by Optus data breach

#61
If the executive knew at all about the state of security or the potential risk of breach, then they are culpable and should be personally prosecuted.

The story HAS to be that if you, as an exec in power, know your company has deficient safety protocols regarding its care of toxic material, the breach of which is known to cause serious damage and harms, AND you do nothing: hello personal prosection, reaching right through the corporate veil.

Until we set this kind of legal precedent for the egregious disregard for the integrity of private and personal data, this is just going to keep happening.

Re: 9M Australians affected by Optus data breach

#62
Great.

My coworker got hit by massive targeted identity theft which started with their SIM, provided by Optus. The attackers were able to successfully port my coworker’s Optus number and then hacked their Optus email which had everything in it. It took them months to undo the damage, and more trouble was always around the corner usually while they were sleeping or the service being hit didn’t have support staff online. Do Optus even have any security checks at all for preventing fraud?

Lessons: if the service doesn’t support MFA, don’t use it; don’t put all your service eggs in one basket; don’t assume that your phone number is safe, and act accordingly.

Optus needs to pay for this and I don’t just mean dollars. Comfortable people with responsibilities they didn’t failed to keep need to see gaol time, or at the very least lose their jobs and not be allowed to walk back into the revolving door for a long time. This is outrageous.

Re: 9M Australians affected by Optus data breach

#63
post #52

In Australia, due to counter terror laws, you can't get a phone sim without providing verifiable government ID. So the consequence of that is that they phone companies have a really large amount of sensitive information. This information loss should be treated like a workplace death. Or a toxic spill. things will only change when a CEO goes to jail for this sort of obvious negligence. It may be harsh, but until there…

Optus CEO Kelly Bayer Rosmarin did an interview with ABC today, and said "some of the customer information is information you would find on Facebook or LinkedIn such as name, date of birth, phone number and email address". Umm...no. Most people do NOT publicise that information to the public. Agreed. Until a CEO goes to jail for something like this, it'll continue to become a "pay the fine and move on" situation.

Worth keeping in mind that Optus recently hired Gladys Berejiklian, which may say something about the character of the company:

https://finance.yahoo.com/news/optus-appoints-ex-nsw-premier...

For international readers, Gladys Berejiklian was the Premier of the state of New South Wales, and resigned as Premier once it became public that she and her boyfriend were being investigated by the Independent Commission Against Corruption. Optus is the job she accepted while the corruption investigation continued.

https://au.finance.yahoo.com/news/gladys-berejiklian-resigns...

Re: 9M Australians affected by Optus data breach

#64
DOB, name and address are typically enough details to commit severe identity theft, at least back in 2017 when it happened to me in Australia. Someone stole a letter from my insurer in my mailbox and used my name and address to impersonate me and obtain my DOB and email from my insurer. They then used these details to hijack my phone number (SIM porting) and obtain my bank account details. They ended up hacking into my online banking (because my bank used and still uses SMS based OTP, not a device key - St George Bank, I’m looking at you) and tried withdrawing thousands of dollars in cash from an atm using cardless withdrawal. They didn’t succeed because I was overseas at the time and the bank fraud monitoring picked it up on the spot and froze all my cards. Very scary indeed and firm proof that you can do a lot of damage with very little information about someone, at least in Australia.

Re: 9M Australians affected by Optus data breach

#65
post #12

This is bad. Australia isn't know for it's strong privacy laws anyway, but with the kind of data that's now available out there, ID theft is going to be a huge risk for almost half the country. Even if Optus gets sued, how the hell are people supposed to protect themselves?

To protect themselves, I suspect services like "credit monitoring and alerting" services will see increased subscribers in coming months. I'm in no way affiliated, but an example is https://www.equifax.com.au/lp/protect-your-identity AUD$15 per month to tell you if your details are leaked or used to create an account in your name.

https://en.wikipedia.org/wiki/2017_Equifax_data_breach

Re: 9M Australians affected by Optus data breach

#66
post #62

Great. My coworker got hit by massive targeted identity theft which started with their SIM, provided by Optus. The attackers were able to successfully port my coworker’s Optus number and then hacked their Optus email which had everything in it. It took them months to undo the damage, and more trouble was always around the corner usually while they were sleeping or the service being hit didn’t have support staff onlin…

This just twigged something for me - there is now enough information available to easily do number ports, giving someone else control of the number used for MFA. Anything that relies on your number to verify account actions, transactions, etc is now at risk.

Re: 9M Australians affected by Optus data breach

#67
I know Optus would have had a copy of my drivers license on record.. quite possibly my passport as well ;(

Haven’t actually received any communication about the breach from them yet either.

Seems like a complete screw up. They couldn’t even notify their customers before everyone found out on the news.

I wouldn’t trust Vodafone to organise a piss up in a brewery… maybe Telstra are better (hah!)

Re: 9M Australians affected by Optus data breach

#69

Earlier quoted context omitted.

I'm an Australian living in Sweden who loves BankID but I don't trust the Aus Govt to provide a similar service.

I hear this often, and as an Aussie techie it's such a shame. Whether or not it's true, it almost certainly means we'll never try. How do we get past this?

Personally, it would take strong legislation preventing any variation of law enforcement having any access to any of the data, even that of convicted criminals, to make me comfortable to provide mine into the system. Perhaps even constitutional change prohibiting it. Currently, home affairs could feasibly access any data in just about anything the government does with barely a sign-off which I’m not comfortable with.

Our laws protecting us from the government are way too weak for systems like this to take off. Also we keep hiring contractors who do a fairly poor job building the things in the first place.

Re: 9M Australians affected by Optus data breach

#70
post #25

> Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers Okay so this was half the country. I cant honestly understand how anyone thinks KYC laws make sense if anyone can make a bank account as anyone else, and it all looks like legitimate money or the…

You can't make an account with the number or a scan of an ID document (at least here in the EU, but i doubt it'd be much different down under). The real thing is required, or in the case of neobanks, multiple photos at specific angles + selfie from their app.

All it takes to register a new number here, are your details including name, DoB, physical address (all the complete ones leaked), the type of ID used (passport, drivers license) and the number on that ID. You can do it in about 5 minutes online, and the number is then active (but not before).

Not even a copy of the document is required, and it doesn't have to be sighted by anyone. From memory, you don't even have to supply the expiry date on the document (and driver's license numbers remain static).

One of the first things I see happening, is criminals using this to obtain burner numbers not traceable to them.

Post reply on HN