Live data from Hacker News

9M Australians affected by Optus data breach

optus.com.au

91–100 of 104 posts

Re: 9M Australians affected by Optus data breach

#91
post #86

Earlier quoted context omitted.

Yep, my details were part of the breach unfortunately. I hate Optus now more than ever. I left them 2 years ago but they keep my details in a database accessible to the internet? Why? Details leaked are name, email, phone, DOB, home address, drivers license number. About 4 years ago I emailed them complaining that their marketing team were using my date of birth to send me "birthday deals" on my birthday. Something I…

Ah man, I'm sorry to hear that. No emails here yet, but not to say I'm not in the category one down yet (which is only slightly less bad). I'm starting to worry about the general public's understanding of the ramifications of this. When it first broke, I was pretty upset, and my partner (well educated, and with me long enough to understand some things about breaches) thought my concerns and anger at optus was excessi…

> scenarios of what could happen

What could happen?

In my case the home address is old, not my current one, so I dodged a bullet there. That leaves name, DOB and drivers license number. How can those 3 things alone be used?

Email and phone were taken, but nobody can use those if verification is needed. And I can easily change those details in the various places they are used.

I'm quietly confident that because my home address is my old address, and therefore not associated with my drivers license, I'm in better shape than millions of others in this breach.

I'm still angry about it! The email from Optus was tone deaf. They worded it like they are the victims, downplayed the importance, and even ended with "warm regards".

Re: 9M Australians affected by Optus data breach

#92

OP here. Some more information here (not my preferred source, but oh well): https://www.news.com.au/technology/online/hacking/up-to-9-mi... It seems around 2.8m have had 'all' data stolen (including ID, address, etc), and around 7m 'just' names, DoB and numbers/e-mail addresses. Apparently Optus is working on sending personalised details to customers. What a monumental stuff up.

Myself included. All data listed, though they couldn't specify if it was my passport or driver's license number. I haven't been a customer with them for over 5 years.

Re: 9M Australians affected by Optus data breach

#93

DOB, name and address are typically enough details to commit severe identity theft, at least back in 2017 when it happened to me in Australia. Someone stole a letter from my insurer in my mailbox and used my name and address to impersonate me and obtain my DOB and email from my insurer. They then used these details to hijack my phone number (SIM porting) and obtain my bank account details. They ended up hacking into…

> used my name and address to impersonate me and obtain my DOB and email from my insurer

Sounds like the biggest fail was your insurer handing over those details based only on your name and address. How did that work? "Hi, I'm Dave Smith from 101 Easy Street South Sydney, can you tell me my DOB and email please?" Why would the insurer give a customer their own personal details? They are supposed to ask the caller to state those details in order to proceed with account access.

Re: 9M Australians affected by Optus data breach

#94
post #52

In Australia, due to counter terror laws, you can't get a phone sim without providing verifiable government ID. So the consequence of that is that they phone companies have a really large amount of sensitive information. This information loss should be treated like a workplace death. Or a toxic spill. things will only change when a CEO goes to jail for this sort of obvious negligence. It may be harsh, but until there…

It's probably not from prepaid SIM ID checks. Telcos are forbidden from retaining your passport/drivers licence details after your identity has been verified [1].

[1] https://www.legislation.gov.au/Details/F2017L00399 (Section 6.4)

Re: 9M Australians affected by Optus data breach

#95
post #91

Earlier quoted context omitted.

Ah man, I'm sorry to hear that. No emails here yet, but not to say I'm not in the category one down yet (which is only slightly less bad). I'm starting to worry about the general public's understanding of the ramifications of this. When it first broke, I was pretty upset, and my partner (well educated, and with me long enough to understand some things about breaches) thought my concerns and anger at optus was excessi…

> scenarios of what could happen What could happen? In my case the home address is old, not my current one, so I dodged a bullet there. That leaves name, DOB and drivers license number. How can those 3 things alone be used? Email and phone were taken, but nobody can use those if verification is needed. And I can easily change those details in the various places they are used. I'm quietly confident that because my hom…

My main concern is that, with ID, it becomes possible to do a Sim swap or number port, which would be the start of a heap of nightmares. Luckily, buried at the bottom of Optus' announcement, they mention that (for the moment) those can now only be done in person, in-store, with physical ID.

For the other stuff (address, name, DoB)...what are the things nearly everyone asks when you ring to make account changes, to verify you are you..

I'd be careful with the home address too (although you should be ok). I moved around a bit a few years ago, and lost track of where I'd updated my address. It was usually as simple as 'I think my most recent address with you is X, can you please update it to Y', and as long as the other stuff checked out, no questions were asked.

And yeah, I had to laugh about that press release :/

Still no email this side. No news is good news, right?

Re: 9M Australians affected by Optus data breach

#96
How can we protect ourself. What steps can we take given the CEO says the following:

"Importantly, no financial information or passwords have been accessed. The information which has been exposed is your name, date of birth, email, and the number of the ID document you provided such as drivers licence or passport number. No copies of photo IDs have been affected.

It is also important to know that Optus’ network and Optus services including mobile and home Wi-Fi aren’t affected, and no passwords were compromised, so our services remain safe to use and operate as per normal."

Effectively saying, dont change your password. Hackers dont need it.

Re: 9M Australians affected by Optus data breach

#97
post #62

Great. My coworker got hit by massive targeted identity theft which started with their SIM, provided by Optus. The attackers were able to successfully port my coworker’s Optus number and then hacked their Optus email which had everything in it. It took them months to undo the damage, and more trouble was always around the corner usually while they were sleeping or the service being hit didn’t have support staff onlin…

This just twigged something for me - there is now enough information available to easily do number ports, giving someone else control of the number used for MFA. Anything that relies on your number to verify account actions, transactions, etc is now at risk.

Absolutely, and you can bet this is going to happen once this dataset is sold off.

Re: 9M Australians affected by Optus data breach

#98
post #97

Earlier quoted context omitted.

This just twigged something for me - there is now enough information available to easily do number ports, giving someone else control of the number used for MFA. Anything that relies on your number to verify account actions, transactions, etc is now at risk.

Absolutely, and you can bet this is going to happen once this dataset is sold off.

Luckily (buried at the bottom of their announcement), at least for the moment sim swaps, ports, etc are in-person, in-store with physical ID only.

Re: 9M Australians affected by Optus data breach

#99

Because of this I finally decided to complain to my (Australian) bank about their max 6 character (alphanumeric) no symbol password policy... And lack of MFA for personal accounts... And continuing to only offer OTP via SMS to authorise transactions. Well, I tried to complain... for you see after going through multiple pages/steps in the UI, when it came time to review and submit, after you press submit you are told…

ING only requires a customer number, and a four digit PIN for online banking access. The customer number is printed on the back of the cards and at the top of letters. There is no MFA. I wish I was joking.

https://www.ing.com.au/securebanking

Re: 9M Australians affected by Optus data breach

#100

DOB, name and address are typically enough details to commit severe identity theft, at least back in 2017 when it happened to me in Australia. Someone stole a letter from my insurer in my mailbox and used my name and address to impersonate me and obtain my DOB and email from my insurer. They then used these details to hijack my phone number (SIM porting) and obtain my bank account details. They ended up hacking into…

The reliance on using OTP by SMS has become worse in that time, if anything. Although these days they prefer to set up a fake Linkt website and phish the OTPs since Facebook leaked everyone’s mobile numbers.
Post reply on HN