TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

9M Australians affected by Optus data breach

136 pointsby tonteldoosover 2 years ago

28 comments

jiggawattsover 2 years ago
I’ve seen Optus “computer security” in action. I use quotes for a reason.<p>There was a court-enforced order requiring them to apply security updates to their production systems. That was in response to a <i>previous</i> breach.<p>You see, until a judge made them do it… they weren’t patching anything. They would just build systems and <i>walk away</i>. For some software systems they had every major and minor version deployed, like a museum of software history.<p>They had operating system versions in production that were in my university text books… in the late 1990s.<p>Their interpretation of the court order was to update <i>only</i> production systems. Non-production on the same network was not to be touched.<p>And by “update” they meant simply running the system update tool, which does precisely nothing on software that has passed its end-of-extended-support before some of the IT staff on the payroll were <i>born</i>.<p>They also fired their entire IT staff recently and replaced them with a low-cost Indian outsourcer.<p>Most of the above is a matter of public record. I wish I could tell you all about things that are still under NDA.
评论 #32935441 未加载
评论 #32935526 未加载
评论 #32935747 未加载
评论 #32948229 未加载
评论 #32967564 未加载
gonzo41over 2 years ago
In Australia, due to counter terror laws, you can&#x27;t get a phone sim without providing verifiable government ID. So the consequence of that is that they phone companies have a really large amount of sensitive information. This information loss should be treated like a workplace death. Or a toxic spill. things will only change when a CEO goes to jail for this sort of obvious negligence. It may be harsh, but until there&#x27;s real consequences, nothing will change.
评论 #32936756 未加载
评论 #32970116 未加载
robertwt7over 2 years ago
&gt; Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver&#x27;s licence or passport numbers. Payment detail and account passwords have not been compromised.<p>Geez, ID document numbers is such a big thing. Now hackers can basically call most institution and impersonate victims. this is quite huge
评论 #32935492 未加载
评论 #32936664 未加载
评论 #32936143 未加载
tonteldoosover 2 years ago
OP here.<p>Some more information here (not my preferred source, but oh well): <a href="https:&#x2F;&#x2F;www.news.com.au&#x2F;technology&#x2F;online&#x2F;hacking&#x2F;up-to-9-million-aussies-affected-in-major-optus-data-breach&#x2F;news-story&#x2F;c3e98ef6123f4871739cc1525fddd6ef" rel="nofollow">https:&#x2F;&#x2F;www.news.com.au&#x2F;technology&#x2F;online&#x2F;hacking&#x2F;up-to-9-mi...</a><p>It seems around 2.8m have had &#x27;all&#x27; data stolen (including ID, address, etc), and around 7m &#x27;just&#x27; names, DoB and numbers&#x2F;e-mail addresses.<p>Apparently Optus is working on sending personalised details to customers.<p>What a monumental stuff up.
评论 #32968997 未加载
fblpover 2 years ago
FYI optics is Australia&#x27;s second largest telecommunications provider. This would be the worst known databreach in Australian history.<p>It is interesting that compared to identity theft announcements from many US corporations they are direct, apologize and state the authorities they are working with. I imagine there&#x27;s less fear of the legal consequences of not having a tight response as the culture isn&#x27;t as litigious.
评论 #32936134 未加载
hestefiskover 2 years ago
DOB, name and address are typically enough details to commit severe identity theft, at least back in 2017 when it happened to me in Australia. Someone stole a letter from my insurer in my mailbox and used my name and address to impersonate me and obtain my DOB and email from my insurer. They then used these details to hijack my phone number (SIM porting) and obtain my bank account details. They ended up hacking into my online banking (because my bank used and still uses SMS based OTP, not a device key - St George Bank, I’m looking at you) and tried withdrawing thousands of dollars in cash from an atm using cardless withdrawal. They didn’t succeed because I was overseas at the time and the bank fraud monitoring picked it up on the spot and froze all my cards. Very scary indeed and firm proof that you can do a lot of damage with very little information about someone, at least in Australia.
评论 #32969111 未加载
评论 #32992788 未加载
kdtshover 2 years ago
Great.<p>My coworker got hit by massive targeted identity theft which started with their SIM, provided by Optus. The attackers were able to successfully port my coworker’s Optus number and then hacked their Optus email which had everything in it. It took them months to undo the damage, and more trouble was always around the corner usually while they were sleeping or the service being hit didn’t have support staff online. Do Optus even have any security checks at all for preventing fraud?<p>Lessons: if the service doesn’t support MFA, don’t use it; don’t put all your service eggs in one basket; don’t assume that your phone number is safe, and act accordingly.<p>Optus needs to pay for this and I don’t just mean dollars. Comfortable people with responsibilities they didn’t failed to keep need to see gaol time, or at the very least lose their jobs and not be allowed to walk back into the revolving door for a long time. This is outrageous.
评论 #32937638 未加载
top_postover 2 years ago
&quot;Payment detail and account passwords have not been compromised.&quot;<p>No, just your identity is. If you&#x27;re Australian, you or someone you know will be in this. What a total fuck up.
评论 #32936232 未加载
qweryover 2 years ago
&gt; Optus notifies customers of cyberattack compromising customer information<p>- the notification being finding a link to their quietly released press release on HN this afternoon? Thanks Optus!<p>- cyberattack is the word to use to encourage speculation that a nation-state was behind the breach, that there was no way to defend against this and to avoid saying &quot;data breach&quot;<p>- here &quot;customer information&quot; means <i>current and former Optus customers&#x27; personal information</i>
popcorncowboyover 2 years ago
If the executive knew <i>at all</i> about the state of security or the potential risk of breach, then they are culpable and should be <i>personally</i> prosecuted.<p>The story HAS to be that if you, as an exec in power, <i>know</i> your company has deficient safety protocols regarding its care of toxic material, the breach of which is <i>known</i> to cause serious damage and harms, AND you do nothing: hello personal prosection, reaching right through the corporate veil.<p>Until we set this kind of legal precedent for the egregious disregard for the integrity of private and personal data, this is just going to keep happening.
Traubenfuchsover 2 years ago
I want to point out that Optus also offers a Digital Identity verification solution via Mastercards DI infrastructure. I am currently implementing Mastercards DI solution somewhere...<p>The way that is implemented SHOULD be mostly unhackable, with everything server side being encrypted and inaccessible without user action and communication with MCs backend.<p>Still, this is not a good look for trust. Should we now go to Australian customers and say &quot;and now you authenticate via the Optus app, it&#x27;s super secure&quot; while they immediately think of this hack?<p><a href="https:&#x2F;&#x2F;www.optus.com.au&#x2F;customer-extras&#x2F;mastercard-id" rel="nofollow">https:&#x2F;&#x2F;www.optus.com.au&#x2F;customer-extras&#x2F;mastercard-id</a>
triggercutover 2 years ago
Because of this I finally decided to complain to my (Australian) bank about their max 6 character (alphanumeric) no symbol password policy... And lack of MFA for personal accounts... And continuing to only offer OTP via SMS to authorise transactions.<p>Well, I tried to complain... for you see after going through multiple pages&#x2F;steps in the UI, when it came time to review and submit, after you press submit you are told that they can&#x27;t receive complaints online at this time.<p>So I wrote in the web feedback form instead. At least that went through. As will, I hope, my screenshots of the process to the ombudsman.<p>In nearly all these microservice components, the UI has an outdated copyright year in the footer. 2016 in the feedback app, 2017 in a preference update component. The year sits right underneath a lock symbol and some text telling you how secure they are.<p>This tells me a number of things. Either no one has smoke-tested that component for 6 years, or picked up that the year was off, or it has been picked up and left in backlog because of other priorities leaving me to ask what else could be in the aged backlog, but really telling me they don&#x27;t have the resources to do or to take software or UX seriously.
评论 #32989506 未加载
评论 #32950302 未加载
评论 #32950650 未加载
Karupanover 2 years ago
This is bad. Australia isn&#x27;t know for it&#x27;s strong privacy laws anyway, but with the kind of data that&#x27;s now available out there, ID theft is going to be a huge risk for almost half the country. Even if Optus gets sued, how the hell are people supposed to protect themselves?
评论 #32936948 未加载
yieldcrvover 2 years ago
&gt; Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, <i>ID document numbers such as driver&#x27;s licence or passport numbers</i><p>Okay so this was half the country.<p>I cant honestly understand how anyone thinks KYC laws make sense if anyone can make a bank account as anyone else, and it all looks like legitimate money <i>or</i> the human is getting framed while the criminal just rotates IDs.
评论 #32935505 未加载
评论 #32936048 未加载
tsujpover 2 years ago
For those not aware this is about 35% of the population of Australia which is around 26 million.
评论 #32935333 未加载
ps-ozover 2 years ago
How can we protect ourself. What steps can we take given the CEO says the following:<p>&quot;Importantly, no financial information or passwords have been accessed. The information which has been exposed is your name, date of birth, email, and the number of the ID document you provided such as drivers licence or passport number. No copies of photo IDs have been affected.<p>It is also important to know that Optus’ network and Optus services including mobile and home Wi-Fi aren’t affected, and no passwords were compromised, so our services remain safe to use and operate as per normal.&quot;<p>Effectively saying, dont change your password. Hackers dont need it.
exodustover 2 years ago
Glad I dumped them 2 years ago. I hated their imposed &quot;non direct debit fee&quot; if you elected to pay manually instead of direct debit.<p>I hated their mandatory text messages that couldn&#x27;t be blocked, such as upcoming bill reminders. Spam my email as much as you want, but stay out of my text messages!
评论 #32936367 未加载
ehPRethover 2 years ago
i wonder if passwords really haven’t been affected or if they’re just hashed so they think they can get away with saying that
YPPHover 2 years ago
Today is a one-off national public holiday in Australia to mourn the loss of the Queen. I&#x27;d be curious to know when this attack started and whether it coincided with the public holiday by chance or by choice.
评论 #32935713 未加载
ostenningover 2 years ago
CEO Should absolutely be charged with criminal negligence. Throw the book at him.
评论 #32965993 未加载
steve_mcdougallover 2 years ago
How could Dan Andrews let this happen? &#x2F;s
评论 #32935897 未加载
评论 #32935654 未加载
vertisover 2 years ago
It&#x27;s long past time for countries to embrace the digital id the way Estonia (and a few others) have.<p>For comparison, visit <a href="https:&#x2F;&#x2F;www.telia.ee&#x2F;en" rel="nofollow">https:&#x2F;&#x2F;www.telia.ee&#x2F;en</a> and you&#x27;re prompted for your smart card or associated Smart ID (which is mobile app you can bootstrap from your smart card).<p>No more need to do a 100 point check (and then hold that information indefinitely), it&#x27;s been done.<p>Even if you don&#x27;t like the Estonian system it&#x27;s high time to get serious about digital identity and stop pretending that knowing your DoB etc (or social security number in US) is a secure mechanism of proving identity.<p>Aside: Highly recommend Estonia&#x27;s e-residency program. Great place to run a company. Future focused.
评论 #32936450 未加载
jeeebover 2 years ago
I know Optus would have had a copy of my drivers license on record.. quite possibly my passport as well ;(<p>Haven’t actually received any communication about the breach from them yet either.<p>Seems like a complete screw up. They couldn’t even notify their customers before everyone found out on the news.<p>I wouldn’t trust Vodafone to organise a piss up in a brewery… maybe Telstra are better (hah!)
jaimex2over 2 years ago
Ah, good old Sloptus living up to its name.
wwfzynover 2 years ago
A mobile company that wants so much of their users ID info. Is it really necessary for them to get all that user info?
评论 #32935438 未加载
评论 #32935423 未加载
评论 #32935819 未加载
评论 #32935652 未加载
评论 #32935376 未加载
评论 #32936165 未加载
tsujaminover 2 years ago
and the meaning of the phrase <i>cyberattack</i> is further diminished
libpcapover 2 years ago
State-sponsored?
samstaveover 2 years ago
isnt that like half the population??
评论 #32935394 未加载