Monday, 26 September 2022

Optus data breach “wake-up call” sparks government security crackdown

Australian banks will be informed of attacks such as the Optus data breach more swiftly, as the Federal government prepares to announce a security crackdown to tackle the impact of cyber attacks which expose personal information and put customers at risk.

The recent Optus data breach exposed the personal information of up to 9.8 million Australians, including details such as customers’ names, dates of birth, phone numbers and email addresses. For 2.8 million customers, their home address was also exposed, along with ID document numbers such as their driver’s licence or passport.

The attack appears to impact Optus customers dating as far back as 2017, including former customers. The telco says account passwords were not compromised, and neither were financial and payment details.

One of the largest data breaches in Australia history, the attack leaves affected Optus customers at risk of fraud and identity theft. It also leaves all Optus customers at risk of falling prey to further attacks, as scammers take advantage of poeple’s concern through bogus emails and text messages.

Customers warned of Optus data breach 

Optus first alerted customers and media to the cyberattack on Thursday September 22, but the full extent of the data breach and those responsible for the attack is still unclear.

“While not everyone may be affected and our investigation is not yet complete, we want all of our customers to be aware of what has happened as soon as possible so that they can increase their vigilance,” said Optus CEO, Kelly Bayer Rosmarin. 

Optus assured customers the data breach has been blocked and that phone and internet services remain safe to use. It says that its SIM-only brands Amaysim and Gomo, along with Optus resellers, were not impacted by the attack.  

The attackers claim to have already released the details of 10,000 Optus customers on the dark web and are demanding a $1.5 million ransom. The threat is yet to be confirmed as genuine by Optus, although cyber experts view early customer data released by the alleged hackers as genuine.

Optus has sent emails or text messages to all customers who had their identification documents compromised in the data breach. The telco is offering its “most affected” customers a free 12-month subscription to Equifax Protect, an ID and credit monitoring service to help them detect signs of fraud.

Government response to Optus data breach 

Australian Prime Minister, Anthony Albanese, labelled the Optus data breach as a “huge wake-up call”, as the government flags introducing large fines for future breaches and overhauling the nation’s data retention laws.

Home Affairs Minister, Clare O’Neil, laid blame for the attack at the feet of Optus and said the government is looking to work with financial regulators and the banking sector to see what steps can be taken to protect impacted customers.

“One significant question is whether the cyber security requirements we place on large telecommunications providers in this country are fit for purpose,” O’Neil said.

“In other jurisdictions, a data breach of this size will result in fines amounting to hundreds of millions of dollars.”

How Optus customers can protect themselves

As law firm Slater and Gordon announces it is investigating a class action against the telco over the data breach, customers can take several precautions to reduce their risk from the Optus data breach.

Australian Competition and Consumer Commission’s ScamWatch has urged Optus customers to take extra steps to secure their accounts, as well as watch out for signs of identity.

Sensible precautions include changing passwords on Optus email accounts and linked services, such as online banking, as well as enabling multi-factor authentication as an extra layer of defence.

Optus customers should also closely monitor their bank and credit card statements, along with other personal financial accounts, and immediately flag suspicious activity. 

They should also be on guard for calls, emails or text messages from scammers attempting to take advantage of the situation. This includes bogus messages claiming to be from Optus or other organisations, asking customers to hand over personal information or click on links.

Optus says that no legitimate communications from Optus relating to this incident will include any links, as it recognises that cyber criminals will be using this incident to conduct phishing scams. 

More eSafety news at GadgetGuy.

The post Optus data breach “wake-up call” sparks government security crackdown appeared first on GadgetGuy.


Related Posts:

  • End of financial year mobile plan dealsFind the best mobile plan deals always, by visiting GadgetGuy. Every month, GadgetGuy publishes a guide to the cheapest SIM plans available that month. We also explain just how easy it is to port your existing number to your … Read More
  • Telstra Smart Modem Gen 3: get connected (review) 8.5 Boosting the Wi-Fi signal around your home, with 4G fallback for when disaster strikes, the Telstra Smart Modem Gen 3 has you covered. Whichever part of the NBN’s Multi-Technology Mix runs to your door, there’ll be … Read More
  • Epson wins big at iF Design Award 2022Epson recently received major recognition for four of its products at the latest prestigious iF Design Awards, including awards for the company’s various printing and projector devices. Epson’s EH-LS12000B can create a 300-… Read More
  • Meta VR headset prototypes aim to pass Visual Turing TestWith an eye on the future of the Metaverse, CEO Mark Zuckerberg has unveiled a slew of Meta VR headset prototypes as the tech giant works towards making virtual reality “as vivid and realistic as the physical world”. Immersiv… Read More
  • 8 huge gaming announcements from ‘Not-E3’Not-E3, faux-E3, “Keigh-3” – in reference to video game presenter Geoff Keighly – whatever you want to call it, the past few weeks have been stacked with gaming announcements. This is despite E3, the Electronic Entertainment … Read More

0 comments:

Post a Comment