Blog, Reflectiz Blog
40% of Australians Have Had Personal Data Stolen in the Optus Massive Data Breach | Reflectiz
40% of Australians Have Had Personal Data Stolen in the Optus Massive Data Breach
**This article is originally published by our partner, Reflectiz. Click here to view the original article.

Last month, Australia’s second-largest Telecommunications provider, Optus, suffered a data breach that was unprecedented in its size, with 10 million customers impacted by stolen personal data.
The data stolen included full names, dates of birth, home addresses, phone numbers, email addresses, and both passport and driving license numbers. Undisclosed initially, Medicare numbers were also part of the breach.
The Australian federal government has warned that the 2.8 million victims who have had a passport and driver’s license IDs stolen are at what they called a “significant risk” of having their identities stolen or used in instances of fraud.
Governments and Regulators Pile on the Heat
The government appears to be blaming Optus, with Reuters reporting that they believe the company “effectively left the window open” for hackers and believe that the organization needs to be held accountable with an overhaul of its privacy rules and more considerable fines as a consequence.
As well as the government, as of October 11th, two regulators have announced investigations into the Optus breach. First, the Office of the Australian Information Commissioner (OAIC) announced a deep dive into whether Optus took “reasonable steps to protect customer data and comply with privacy laws.” At the same time, the Australian Communications and Media Authority (ACMA) also clarified that they are putting Optus under the spotlight to investigate whether Optus could have met its industry obligations regarding its customers’ sensitive and personal data.
Suppose the OAIC finds Optus liable, and there was a preventable breach of Australian privacy law. In that case, civil penalties can be up to 2.2 Australian dollars for each broken law. This would be in addition to any class action lawsuits that individual law firms file, already under consideration by firms such as Slater, Gordon, and Maurice Blackburn. According to legal experts, “compensatory damages could easily be billions of dollars.”
Even if Optus can make it through the financial, regulatory, and governmental hurdles – its brand damage is likely to be immense, and at the moment, the public is not on its side. Chair of the Australian Competition and Consumer Commission, Gina Cass-Gottlieb, told parliament that the regulator received approximately 600 calls per day from concerned Optus customers. Many of these customers are demanding payment for new passports and driver’s licenses and will not soon forget that their most sensitive data was put at risk.
Don’t be the Next Optus: What are the Reasonable Steps for Protecting Customer Data?
In what way will the wind blow for Optus in the long term? This will probably hinge on whether Optus can prove that it took what’s known as reasonable steps to safeguard its customers’ privacy and active measures to protect its data.
Currently, we don’t have enough information about the cause of the breach to answer this question. Still, at Reflectiz, we recognize the pattern of an organization that believes it is secure when there are glaring security gaps that could expose customer information.
Optus’ Chief Executive, Kelly Bayer Rosmarin, described the attack as “sophisticated,” claiming the company has extreme cybersecurity measures and “multiple layers of protection.” However, journalists have uncovered that the hacker has revealed the data was taken from a “freely available software API.”
For ease of integration and seamless functionality, software APIs are incredibly useful for today’s businesses, which need to connect with third parties to offer their services. APIs allow applications to exchange data, automatically react to triggers, and relay communications. However, if your APIs aren’t secure, neither is your business. While you might have dozens of security tools to protect your environment, what about these third parties?
Reflectiz offers robust security enforcement so that the actions taken by third-party assets are under your control. You can easily spot weak authentication, misconfigurations, and data leakage or exposure, even when it doesn’t originate from your network. You can set a defensive baseline according to your business context, and when any action deviates from that norm, you can block the behavior. You’ll be immediately alerted to the risk.
Securing Your Online Presence
Keep your online businesses safe by mitigating security and privacy risks resulting from next generation third-party threats on your website, without adding a single line of code.
Free Reflectiz Information Kit
Get first-hand information and use cases to discover how Reflectiz can protect your website from advanced third party based attacks
Get Web Asset Free Assessment
Request a free non-intrusive security assessment of your website, and get a report with an overview of client-side security risks.






