Warning for Optus customers

chemdog

Kennel Immortal
Joined
Apr 5, 2015
Messages
15,280
Reaction score
19,376
So far just one scam message hitting me up for toll money.

Naturally I paid but find it weird because there are no tolls in Canberra.
I had that message a few wks back i just ignored it and blocked the number
 

Gene Krupa

Kennel Legend
Joined
Jul 8, 2020
Messages
8,477
Reaction score
10,656
If you pool your efforts in a class action with a firm willing to take it on perhaps but I think individually it would be a waste of time.
And when they lose, they will have to pay the lawyers for Optus.
 

Mitch Connor

Super Moderator
Staff member
Moderator
Premium Member
SC Top Scorer
Joined
Feb 26, 2005
Messages
27,746
Reaction score
8,925
Lol I was kidding
 

Natboy

Banned
Premium Member
SC H2H Champion
SC Top Scorer
Joined
Aug 11, 2019
Messages
8,945
Reaction score
11,608
I have a phone with Optus and had three transactions taken off one of my accounts for 3.5k overnight. It’s annoying but the card for that account was a bit worn so I wanted a new card anyway. Thanks Optus haha
 

senshidog

Kennel Enthusiast
Joined
Apr 11, 2020
Messages
3,565
Reaction score
5,009
Be interesting to see how the Office of the Australian Information Commissioner handle this one.

Whilst not a data leak, credentials were still stored in an inproper (plain text) way, which has allowed them to be siphoned out via a cyber attack. How that attack occurred is a completely different story altogether.

But (what the OAIC class as) "personal and private information", should ALWAYS be encrypted in some fashion, or scrubbed after it is used.

I'd imagine theres going to be a rather large fine coming Optus's way for inproper handling of customer information. Data like that should be WAY back in Optus's systems, and not accessible by way of a systems breach on the edge of their network.

I'd find it hard to imagine that someones hacked all the way to a several DMZ / firewalled deep server housing customer information, and likewise I highly doubt it's been a hack that's happened from a store.

For examples sake with Centrelinks systems (EssWeb), they actually cannot be accessed except if connected to via a totally secure network. So you can't use free or shared Wifi to connect to it.
 

Rockford

Kennel Established
Gilded
Joined
Jun 21, 2008
Messages
876
Reaction score
931
What makes it worse is that it wasn't socially engineered. There seems to have been a hole in the firewall, be it via lack of patching a known exploit or a bad config - this is something that a company that says they spend a lot of money on security trying to stop this, has screwed up in a big way. Their Pen Testing should be ongoing, not just quarterly/bi-annual runs (no idea what they do), they are a huge target.
 

Abdul..

Kennel Addict
Joined
Jul 21, 2005
Messages
5,367
Reaction score
1,441
There is no patching this up. CEO is gone, with the CIO and a host of others.

Yes personal information should be destroyed and not stored once it has been verified.

What was the purpose of holding DLs and Passports?
 

Abdul..

Kennel Addict
Joined
Jul 21, 2005
Messages
5,367
Reaction score
1,441
Also, it was discovered on Wednesday. But when did the breach actually occur?
 

Hacky McAxe

Super Moderator
Staff member
Moderator
Gilded
Joined
May 7, 2011
Messages
37,175
Reaction score
29,710
Also, it was discovered on Wednesday. But when did the breach actually occur?
Not sure. But Optus hasn't bothered informing customers yet. And it's illegal to not inform customers of a data breach. They may be able to get out of it by saying that it's on the news so they don't have to inform customers.
 

The DoggFather

ASSASSIN
Premium Member
Gilded
Site's Top Poster
Joined
Sep 2, 2012
Messages
107,834
Reaction score
120,520
All the details are on the dark Web now according to 10 news
 
Top