2022 Optus Data Breach
   HOME

TheInfoList



OR:

In September 2022, Australian
telecommunications Telecommunication, often used in its plural form or abbreviated as telecom, is the transmission of information over a distance using electronic means, typically through cables, radio waves, or other communication technologies. These means of ...
company
Optus Singtel Optus Pty Limited is an Australian Telecommunications in Australia, telecommunications company headquartered in Macquarie Park, a suburb in the Northern Sydney region of Sydney, New South Wales, Australia. It is a wholly owned subsidiar ...
suffered a
data breach A data breach, also known as data leakage, is "the unauthorized exposure, disclosure, or loss of personal information". Attackers have a variety of motives, from financial gain to political activism, political repression, and espionage. There ...
that affected up to 10 million current and former customers comprising a third of Australia's population. Information was illegally obtained, including names, dates of birth, home addresses, telephone numbers, email contacts, and numbers of passports and driving licences. Conflicting claims about how the breach happened were made; Optus presented it as a complicated attack on its systems while an Optus insider and the
Australian Government The Australian Government, also known as the Commonwealth Government or simply as the federal government, is the national executive government of Australia, a federal parliamentary constitutional monarchy. The executive consists of the pr ...
said a human error caused a vulnerability in the company's
API An application programming interface (API) is a connection between computers or between computer programs. It is a type of software interface, offering a service to other pieces of software. A document or standard that describes how to build ...
. A ransom notice asking for A$1,500,000 to stop the data from being sold online was issued. After a few hours, the data thieves deleted the ransom notice and apologised for their actions. Government figures, including
Home Affairs An interior ministry or ministry of the interior (also called ministry of home affairs or ministry of internal affairs) is a Ministry (government department), government department that is responsible for domestic policy, public security and law e ...
and Cyber Security Minister
Clare O'Neil Clare Ellen O'Neil (born 12 September 1980) is an Australian politician who is the Minister for Housing and Minister for Homelessness since July 2024, Minister for Cities since May 2025 and was the Minister for Home Affairs and Minister f ...
, and
Minister for Government Services The Minister for Government Services is the minister in the Government of Australia responsible for Services Australia. The current minister is Senator Katy Gallagher, who has held the position since 20 January 2025 following a cabinet reshuffle ...
Bill Shorten William Richard Shorten (born 12 May 1967) is an Australian former politician and trade unionist. He was the leader of the Australian Labor Party (ALP) and Leader of the Opposition (Australia), Leader of the Opposition from 2013 to 2019. He also ...
, criticised Optus for its role in the attack, and for being uncooperative with government agencies and the public. The government announced legislation, including the allowance of information-sharing with financial services and government agencies, and reforms to Australia's laws on security of critical infrastructure to help the government act in the event of future breaches. In response to the data breach, Optus agreed to pay for the replacements of compromised passports, commissioned an external review, and gave seriously affected customers a subscription to a
credit monitoring Credit report monitoring or company tracking is the monitoring of one's credit history in order to detect any suspicious activity or changes. Companies offer such service on a subscription basis, typically granting regular access to one's credit h ...
service. Optus also apologised for the breach. Customers criticized Optus for not being responsive and providing inadequate responses to those affected. As of June 2023, investigations into the breach and a
class-action lawsuit A class action is a form of lawsuit. Class Action may also refer to: * ''Class Action'' (film), 1991, starring Gene Hackman and Mary Elizabeth Mastrantonio * Class Action (band), a garage house band * "Class Action" (''Teenage Robot''), a 2002 e ...
from affected customers were ongoing.


Background

Optus Singtel Optus Pty Limited is an Australian Telecommunications in Australia, telecommunications company headquartered in Macquarie Park, a suburb in the Northern Sydney region of Sydney, New South Wales, Australia. It is a wholly owned subsidiar ...
, an Australian
telecommunications Telecommunication, often used in its plural form or abbreviated as telecom, is the transmission of information over a distance using electronic means, typically through cables, radio waves, or other communication technologies. These means of ...
company owned by
Singtel Singapore Telecommunications Limited, trading as Singtel, is a Singaporean telecommunications conglomerate, the country's principal fixed-line operator and one of the four major mobile network operators operating in the country. Overview T ...
, was founded in 1981 with the formation of the government-owned satellite-communications company AUSSAT. AUSSAT was privatised in 1991 and sold to a consortium that included Mayne Nickless and
AMP Amp or AMP may refer to: * Ampere, a unit of electric current, often shortened to amp * Amplifier, a device that increases the amplitude of a signal Arts and entertainment Music * After Midnight Project, Los Angeles alternative rock band * A ...
. In 2022, Optus was Australia's third-largest telecommunications company with a 13.1% market share. In September 2022, Optus had around 10 million customers, comprising more than a third of Australia's population of around 26.12 million people.


Breach

On 20 September 2022, Optus's technical team noticed and investigated suspicious activity on its network. The next day, Optus's systems were found to have sustained a data breach and regulators were informed. On 22 September, the company publicly announced the data breach and informed news agencies. Optus advised the public to be vigilant for potential fraudulent activity but stated it did not know whether the breach had caused any harm to customers. Optus did not state how many customers were affected or whether the theft of data had caused harm. Illegally obtained Information included names, dates of birth, home addresses, telephone numbers, email contacts, and passport and driving-licence numbers. On 23 September, Optus denied an insider's claims an
application programming interface An application programming interface (API) is a connection between computers or between computer programs. It is a type of software Interface (computing), interface, offering a service to other pieces of software. A document or standard that des ...
(API) had accidentally been left exposed to a test network that had access to the Internet. The company also said a complicated breach had occurred and that it had a strong cybersecurity system. The
Australian Broadcasting Corporation The Australian Broadcasting Corporation (ABC) is Australia’s principal public service broadcaster. It is funded primarily by grants from the federal government and is administered by a government-appointed board of directors. The ABC is ...
(ABC) was told Optus believed the hacker had scraped the company's consumer database, and that a third of the data in the database had been copied and extracted. On 24 September, Optus and the
Australian Federal Police The Australian Federal Police (AFP) is the principal Federal police, federal law enforcement agency of the Australian Government responsible for investigating Crime in Australia, crime and protecting the national security of the Commonwealth ...
(AFP), which had opened a criminal investigation, received reports data from the leak was being sold online and were monitoring the
dark web The dark web is the World Wide Web content that exists on darknets ( overlay networks) that use the Internet but require specific software, configurations, or authorization to access. Through the dark web, private computer networks can communica ...
for any attempt to sell the data. The same day, a user on the website
BreachForums BreachForums, sometimes referred to as Breached, was an English-language black hat–hacking crime forum. The website acted as an alternative and successor to RaidForums following its shutdown and seizure in 2022. Like its predecessor, BreachF ...
posted a ransom note; some cybersecurity experts believed the note was genuine but Optus and the AFP did not confirm its genuineness. The note demanded Optus pay $1,500,000 in the privacy-focused cryptocurrency
Monero Monero (; Abbreviation: XMR) is a cryptocurrency which uses a blockchain with privacy-enhancing technologies to obfuscate transactions to achieve anonymity and fungibility. Observers cannot decipher addresses trading Monero, transaction amount ...
, provided a sample of data from 200 customers, and said the data thieves would release the personal information of 10,000 customers every day if Optus did not pay the ransom until a week elapsed. After the week elapsed, the thieves would sell the data for A$400,000 to anyone who wanted them. After several hours, the user deleted their original post and appeared to apologise for their actions despite no ransom being paid, stating it was a "mistake to scrape publish icdata in first place" and that too many people were paying attention to the breach. The user noted they would have reported the exploit they used if they had the ability to contact Optus, noting the lack of a secure mail, a messaging contact and bug bounties.


Government response

Home Affairs An interior ministry or ministry of the interior (also called ministry of home affairs or ministry of internal affairs) is a Ministry (government department), government department that is responsible for domestic policy, public security and law e ...
and
Cyber Security Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and networks from thr ...
Minister
Clare O'Neil Clare Ellen O'Neil (born 12 September 1980) is an Australian politician who is the Minister for Housing and Minister for Homelessness since July 2024, Minister for Cities since May 2025 and was the Minister for Home Affairs and Minister f ...
said Optus was at fault for the attack, refuting Optus's argument the attack was complicated. O'Neil also stated the attack should not have happened, stating: "Responsibility for the security breach rests with Optus and I want to note that the breach is of a nature that we should not expect to see in a large telecommunications provider in this country". On October 6, the federal government announced an emergency regulation to temporarily allow drivers licences, Medicare information, and passport numbers to be shared with financial services, the Commonwealth, and state and territory agencies to assist monitoring of accounts of customers affected by the breach for potential scams or fraud. Financial institutions had to commit to several actions to receive the data, including honouring privacy obligations and deleting data once it has been used. The Council of Financial Regulators was asked to identify and report on changes to financial instructions to identify customers who were at risk of scams and fraud. The changes were in place for 12 months.
Treasurer A treasurer is a person responsible for the financial operations of a government, business, or other organization. Government The treasury of a country is the department responsible for the country's economy, finance and revenue. The treasure ...
Jim Chalmers James Edward Chalmers (born 2 March 1978) is an Australian politician and economist who has been serving as the treasurer of Australia in the Albanese government since May 2022. A member of the Labor Party (ALP), he has been the member of p ...
stated the measures would help protect customers from scams and detect fraud. O'Neil expressed frustration at the lack of ability for the government to intervene in the data breach, its inability to assist with the clean-up or compel Optus to give government services information. She stated Australian law had no use for the government when needed because Australia's laws governing security of critical infrastructure only allowed the government to intervene while a data breach was occurring. Following the breach, several new security measures to protect victims from fraud, including banks being more-quickly informed of data breaches to prevent the use of data to fraudulently access bank accounts, were announced. The federal government announced an overhaul of the $1.7 billion cybersecurity plan introduced by the previous government, including additional powers to intervene in cybersecurity. The government also considered a Cyber Security Act to create standards and obligations for industry and government, and a reform to the Security of Critical Infrastructure Act to bring customer data and systems under the definition of "critical infrastructure", allowing the government to intervene in major data breaches. In April 2023, the National Office of Cyber Security was founded with five full-time staff and no additional funding beyond what was already given to the
Department of Home Affairs An interior ministry or ministry of the interior (also called ministry of home affairs or ministry of internal affairs) is a government department that is responsible for domestic policy, public security and law enforcement. In some states, the i ...
. In June 2023, Air Marshal
Darren Goldie Air Marshal Darren James Goldie, (born 1975) is a retired senior officer of the Royal Australian Air Force (RAAF). He joined the RAAF through the Australian Defence Force Academy in 1993 and gained his pilot's wings in 1997. He deployed on oper ...
was appointed as Australia's inaugural Cyber Security Coordinator. In November 2023, Goldie was recalled to the Department of Defence regarding a workplace matter, and cyber-and-infrastructure security head Hamish Hansford took on the position in the interim. On 27 February 2023,
Prime Minister A prime minister or chief of cabinet is the head of the cabinet and the leader of the ministers in the executive branch of government, often in a parliamentary or semi-presidential system. A prime minister is not the head of state, but r ...
Anthony Albanese Anthony Norman Albanese ( or ; born 2 March 1963) is an Australian politician serving as the 31st and current prime minister of Australia since 2022. He has been the Leaders of the Australian Labor Party#Leader, leader of the Labor Party si ...
and O'Neil hosted a roundtable with industry and civil society groups on cybersecurity following the data breach. A discussion paper was released regarding the role of the federal government in increasing Australia's cybersecurity capability. The state governments of
Queensland Queensland ( , commonly abbreviated as Qld) is a States and territories of Australia, state in northeastern Australia, and is the second-largest and third-most populous state in Australia. It is bordered by the Northern Territory, South Austr ...
,
Victoria Victoria most commonly refers to: * Queen Victoria (1819–1901), Queen of the United Kingdom and Empress of India * Victoria (state), a state of Australia * Victoria, British Columbia, Canada, a provincial capital * Victoria, Seychelles, the capi ...
,
South Australia South Australia (commonly abbreviated as SA) is a States and territories of Australia, state in the southern central part of Australia. With a total land area of , it is the fourth-largest of Australia's states and territories by area, which in ...
and
Western Australia Western Australia (WA) is the westernmost state of Australia. It is bounded by the Indian Ocean to the north and west, the Southern Ocean to the south, the Northern Territory to the north-east, and South Australia to the south-east. Western Aust ...
agreed to pay for the replacement of driver's licences for people whose driver's licence numbers were compromised by the breach. In Victoria, plans to add a second number to driver's licences were quickly enacted; all victims of the breach received the second number as part of their replacements, to protect Victorians from identity theft.


Optus response

On the day the breach was announced, Optus set up a "war room" at its headquarters in
Macquarie Park, New South Wales Macquarie Park () is a suburb in the Northern Sydney region of Sydney, New South Wales, Australia. Macquarie Park is located 13 kilometres north-west of the Sydney central business district in the local government area of the City of Ryde. Macq ...
. This involved around 150 employees, and was headed by former Premier of New South Wales
Gladys Berejiklian Gladys Berejiklian (; born 22 September 1970) is an Australian businesswoman and former politician who served as the 45th premier of New South Wales and the leader of the New South Wales division of the Liberal Party from 2017 to 2021. Berejikl ...
and regulatory and public affairs head Andrew Sheridan. Optus commissioned
Deloitte Deloitte is a multinational professional services network based in London, United Kingdom. It is the largest professional services network in the world by revenue and number of employees, and is one of the Big Four accounting firms, along wi ...
to perform an "independent external review" regarding the breach. Optus also offered its "most affected" customers a 12-month subscription to credit-monitoring service Equifax Protect after O'Neil requested the company buy credit monitoring for its customers in Question Time. Optus CEO Kelly Bayer Rosmarin apologised for the attack on behalf of the company. Optus reserved $140 million for costs relating to the breach, including the replacement of hacked identity documents, Equifax Protect subscriptions, and the Deloitte review. Optus promised to pay for the replacement of compromised Australian and foreign passports. Optus reported 2.1 million of its customers had had identity documents stolen in the hack. Of these, 1.2 million had at least one current, valid number from a form of personal identification stolen. The remaining 900,000 customers had expired identity numbers stolen.
Services Australia Services Australia, formerly the Department of Human Services and before that the Department of Social Security, is an executive agency of the Australian Government, responsible for delivering a range of welfare payments, health insurance pay ...
accused Optus of a lack of communication. On 27 September, Services Australia wrote to Optus "asking for the full details of all affected customers with Services Australia credentials exposed, such as Medicare cards and/or Centrelink concession cards".
Minister for Government Services The Minister for Government Services is the minister in the Government of Australia responsible for Services Australia. The current minister is Senator Katy Gallagher, who has held the position since 20 January 2025 following a cabinet reshuffle ...
Bill Shorten William Richard Shorten (born 12 May 1967) is an Australian former politician and trade unionist. He was the leader of the Australian Labor Party (ALP) and Leader of the Opposition (Australia), Leader of the Opposition from 2013 to 2019. He also ...
stated a week later, Services Australia had not received any data from Optus, which said it was "in contact with Services Australia and we will be letting all affected customers know the guidance on the steps they can take". There was also confusion about the number of stolen Medicare ID numbers; Shorten told a press conference around 36,900 ID numbers had been stolen and Optus said 14,900 ID numbers had been stolen. Customers also reported having problems communicating with Optus. Customers stated Optus could not confirm their personal information was part of the data breach. Customers reported after contacting Optus several times, the company's
chatbot A chatbot (originally chatterbot) is a software application or web interface designed to have textual or spoken conversations. Modern chatbots are typically online and use generative artificial intelligence systems that are capable of main ...
failed to understand customers' questions about the breach, sales representatives gave poor responses, they did not receive a response from Optus at all, and there were delays in warning customers of compromised personal information. One customer stated: "Ultimately, we are sitting ducks for identity theft, and given that we can’t change our dates of birth, address or names, there isn’t much we can do about it, which is incredibly frustrating". On 8 March 2023, Bayer Rosmarin restated Optus's claim the attack was sophisticated, stating at a business summit: " e skilled criminal had knowledge of Optus' systems and cycled through many tens of thousands of internet protocol addresses in an attempt to evade our automated cyber monitoring". She also stated Optus never paid a ransom to the hacker and that the main reason for the breach was other scam purposes. In November 2023, Bayer Rosmarin resigned as CEO of Optus after the 2023 Optus outage; there had been mounting pressure on her to resign due to the outage and the data breach.


Legal action

On 6 October 2022, the
Australian Federal Police The Australian Federal Police (AFP) is the principal Federal police, federal law enforcement agency of the Australian Government responsible for investigating Crime in Australia, crime and protecting the national security of the Commonwealth ...
(AFP) arrested a 19-year-old Sydney man Dennis Su in his home at Rockdale for blackmailing 93 breach-affected Optus customers. Su said he would commit financial crimes using the customers' personal data unless they paid him A$2,000, which none did. He was charged with one count of using a telecommunication network with intent to commit a serious offence and one count of dealing with identification information with intent to commit an offence. AFP Assistant Commissioner Justine Gough stated Su was not suspected of being responsible for the breach and warned people not to click on links claiming to be from Optus. Su pleaded guilty in November 2022; he did not go to jail due to a guilty plea, his age, and remorse shown for his actions, and he received an 18-month community corrections order. On 11 October, the
Office of the Australian Information Commissioner The Office of the Australian Information Commissioner (OAIC), known until 2010 as the Office of the Australian Privacy Commissioner is an independent Australian Government agency, acting as the national data protection authority for Australia, e ...
(OAIC) launched an investigation into the breach, Optus's handling of customers' personal data, whether Optus took reasonable steps to protect consumers affected by the breach from fraud, misuse, or loss, and whether Optus needed to keep the collected information. The
Australian Communications and Media Authority The Australian Communications and Media Authority (ACMA) is an Australian government statutory authority within the Communications portfolio. ACMA was formed on 1 July 2005 with the merger of the Australian Broadcasting Authority and the Aus ...
(ACMA) also launched an investigation into the breach, focusing on Optus's obligations to protect and dispose of personal data. The federal government gave OAIC $5.5 million to investigate the breach over two years in its October 2022 budget. Law firm
Slater & Gordon Slater & Gordon Lawyers is a law firm in Australia. The firm was founded in Melbourne, Victoria, in 1935 by a barrister and solicitor from Irymple, Victoria, Hugh Lyons Gordon, and Labor politician Bill Slater. Since April 2023, the law firm ...
launched a
class action A class action is a form of lawsuit. Class Action may also refer to: * ''Class Action'' (film), 1991, starring Gene Hackman and Mary Elizabeth Mastrantonio * Class Action (band), a garage house band * "Class Action" (''Teenage Robot''), a 2002 e ...
alleging Optus "breached laws and its own policies by failing to adequately protect customer data and destroy or de-identify former customer data". The ongoing class action was joined by 100,000 current and former Optus customers who wanted compensation for losses, including the time to replace identification documents and the stress it caused. Optus stated it would defend its actions. In court, Slater & Gordon lawyers requested the public release of the Deloitte report, arguing it could reveal the possible causes of the data breach. Optus declined to release the report despite Bayer Rosmarin stating in March 2023 Optus would share "key recommendations and learnings" from the report. In November 2023, Optus lost a bid to keep the report confidential.


See also

* 2023 Optus outage *
Telecommunications in Australia Telecommunications in Australia refers to communication in Australia through electronic means, using devices such as telephone, television, radio or computer, and services such as the telephony and broadband networks. Telecommunications have a ...


References

{{Reflist 2022 controversies Data breaches Identity theft incidents Optus September 2022 crimes in Oceania September 2022 in Australia Telecommunications in Australia