Case Study

Cyberattack Triggers Telco Crisis in Australia

Thousands of Australian residents have been replacing their passports, driver licenses and Medicare cards following the recent cyberattack on telecommunications giant Optus. On September 21, 2022, the company announced a massive data breach that affected 10 million current and former customers in Australia, and the subsequent exposure online of the personal details for 10,000 people.…

Thousands of Australian residents have been replacing their passports, driver licenses and Medicare cards following the recent cyberattack on telecommunications giant Optus. On September 21, 2022, the company announced a massive data breach that affected 10 million current and former customers in Australia, and the subsequent exposure online of the personal details for 10,000 people.

(Note: Jamaican readers can relate to this incident as a data breach occurred on the JAMCOVID web portal in early 2021 resulting in the exposure of personal data for tens of thousands of Jamaican and international travelers).

In addition to the number on the identity documents stolen in Australia, personal details including name, date of birth, email address, home address, and phone number were compromised. In the aftermath, the affected Australians are fearful of identity theft as well as financial loss arising from fraud. Already there have been reports of scammers disguising themselves as official investigators and approach Optus customers. In the main, people are being alert, and the Australian federal government has introduced measures to facilitate the sharing of information by Optus with financial institutions to mitigate the risk of fraud being perpetrated on customers whose personal details have been exposed.

How did the hacking occur? Did Optus have effective cyber security in place? Does the telco have effective systems in place to protect and ensure the privacy of data about its customers. The data breach affected past customers. Should Optus still retain that information? These questions and others will hopefully be answered by investigations to be conducted by regulatory and consumer watchdog agencies.

The Office of the Australian Information Commissioner (OAIC) announced that it would launch an investigation focusing on “whether the Optus companies took reasonable steps to protect the personal information they held from misuse, interference, loss, unauthorised access, modification or disclosure, and whether the information collected and retained was necessary to carry out their business.”

The OAIC said, “The investigation will also consider whether the Optus companies took reasonable steps to implement practices, procedures and systems to ensure compliance with the Australian Privacy Principles (APPs), including enabling them to deal with related inquiries or complaints.” If found guilty of breaches or negligence Optus will face significant fines.

Read: The Hidden Cost of Cybercrimes

The Australian Communications and Media Authority (ACMA) has also launched an investigation. According to ACMA Chair Nerida O’Loughlin, “when customers entrust their personal information to their telecommunications provider, they rightly expect that information will be properly safeguarded. Failure to do this has significant consequences for all involved,” she said in a statement.

She pointed out that all telcos have obligations regarding how they acquire, retain, protect and dispose of the personal information of their customers. Hence, a “key focus for the ACMA will be Optus’s compliance with these obligations.”

Managing the crisis

In managing the crisis, Optus has commissioned an independent external review of the cyberattack to be undertaken by the international audit and management consulting firm Deloitte. The review will look at the security systems, controls and processes at the telco.

Optus Chief Executive Officer, Kelly Bayer Rosmarin said while the company’s “overwhelming focus remains on protecting our customers and minimising the harm that might come from the theft of their information, we are determined to find out what went wrong.”

She added, “This review will help ensure we understand how it occurred and how we can prevent it from occurring again. It will help inform the response to the incident for Optus.  This may also help others in the private and public sector where sensitive data is held and risk of cyberattack exists.

“I am committed to rebuilding trust with our customers and this important process will assist those efforts.”

Other crisis management strategies implemented by Optus in relating to its affected stakeholders include:

  • Establishment of a ‘bulletin board’ on its website which frequently carries updates and critical information
  • Providing customers with self-help information on how to apply for the replacement of identity documents.
  • Providing affected customers with 12 months of service by Equifax Protect, which is a credit monitoring and identity protection service that may help reduce the risk of identity theft or financial loss.
  • Establishment of a joint-working group with government

 Footnote: Jamaican readers can relate to the data breach that occurred on the JAMCOVID web portal in early 2021 resulting in the exposure of personal data for tens of thousands of Jamaican and international standards.

READ ABOUT RISK MANAGEMENT AND CYBER SECURITY

Comments

Leave a Reply