Breach report
Financial ServicesLatitude Financial
Latitude Financial data breach now impacts 14 million customers
Using an employee's stolen login, attackers reached systems at two Latitude Financial service providers and took about 14 million records, including 7.9 million driver's license numbers from customers dating back to 2005.
Reported by BleepingComputer
Records exposed
14M
About 14 million customers and applicants
Scale vs. largest on file
- When
- 2023
- How they got in
- Stolen employee credentials used to access service providers
- Sector
- Financial Services
On March 16, 2023, Latitude Financial, a major Australian consumer lender that provides personal loans, credit cards and retail financing for large chains, disclosed that it had been hit by a cyberattack. It initially said about 328,000 customer records had been stolen. Less than two weeks later, on March 27, the company revised the figure dramatically, saying roughly 14 million records belonging to customers and loan applicants in Australia and New Zealand had been taken.
Latitude said the attacker used login credentials stolen from an employee to access systems at two service providers that stored its customer data. The company did not publicly name the vendors or detail how the credentials were obtained. The attack disrupted operations for weeks, as Latitude took platforms offline and paused onboarding of new customers while it investigated.
The revised tally included about 7.9 million driver's license numbers, around 6.1 million older records going back to at least 2005 that contained names, addresses, phone numbers and dates of birth, and roughly 53,000 passport numbers. A smaller number of customers had monthly financial statements exposed. The presence of records nearly two decades old drew particular criticism, since many affected people had not dealt with the lender in years.
On April 11, Latitude said it had received a ransom demand and would not pay, citing government advice that payment would not guarantee the data's deletion and would encourage further attacks. The company committed to reimbursing customers who chose to replace their identity documents, and Australian Federal Police widened an existing operation to protect breach victims. Latitude later reported that the incident cost it about A$76 million in pre-tax costs, and it faced a class action and investigations by privacy regulators in Australia and New Zealand.
The breach arrived only months after the Optus and Medibank incidents and deepened Australian concern about how long businesses keep identity documents. It highlighted the risks of third-party service providers holding customer data and the dangers of indefinite retention. For lenders, it strengthened the case for deleting ID numbers once verification is complete and for requiring phishing-resistant multi-factor authentication for any account that can reach customer databases.