Skip to main content
Breach Signal

Breach report

Telecom

Optus (Singtel)

Nearly 10 million Australians’ data possibly compromised in hack

An attacker pulled customer records from an exposed Optus API, compromising personal data on up to 9.8 million Australians, roughly a third of the population, and pushing the country to toughen its privacy penalties.

Reported by Al Jazeera

Records exposed

9.8M

Up to 9.8 million customers

Scale vs. largest on file

When
2022
How they got in
Unauthenticated internet-facing API
Sector
Telecom

On September 22, 2022, Optus, Australia's second-largest telecommunications company and a subsidiary of Singapore's Singtel, disclosed that it had suffered a cyberattack exposing customer information. The company said up to 9.8 million current and former customers might be affected, a figure equal to roughly 40 percent of Australia's population. Later regulatory filings put the number of affected people at about 9.5 million.

Optus initially described the attacker as sophisticated, but that account was quickly challenged. Reporting and later legal proceedings indicated that the data had been retrieved through an application programming interface that was reachable from the internet without authentication, allowing records to be requested in sequence. An independent review commissioned by Optus and conducted by Deloitte found that a coding error had weakened access controls on the interface years before the attack and had gone unnoticed.

The exposed data included names, dates of birth, phone numbers and email addresses for all affected customers. For a subset, home addresses and identity document numbers were also taken. About 2.1 million people had a driver's license, passport or Medicare number compromised. Passwords and financial information were not affected, but the ID numbers prompted a costly national effort to replace licenses and passports, which Optus agreed to fund.

Days after the disclosure, a user on a hacking forum demanded a ransom and published a sample of 10,000 records before abruptly withdrawing the demand and claiming to have deleted the data. Australian Federal Police launched an operation to protect victims, and a Sydney man was later charged over a scheme that texted affected customers demanding payment. Optus faced class actions, and in 2024 the Australian Communications and Media Authority took the company to Federal Court alleging it failed to protect customer data. Chief executive Kelly Bayer Rosmarin resigned in November 2023, shortly after a separate nationwide network outage.

The breach had lasting policy consequences. Within weeks, the Australian government pushed legislation sharply raising maximum penalties for serious privacy breaches, and it accelerated debate over how long companies should retain identity documents. Along with the Medibank attack weeks later, Optus reshaped how Australians view the risk of handing ID numbers to businesses.

More from the wire

More in Telecom.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.