Australian hacker who breached 10 mn people's data concealed their identity

The computer hacker who stole data of almost 10 million customers of a telecommunications company in one of Australia's worst privacy breaches used techniques to conceal their identity and whereabouts

Cybercrime
AP Canberra
3 min read Last Updated : Sep 30 2022 | 12:07 PM IST

The computer hacker who stole personal data of almost 10 million customers of a telecommunications company in one of Australia's worst privacy breaches used techniques to conceal their identity, actions and whereabouts, police said on Friday.

Australian Federal Police Assistant Commissioner Justine Gough, who heads cyber investigations, said the international probe, that includes the US Federal Bureau of Investigation, into the Optus cyberattack last week would be long and complex.

"You can be assured that our very clever and dedicated cyber investigators are focused on delivering justice for those whose personal information has been compromised, Gough said.

The government blames lax cybersecurity at Optus, Australia's second-largest wireless carrier, for the theft of current and former customers' personal information.

Cybersecurity Minister Clare O'Neil described the crime as quite a basic hack. She said Optus, a subsidiary of Singapore Telecommunications Ltd, also known as Singtel, had effectively left the window open for data of this nature to be stolen.

Optus maintains it was the target of a sophisticated cyberattack that penetrated several layers of security.

Gough declined to say whether the crime fitted the description of sophisticated or basic.

I'm not going to go into the details as to the attack because...it is subject of our ongoing investigation, Gough said.

But I would say that whoever is behind this attack has used obfuscation techniques to conceal their identity, their location and their activity, she added.

While details of 9.8 million Optus customers were stolen, authorities are most concerned for more than 10,000 customers whose records were dumped on the dark web on Tuesday as part of an extortion attempt.

The hacker later withdrew a $1 million ransom demand in a post that apologized for the crime and claimed that all the stolen data had been destroyed. Experts are sceptical.

Gough declined to say whether any further extortion attempt had been made.

But she announced police forces throughout Australia had combined resources to supercharge the protection of the 10,000 who are most vulnerable to identify theft and fraud. Police are also working with the finance and services sectors to detect fraud.

Customers affected by the breach will receive multijurisdictional and multilayered protection from identity crime and financial fraud, Gough said.

Operation Guardian will eventually extend to the next-most vulnerable tier of customers, the 2.8 million who have had their driver's license and passport numbers stolen.

Prime Minister Anthony Albanese said Optus had agreed to pay to replace the passports of compromised customers.

I think that's entirely appropriate, Albanese said.

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :AustraliaData breachData Privacydigital identity

First Published: Sep 30 2022 | 12:07 PM IST

Next Story