Optus Data Breach: Australia Plans Tough Data Protection Laws After Cyberattack on Telecoms Firm

The Australian government blames lax cybersecurity at Optus for the theft of current and former customers’ personal information.

Advertisement
By Associated Press | Updated: 29 September 2022 18:35 IST
Highlights
  • Penalties for failing to protect personal data had to be increased
  • Companies need to look at data storage not as an asset
  • The government blames lax cybersecurity at Optus

Australia could have tough new data protection laws in place this year

Australia could have tough new data protection laws in place this year in an urgent response to a cyberattack that stole from a telecommunications company the personal data of 9.8 million customers, the attorney-general said Thursday.

Attorney-General Mark Dreyfus said the government would make “urgent reforms” to the Privacy Act following the unprecedented hack last week on Optus, Australia's second-largest wireless carrier.

Dreyfus said “I think it's possible” for the law to be changed in the four remaining weeks that Parliament is scheduled to sit this year.

Advertisement

"I'm going to be looking very hard over the next four weeks at whether or not we can get reforms to the Privacy Act into the Parliament before the end of the year,” Dreyfus told reporters. Parliament next sits on October 25.

Advertisement

Dreyfus said penalties for failing to protect personal data had to be increased so that corporate boards could not dismiss fines as a “cost of doing business.”

The “absolutely huge amounts” of customer data companies held for years would have to be justified under the amended law, Dreyfus said.

Advertisement

“Companies need to look at data storage not as an asset, but as a liability or a potential liability,” Dreyfus said. “For too long we have had companies solely looking at data as an asset that they can use commercially."

The government blames lax cybersecurity at Optus, a subsidiary of Singapore Telecommunications, also known as Singtel, for the theft of current and former customers' personal information.

Advertisement

Singtel apologised in a statement issued Wednesday by its management saying, “We are deeply sorry to everyone affected by the data theft.”

“Since the incident, our focus has been on supporting Optus' efforts to help impacted customers and strengthen their security controls,” the statement said.

“Information security is of paramount importance to the Singtel Group and a top priority across all of its business units and we invest significant resources to continually strengthen our defenses against emerging threats,” the statement added.

The data included passport, driver's licence, and national health care identification numbers which could be used for identity theft and fraud.

Authorities are critical of Optus' initial failure to disclose that Medicare numbers were among the stolen data. That became apparent Tuesday when the hacker dumped the records of 10,000 customers on the dark web — six days after Optus discovered the cyberattack.

The urgent legislative response is separate from a broader review of the Privacy Act that began three years ago. The law was passed in 1988 and critics argue it badly needs to be adapted to the digital age.

Optus could potentially be fined a maximum AUD 2 million (roughly Rs. 10 crore) for breaching the Privacy Act, the government said.

It could be fined hundreds of millions of dollars over a similar security breach under European Union laws, the government said.

Submissions to the Privacy Act review have suggested penalties for breaches equivalent to 10% of revenue from Australian operations.

Optus CEO Kelly Bayer Rosmarin has argued against increased fines, telling the Australian Broadcasting Corp. on Tuesday: “Honestly, I'm not sure what penalties benefit anybody.”

Optus maintains it was the target of a sophisticated cyberattack that penetrated several layers of security.

After an emergency meeting with banking and consumer regulators, Financial Services Minister Stephen Jones said “fraudsters” and “scammers” were already beginning to use the stolen data, which includes phone numbers and email addresses.

With personal information stolen from 38 percent of Australia's population of 26 million in the hack, “you can't overestimate the impact of this breach on consumer issues,” Jones said.

He warned compromised Optus customers against activating URLs they receive by text or email because they could be from criminals attempting to steal more information.

“We're all working as best as we can to try and work our way through the long tail of problems that is going to be a consequence of this massive data breach,” Jones said.


Can Moto's new premium phones take on iPhone, OnePlus, and Samsung? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  2. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  3. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  4. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  5. Ethirneechal Thodargiradhu Now Streaming on SunNXT: What You Need to Know
  6. Apple's Foldable iPhone Could Resemble This iPad Model When Unfolded
  7. Vivo V70 Stops By US FCC Database Along With RAM and Storage Details
  8. Nvidia's GeForce RTX 50 Series GPUs Are About to Be Scarce
  9. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan
  10. Infinix Xpad Edge With 13.2-Inch Display, 8,000mAh Battery Launched
  1. Samsung Exynos 2600 Details Leak Ahead of Galaxy S26 Launch; Could Be Equipped With 10-Core CPU, AMD GPU
  2. Vivo Y50e 5G, Vivo Y50s 5G Appear on Google Play Console; Mysterious Vivo Phone Listed on Certification Site
  3. Nvidia to Reportedly Cut GeForce RTX 50 Series GPU Production Amid Global RAM Shortage
  4. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan to Comply With MSCA Act
  5. Hogwarts Legacy Has Sold 40 Million Copies, Warner Bros. Games Announces
  6. OnePlus 15s Listing on BIS Certification Website Hints at Imminent Launch in India
  7. Infinix Xpad Edge Launched With 13.2-Inch Display, 8,000mAh Battery: Price, Specifications
  8. Ethirneechal Thodargiradhu Now Streaming on SunNXT: What You Need to Know
  9. The Villainess Is Adored by the Prince of the Neighbor Kingdom OTT Release Date: Know When and Where to Watch This Japanese Anime Series Online
  10. Easygoing Defense by the Optimistic Lord Anime to Stream on Crunchyroll in January 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.