Optus Data Breach: Australian Police Investigate Purported Hacker's $1 Million Ransom Demand

Optus, Australia's second-largest carrier, was impacted by a data breach exposing personal data of 9.8 million current and former customers.

Advertisement
By Associated Press | Updated: 27 September 2022 15:23 IST
Highlights
  • The purported hacker uses the online name Optusdata
  • The hacker released 10,000 Optus customer records on dark web
  • Kirk said released personal data include health care numbers

Cybersecurity Minister urged Optus to give priority to informing customers of what details had been taken

Australian police were investigating a purported hacker's release of the stolen personal data of 10,000 Optus customers and demand for a $1 million (roughly Rs. 8 crore) ransom in cryptocurrency, the telecommunications company's chief executive said Tuesday.

The Australian government has blamed lax cybersecurity at the nation's second-largest wireless carrier for the unprecedented breach last week of the personal data of 9.8 million current and former Optus customers.

Jeremy Kirk, a Sydney-based cybersecurity writer, said the purported hacker, who uses the online name Optusdata, had released 10,000 Optus customer records on the dark Web and threatened to release another 10,000 every day for the next four days unless Optus paid the ransom.

Advertisement

Asked if the hacker had threatened to sell the remaining data if Optus did not pay the $1 million within a week, the company's chief executive Kelly Bayer Rosmarin told Australian Broadcasting Corp.: “We have seen there is a post like that on the dark Web.”

Advertisement

Australian Federal Police said Monday their investigators were working with overseas agencies, including the FBI, to determine who was behind the attack and to help shield the public from identity fraud. Police declined further comment Tuesday as the investigations were ongoing.

“They're looking into every possibility and they're using the time available to see if they can track down that particular criminal and verify if they a bona fide,” Bayer Rosmarin said.

Advertisement

Kirk wrote in his website Bank Info Security that Optusdata later deleted the post along with three samples of the stolen data.

Optusdata sent Kirk a link to the new post that withdrew the ransom demand, claimed the stolen data had been deleted and apologized to Optus as well as its customers.

Advertisement

“Too many eyes. We will not sale (sic) data to anyone,” the post said, adding that Optus had not paid a ransom.

Kirk said he asked why Optusdata had changed their mind but received no response.

Australian Information and Privacy Commissioner Angelene Falk, the national data protection authority, said the latest post “indicates ... this is a very fast-moving incident.”

“It's a major incident of significant concern for the community. What we need to focus on here is ensuring that all steps are maintained to protect the community's personal information from further risk of harm,” Falk said.

Earlier Tuesday, Kirk said the released personal data appeared to include health care numbers, a form of identification not previously revealed publicly to have been hacked.

Cybersecurity Minister Clare O'Neil urged Optus to give priority to informing customers of what information had been taken.

“I am incredibly concerned this morning about reports that personal information from the Optus data breach, including Medicare numbers, are now being offered for free and for ransom,” O'Neil said. “Medicare numbers were never advised to form part of compromised information from the breach,” she added.

O'Neil on Monday described the hack as an “unprecedented theft of consumer information in Australian history.”

Of the 9.8 million people affected, 2.8 million had “significant amounts of personal data,” including driver's licenses and passport numbers, breached and are at significant risk of identity theft and fraud, she said.

Kirk said he used an online forum for criminals who trade in stolen data to ask Optusdata how the Optus information was accessed.

Optus appeared to have left an application programming interface, a piece of software known as an API that allows other systems to communicate and exchange data, open to the public, Kirk said.

“It looks like it was a failure to secure the software system, so anybody on the Internet could find it,” Kirk said.

The Australian Financial Review said the theory that Optus “left open an API” had been widely reported.

Bayer Rosmarin rejected such explanations.

“Given we're not allowed to say much because the police have asked us not to, what I can say — that hopefully will help people understand that it's not as being portrayed — is that our data was encrypted and we have multiple layers of protection,” Bayer Rosmarin said.

“So it is not the case of having some sort of completely exposed API sitting out there,” she added.

O'Neil didn't detail how the breach occurred, but described it as a “quite a basic hack.”

Optus had “effectively left the window open for data of this nature to be stolen,” O'Neil said.

Australia's government is considering tougher cybersecurity rules for telecommunications companies as a result of the hack.

Current cyberprotection law doesn't allow for Optus to be fined for the breach, though O'Neil noted fines of hundreds of millions of dollars would be possible if it had occurred in other countries.

O'Neil said a potential AUD 2 million (roughly Rs. 10 crore) fine under privacy law was inadequate.


Buying an affordable 5G smartphone today usually means you will end up paying a "5G tax". What does that mean for those looking to get access to 5G networks as soon as they launch? Find out on this week's episode. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Optus, Cybersecurity
Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  2. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  3. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  4. Butterfly-Shaped Hole in the Sun Could Spark Solar Storms Worldwide
  5. iQOO 15 Live Image Leaked; Company Reveals Display Details
  6. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  7. Apple AirPods 4 at Rs 9,999, Other Top Deals in Zepto's Fastest Sale Ever
  8. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  9. Best Mobiles Under Rs. 60,000 in India
  10. Oppo Find X9 Launch Timeline Revealed: See Find X9 Pro Camera Samples
  1. Treasure Hunters Season 1 Now Streaming on JioHotstar: Everything You Need to Know
  2. London Stock Exchange Completes First Blockchain-Powered Fundraising via DMI Platform
  3. Zepto Fastest Sale Ever: Apple AirPods 4 Price Drops to Rs 9,999; Check Top Deals on Electronics, Accessories
  4. War 2 OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  5. MeitY Proposes 20-Year Tax Holiday for Data Centres to Boost Investment: Report
  6. Resident Evil Requiem, Resident Evil 7: Biohazard and Resident Evil Village Are Coming to Switch 2 Next Year
  7. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  8. iQOO 15 Live Image Hints at Design; Confirmed to Feature 2K Samsung AMOLED Display
  9. Vivo Y31 Pro 5G, Vivo Y31 5G Launched in India With 6,500mAh Battery, 50-Megapixel Camera: Price, Features
  10. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones With Dynamic EQ
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.