📉 Nikkei is down nearly 5% -> here are 43 recession-proof Japanese stocks from our screenerUnlock Now

Optus customer data containing 10 million records allegedly for sale on Dark Web

Published 02/08/2023, 03:45 pm
Updated 02/08/2023, 04:00 pm
© Reuters.  Optus customer data containing 10 million records allegedly for sale on Dark Web

In a worrying trend, a threat actor on the Dark Web is claiming to have possession of Optus' extensive database containing the personal details of 10 million customers, which could potentially be related to the data leak which occurred in September last year.

This purported database includes sensitive information such as email addresses, first names, last names and physical addresses.

The news first broke on Twitter via the account @DailyDarkWeb on July 31 and has since sent shockwaves through the cybersecurity community.

Renowned Australian cybersecurity expert, Troy Hunt, responded to the tweet with a measured statement, cautioning, “Claims. Time will tell if it’s genuinely Optus data.”

Last September, the hack on Optus shook the nation, when data of 11.2 million customers were held for ransom by the hacker.

However, in a quick turn of events, the hacker withdrew the ransom demand, apologised to Optus and the Australian people and claimed that the data had been destroyed.

Presently, authorities and cybersecurity experts are in the process of verifying the authenticity of the new claim.

The seller's motives remain unclear, and as of now, no evidence has been provided to substantiate the seller's allegations.

Optus has yet to officially comment on the matter, leaving customers and the public awaiting confirmation on the validity of the situation.

What happened last year?

Last September, Optus revealed that the breach in its systems exposed an unspecified number of customer names, dates of birth, phone numbers and email addresses.

Alarmingly for a subset of customers, addresses and identity document numbers, such as driver’s licences or passport numbers, were also taken in the breach.

However, payment details and account passwords were not compromised in the attack.

Darkweb screenshots surfaced quickly after the attack, with an underground BreachForums user going by the moniker of ‘optusdata’ offering two tranches of data - one with 10 million records.

The hacker claimed to have records for about 11.2 million Optus customers, including their names, dates of birth, phone numbers, email addresses and, for a subset of customers, addresses and ID document numbers such as driver’s licence or passport numbers.

Subsequently, optusdata released 10,000 records to twist Optus’s hand in the negotiations and verify the legitimacy of the claims.

Read more on Proactive Investors AU

Disclaimer

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.