Sign Up
..... Australian Property Network. It's All About Property!
Categories

Posted: 2022-09-23 04:29:41

Preliminary investigations by Optus suggest an error by an IT programmer may have inadvertently allowed cyber criminals to steal personal details of potentially millions of customers.

A senior figure inside Optus has spoken to the ABC on the condition of anonymity to offer confidential insights into the early findings uncovered by the telecommunication company's IT specialists. 

"[It's] still under investigation, however, this breach, like most, appears to come down to human error," the Optus insider told the ABC.

"[They] wanted to make integrating systems easier, to satisfy two-factor authentication regulations from the industry watchdog, the Australian Communications and Media Authority (ACMA)."

The process allegedly involved opening up the Optus customer identity database to other systems via what's known as an Application Programming Interface, with the assumption that the API would only be used by authorised company systems. 

"Eventually one of the networks it was exposed to was a test network which happened to have internet access."

This allowed access to the Optus network from outside the company.

A graphics shows an API which sits between the internet and a web server, which are between a web browser and database.
Application Programming Interfaces enable different applications to talk to each other.(ABC News: Emma Machan)

Optus told the ABC suggestions the attack stemmed from human error were inaccurate, but conceded the incident was still under investigation. 

Earlier today, the ABC put specific questions to Optus CEO Kelly Bayer Rosmarin about whether human error involving the company's API was behind the breach.

"I know people are hungry for details about the exact specificity of how this attack could occur, but it is the subject of criminal proceedings and so we will not be divulging details about that," Ms Bayer Rosmarin told an online media briefing. 

View More
  • 0 Comment(s)
Captcha Challenge
Reload Image
Type in the verification code above