Sign Up
..... Australian Property Network. It's All About Property!
Categories

Posted: 2022-09-27 00:10:47

Optus, Australia's second largest telecommunications company, announced on September 22 that identifying details of up to 9.8 million customers were stolen from their customer database.

The details, dating back to 2017, include names, birth dates, phone numbers, email addresses, and – for some customers – addresses and driver's licence or passport numbers.

According to Australian law, telecommunications providers are required to hold your data while you are their customer and for an additional two years, but may keep the data for longer for their own business purposes.

This means that if you are a previous customer of Optus, your data may also be involved — although it remains unclear how long the details of past customers have been held.

The stolen data constitutes an almost complete suite of identity information about a significant number of Australians. Optus states they have notified those affected, but there are plenty of questions remaining.

What happens with your data next, and what can the average Australian do to protect against the threats caused by this unprecedented data breach?

Space to play or pause, M to mute, left and right arrows to seek, up and down arrows for volume.
Play Video. Duration: 1 minute 47 seconds
Home Affairs Minister says Optus hack should not have happened.

What will happen to the data?

Late last week, an anonymous poster on a dark web forum posted a sample of data ostensibly from the breach, with an offer not to sell the data if Optus pays a $US1 million ransom.

While its legitimacy has not yet been verified, it is unlikely the attackers will delete the data and move on.

More likely, the data will be distributed across the dark net (sold at first, but eventually available for free). Cybercriminals use these data to commit identity theft and fraudulent credit applications, or use the personal information to gain your trust in phishing attacks.

Below, we outline several steps you can take to proactively defend yourself, and how to detect and respond to malicious uses of your data and identity.

A woman uses her phone outside an Optus store as a man looks at his.
Current and previous customers have been affected by the breach.(AAP: Dan Peled)

What should I do if I’ve been affected?

Step 1: Identify your most vulnerable accounts and secure them

Make a list of your most vulnerable accounts.

  • What bank accounts do you hold?
  • What about superannuation or brokerage accounts?
  • Do you have important medical information on any services that thieves may use against you?
  • What accounts are your credit card details saved to?

Amazon and eBay are common targets as people often keep credit card details saved to those accounts.

Next, check how a password reset is done on these accounts.

Does it merely require access to your text messages or email account? If so, you need to protect those accounts as well. Consider updating your password to a new – never before used – password for each account as a precaution.

Many accounts allow multi-factor authentication. This adds an extra layer for criminals to break through, for example by requesting an additional code to type in.

Activate multi-factor authentication on your sensitive accounts, such as banks, superannuation and brokerage accounts.

Ideally, use an application like Google Authenticator or Microsoft Authenticator if the service allows, or an email that is not listed with Optus.

Avoid having codes sent to your Optus phone number, as it's at higher risk of being stolen.

Step 2: Lock your SIM card and credit card if possible

One of the most immediate concerns will be using the leaked data to compromise your phone number, which is what many people use for their multi-factor authentication.

SIM jacking – getting a mobile phone provider to give access to a phone number they don't own – will be a serious threat.

View More
  • 0 Comment(s)
Captcha Challenge
Reload Image
Type in the verification code above