News: 1665464225

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Optus data breach prompts pincer movement of twin regulatory probes

(2022/10/11)


Australian carrier Optus's recent data breach will be investigated by two regulators, the double trouble likely an indicator of the nation's displeasure at the incident – which saw almost ten million locals' personal data exposed online.

One of the probes will be conducted by the Australian Communications and Media Authority (ACMA), which will ponder "obligations relating to the acquisition, authentication, retention, disposal and protection of personal information, and requirements to provide fraud mitigation protections." The Authority's chair, Nerida O'Loughlin, said "A key focus for the ACMA will be Optus's compliance with these obligations."

The other probe will be conducted by the Office of the Australian Information Commissioner (OAIC) and will focus squarely on Optus.

[1]

"The OAIC's investigation will focus on whether the Optus companies took reasonable steps to protect the personal information they held from misuse, interference, loss, unauthorized access, modification or disclosure, and whether the information collected and retained was necessary to carry out their business," states the Commissioner's [2]announcement of the probe.

[3]

[4]

"The investigation will also consider whether the Optus companies took reasonable steps to implement practices, procedures and systems to ensure compliance with the Australian Privacy principles (APPs), including enabling them to deal with related inquiries or complaints," the announcement states.

The two organizations also announced they will co-ordinate their work.

[5]Singtel confirms digital burglary at Dialog subsidiary

[6]Australian Federal Police arrest man suspected of exploiting Optus cyberattack

[7]Australia asks FBI to help find attacker who stole data from millions of users

[8]Significant customer data exposed in attack on Australian telco

Both announcements also hint at a wider probe because Australian carriers are required to collect plenty of personal data to assist with legal investigations. The data exposed in this breach appears to have been captured in line with obligations to verify the identity of telecommunications services customers – a measure aimed at preventing fraud and making it harder for criminals to acquire and use comms services anonymously.

Carriers have no obligation to dispose of information collected during that process. Many Australians are now wondering why carriers aren't obliged to do so, and why they need to collect so much personal information to verify users' identities.

[9]

Identity as a service is therefore now being discussed down under, with a third party repository of data suggested as a better alternative to individual businesses recording and storing details of personal documents.

ID as a service is already offered by nations such as India, where the Aadhaar scheme processes billions of transactions each month. Aadhaar, however, has also been contentious as the colossal data trove it tends has been the target of attacks and [10]leaks on a scale orders of magnitude greater than the Optus incident.

Optus is yet to comment on the investigations. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y0U@vKae9HKD5k3cJAWjiQAAABE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.oaic.gov.au/updates/news-and-media/oaic-opens-investigation-into-optus-over-data-breach

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y0U@vKae9HKD5k3cJAWjiQAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y0U@vKae9HKD5k3cJAWjiQAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/10/10/singtel_dialog_breach/

[6] https://www.theregister.com/2022/10/06/optus_blackmail_arrest/

[7] https://www.theregister.com/2022/09/28/optus_data_breach_summary/

[8] https://www.theregister.com/2022/09/23/cyberattack_optus/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y0U@vKae9HKD5k3cJAWjiQAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2017/05/03/135_million_aadhaar_indian_government_payment_card_details_leaked/

[11] https://whitepapers.theregister.com/



Bubba Von Braun

Well once again corporate addiction to data comes and bites it on the A$$. There is no reason once the identity is validated to retain the information used.

Start off by making the fines well above the cost of doing business. I have seen and worked on so many systems where historical customer data is held for far beyond the customers involvement,in some instances the excuse de juor its too hard to purge. Poor system design, built upon convenient /non-existent legislation creates these honey pots. Add to that better, cheaper faster (the clean up is someone else's problem) and you have the third of the country exposed. I do seriously doubt anything will change here as Govt is on the same data junkie bender big corps are.

Cederic

Surely the ID validation is an ongoing matter. "Who is requesting use of this service" and "Who is using or has used this service".

It's hard to investigate criminal activity unless you remember who the person you validated as the user is.

Retention following account closure should be prevented. Retaining the full initial ID&V information should be prevented.

Hmm. I may have just agreed with you.

Bubba Von Braun

By all means keep the name.. but details such as ID document numbers no.. Use to validate and then destroy.

One major electrical chain here (JBHFI) insists on photocopies your id document (in my case a passport) when you do click an collect. In my case I cancelled the purchase and then purchased the same item over the counter without them recording any ID information!

And yes I have been exposed by Optus and am still awaiting their advice on what documents have been exposed.

A nuclear war can ruin your whole day.