A million Australian pubgoers wake up to find personal info listed on leak site
- Reference: 1714622470
- News link: https://www.theregister.co.uk/2024/05/02/australian_pubs_data_breach/
- Source link:
An anonymously published leak site claims the records came from a tech services company called Outabox.
The leak site, which The Register has visited but will not name or link to for legal reasons, offers a search facility that produces info on individuals’ names, partial addresses, and dates of birth – and the venue at which the information was recorded. The Register has verified that the leak site contains info that accurately describe people of our acquaintance.
[1]
The venues listed on the leak site are registered clubs - Australian institutions that typically combine a pub, a restaurant, a few slot machines, community and sporting facilities, function centers, and sometimes even a sizable theater.
[2]
[3]
Clubs enjoy tax exemptions for some food and drink sales to members, as many were founded as community hubs for military veterans. Members therefore sign in to clubs when they visit to prove they are eligible for the discounts on offer. Clubs capture those sign-ins, plus info on visitors, and data required under laws that regulate gambling and aim to make life hard for money-launderers.
In recent years, much of that data has been collected digitally.
[4]
Outabox appears to be in the business of collecting that sort of data for clubs, as it [5]lists an entry management system called "Triagem" among its products, and describes it as "a state-of-the-art contactless sign-in kiosk that allows both members and guests to sign into the venue with ease." The kiosk can capture facial biometrics and match it to a database.
The leak site alleges Outabox contracted development of some software to offshore developers, and that those coders were given access to data gathered by gaming venues – including facial biometrics, scans of drivers' licenses, and club membership details. The leak site also claims that the outsourced developers were told by Outabox to back up that data into public clouds and suggests that allowing offshore workers unlimited access to personal data, and storing it offshore, is not best practice.
The leak site further alleges that Outabox didn't pay its outsourced contractors – but doesn't suggest those workers are responsible for the leak site.
[6]
The Register contacted Outabox. The biz offered us only a “no comment” response, and would not provide an email address we could use to send further questions.
However Outabox's website contains a [7]statement that declares it "has become aware of a potential breach of data by an unauthorized third party from a sign in system used by our clients" and is "working as a priority to determine the facts around this incident, have notified the relevant authorities and are investigating in cooperation with law enforcement."
[8]Australia’s spies and cops want ‘accountable encryption’ - aka access to backdoors
[9]Australia imposes cyber sanctions on Russian it says ransomwared health insurer
[10]Australia declares 'nationally significant cyber incident' after port attack
[11]Significant customer data exposed in attack on Australian telco
ClubsNSW – the peak body for all licensed clubs in the Australian State of New South Wales – has advised members that it has "been made aware of a cyber security incident involving a third-party IT provider commonly used by hospitality venues, including 16 clubs" and that "some personal information of patrons of the clubs that use this IT provider may have been compromised."
Wests Tradies, a registered club, has [12]posted [PDF] a privacy breach notice, acknowledging it has used a third-party tech company for "ID scanning software and gaming system software," and that the business "has notified the club that it is a target of a cyber extortion campaign."
The privacy breach notice also states: "The club did not authorize, permit, or know that the external IT provider had provided any information obtained from the club to third parties."
Local authorities are investigating the matter, which is being treated as a data breach.
Troy Hunt, founder of leak-tracking website [13]haveibeenpwned.com , used his X account to [14]suggest those named in the breach will need to replace their drivers' licenses.
That requirement could make this an expensive exercise for whoever leaked the data. Past data breaches in Australia have seen victim companies foot the bill for their customers' replacement credentials after breaches. ®
UPDATED AT 08:20 UTC MAY 2nd : Police have arrested a man over the breach. A [15]statement reveals a 46 year-old Sydney man was detained and "is expected to be charged with blackmail."
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjNkRHJasP6FCRLduL4HhAAAAAA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjNkRHJasP6FCRLduL4HhAAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjNkRHJasP6FCRLduL4HhAAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjNkRHJasP6FCRLduL4HhAAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.outabox.io/products/triagementrymgmt/index.html
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjNkRHJasP6FCRLduL4HhAAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.outabox.io/press_release/index.html
[8] https://www.theregister.com/2024/04/25/asio_afp_accountable_encryption/
[9] https://www.theregister.com/2024/01/23/australia_medibank_private_attacker_named/
[10] https://www.theregister.com/2023/11/13/asia_tech_news_roundup/
[11] https://www.theregister.com/2022/09/23/cyberattack_optus/
[12] https://westtradies.com.au/wp-content/uploads/2024/05/Notice-Regarding-Data-Breach.pdf
[13] https://haveibeenpwned.com/
[14] https://twitter.com/troyhunt/status/1785784983313080671
[15] https://www.police.nsw.gov.au/news/news?sq_content_src=%2BdXJsPWh0dHBzJTNBJTJGJTJGZWJpenByZC5wb2xpY2UubnN3Lmdvdi5hdSUyRm1lZGlhJTJGMTExNzc1Lmh0bWwmYWxsPTE%3D
[16] https://whitepapers.theregister.com/
Why keep so much info?
Why did this service even keep driver's licence details, let alone biometrics? After confirming they're legit with whatever gov body handles that, isn't all you need to record just the fact that you verified it, not what you verified?
Re: Why keep so much info?
Because that information is valuable. It isn't as though a system that NFC built into all smartphones would be expensive to implement. Just pull up the wallet app on your and hold it to a scanner when you walk in and it could identify you as a member, without having to provide any personal information other than what they might collect at signup like your name and age (to prove you're old enough to drink) and maybe a credit card number if there is billing involved for membership.
The reason they implement it with facial recognition that is undoubtedly much more expensive is because then it can gather a lot more information. Not just when you enter, but when you leave, how much you spend etc. That's really valuable if either the place you frequent wants to send you offers or other places want to advertise your way. Ideally from the pub owner's perspective the service would be "free" to them, with the profit made by the sale of all the personal info on your customers you allow them to collect!
Re: Why keep so much info?
If you read the article, you might also have spotted the point that some of these clubs are set up to cater to military vets, and offer discounts to the same. So before offering you half off on your drinks, the business should verify that you actually served.
Still doesn't explain why they would keep the license or such on hand afterwards, but I do understand why they would need this information (providing it should be voluntary, obviously - you might well think that your privacy isn't worth the discount even if you *are* a vet).
Re: Why keep so much info?
"Because that information is valuable."
Those who thought it was are now discovering that the correct word is "toxic".
This is why Europe has customer protection protection regulations some commentard recently described as "Stalinist". This is what happens when you don't have them or don't follow them.
Last visited an Oz club a few years ago
They wanted me to scan my drivers licence.
Ahhh, no.
I completed a paper form instead, sans genuine data.
They were warned....
As shown by this Australian Information Commissioner Privacy Case in 2011....
https://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmrCN/2011/2.html?context=1;query=registered%20club;mask_path=au/cases/cth/AICmrCN
The complainant alleged that a registered club interfered with their privacy by scanning their driver licence and, in doing so, recording unnecessary information. The complainant conceded that the club was required to collect their name, address and signature. However, the complainant considered the collection of the other information on the licence, including their date of birth, driver’s licence number, driver’s licence type and photograph to be unnecessary.
The complainant also raised concerns that the registered club ’s notice and security procedures were insufficient.
Re: They were warned....
Yeah, but what was the resolution of that complaint?
TL;DR: the club pointed to its own privacy statement and undertook to delete the data of anyone who asked for it to be deleted. Beyond that, it didn't have to change its ways.
Out of the box cowboys
"The leak site further alleges that Outabox didn't pay its outsourced contractors.
1 : Is there any evidence to suggest that Outabox were ever anything but a bunch of cowboys.
2 : What advantage does facial recognition actually offer, other than being more expensive and far more intrusive.
3 : That sounds like an awful lot of data required just to enter a club.
Leak site?
The "leak site" appears to be similar to haveibeenpwned, it just lets you check if your details have been leaked.
Why store this much data?
About 30 years ago I used to go out underage drinking with friends (in the UK, not Australia). There was a club where they had an unwritten rule that they'd allow slightly underage people in, on the proviso that they signed up for "membership". Membership in this case was free, and they *posted* you physical vouchers every few months with drinks offers. These were valuable because as a teenager you didn't typically earn much money - if any at all.
Of course the reason they did that was because that way they had your address. Where you lived with your parents. So the chances of people causing fights or doing anything too stupid was reduced. It did actually work.
At the time some people questioned how legit this was and even whether it was legal. Well of course it wasn't because they were serving underage drinkers but nobody back then really cared. The greater good was that it reduced problems in the town.
I think this is more sinister though. It's blatantly holding way more data than is really necessary for any reasonable purpose. The question shouldn't just be about how or why the data was leaked, but WTF it was really being stored and used for in the first place.
Pint icon, for obvious reasons.
"The kiosk can capture facial biometrics and match it to a database"
So, one step further down the road to biometrics being used for the most mundane things.
Why does a club require you to give up your face to some datacenter that gives no guarantee that it knows how to manage that data securely and is not under legal obligation to do so ?
The sooner we treat biometrics with the same level of care and security that we treat financial data, the better.
Banks are under serious obligations to have the right to handle our money. Firms using biometrics should be as well, because I can't change my face if you foul up.