Data Breaches 2022 to 2023 (including Optus)

September 14, 2023. myPerpetual is now accessible for some clients, with limited functionality.

Astonishing amount of time for an outage (to the outsider)!

1 Like

I had a nice chat with a lucky lady agent this afternoon with her promises to have a transcription of it sent to her management. Whether she can or will remains to be discovered, if it can be discovered. I may know by mid-week next if something very visible and incompetently stupid I mentioned has been taken care of.

Their ongoing incompetence is mind bending. I’ll refrain from posting their list of new gaffes to avoid ‘bad people’ going looking for ‘things they can play with’.

I also made comments on the senior management, board, and the opaqueness of their 3rd party and what compensation is on the table.

…and more. A clown circus is an appropriate reference and it is ongoing.

1 Like

I at least managed to get my annual tax statement from them so I could do my tax return.
I watch in fascination as they slowly rebuild their computer systems to provide an online facility to customers. And indeed advisors to customers.

Meanwhile elsewhere in cyberspace: Dymocks confirms details of 1.2 million customers shared on dark web in data breach

So just to be clear … do you have access to the web site?

What about you, @Gregr?

You will note that the comment that I posted said that only some clients had access - but I don’t know the details of that obviously.

In some sense, it seems as if the outage is ongoing i.e. until at least all customers have access. So the outage clock is still running …

My understanding is all customers can log in again but it is currently in read-only mode. No transactions can be initiated from it.

It was ‘fascinating’ that prior to being connected to that ‘lucky agent’ I spoke with that I had to endure an outdated minutes long message about how it was last week and for the previous month+, not how it is now. They could not even coordinate that.

Haven’t tried the latest evolution of the rebuild. I am interested to get current tax year distribution and price info. If that is there yet.

I don’t myself have an investment with Perpetual but I checked with someone who does and they confirm that login works for them. That’s just one data point though.

1 Like

Seems Perpetual have an online system again. At least one that serves my purposes for the present.

As for the Dymocks leak, HIBP added that one as occured back in June. June 20 to be exact when presumably it was on the dark web for sale.

2 Likes

Today’s breach news: Super SA and possibly other government stuff in SouthAus

1 Like

And a follow-up on an earlier breach: Pareto Phone, telemarketer at centre of charity cyber hack which targeted tens of thousands of Australian donors, collapses

Not just bad for customers, bad for business.

1 Like

DP World Australia which is responsible for around 40% of the cargo movements in and out of Australia, was hacked sometime around Friday last week. As a result of the cyber hack, they disconnected themselves from the internet to reduce the damage that could be done to their systems. This has resulted in a large backlog of containers (around 30,000) that need to be moved from the ports where they are currently sitting. No responsible party for the hack has been publicly identified as yet, DP Australia are working with cyber security experts both private and Government, to look at the issue. This breach “does show how vulnerable we have been in this country to cyber incidents and how much better we need to work together to make sure we keep our citizens safe,” Cyber Security Minister Clare O’Neil told ABC Radio". Amen to that and the hope that our laxity in this area will be addressed properly.

1 Like

TissuPath: TissuPath data breach victim upset by delayed notification - ABC News

A Melbourne-based pathology company. Breach includes Medicare numbers, which is always helpful to hackers.

2 Likes

And a follow-up to the DP World breach: DP World Australia confirms employee data was stolen during cyber attack, warns of further freight delays ahead of Christmas rush - ABC News

Back in the day, it was often said that HR data should be air-gapped. Not only does this protect the data from an attack from the internet but it also largely protects the data from inappropriate internal access.

3 Likes

Booking.com has been subject of a cyber breach…

The login credentials of a Connectivity provider’s Booking.com extranet account, which they use to provide support services to their connected properties, were stolen. The cybercriminals involved used this extranet account to create a number of guest message templates. They then used these templates to send messages to fraudulently request payment from guests with new reservations at properties connected to this Connectivity provider.

Traditionally messages through the Booking.com platform have been secure, but this breach shows that they have vulnerabilities.

Booking.com and other similar platforms are attractive to hackers/criminals as it is very easy for them to scam payments from travellers. As many travellers book well in advance, payments can be made early and outside the usual credit card/Visa or MC debit card chargeback periods, making the scam more successful and lucrative to criminals.

Phishing is also common with these platforms. Phishing serves two purposes, to steal private details of travellers and to create sham bookings to scam accommodation providers.

4 Likes

Not one but two: St Vincent’s health network and Life Saving Victoria … St Vincent's Health network hit by cyber attack, with data stolen - ABC News , Life Saving Victoria server hacked by 'malicious actors' - ABC News

And Yakult: Yakult Australia targeted in cyber attack, employee files published on dark web - ABC News

123 posts were merged into an existing topic: Data Breaches 2024 to 2025

Some background on the business and it’s services.

1 Like