Telecommunications giant Optus suffered a long-term procedural data leak that resulted in the unauthorized public exposure of 41,728 customers who had explicitly requested unlisted numbers. Between October 2015 and September 2019, a systemic system error failed to process privacy preferences when customers ported their numbers to Optus, mistakenly transmitting their names, addresses, and mobile numbers to Sensis for publication in the physical and digital White Pages. Following a multi-year investigation, the Australian Privacy Commissioner issued a formal determination on 11 June 2026 finding Optus in breach of Privacy Principle 11.1, noting the company was aware of the ongoing risk but failed to take reasonable steps to reconcile its legacy database systems.