Home/Incidents/Optus

Optus

27 Sep 2019 · National · Telecommunications
Data Leak / Misconfiguration HIGH ✓ Verified

What happened

Telecommunications giant Optus suffered a long-term procedural data leak that resulted in the unauthorized public exposure of 41,728 customers who had explicitly requested unlisted numbers. Between October 2015 and September 2019, a systemic system error failed to process privacy preferences when customers ported their numbers to Optus, mistakenly transmitting their names, addresses, and mobile numbers to Sensis for publication in the physical and digital White Pages. Following a multi-year investigation, the Australian Privacy Commissioner issued a formal determination on 11 June 2026 finding Optus in breach of Privacy Principle 11.1, noting the company was aware of the ongoing risk but failed to take reasonable steps to reconcile its legacy database systems.

Incident details

Organisation
Optus
Date
27 Sep 2019
Attack type
Data Leak / Misconfiguration
Severity
HIGH
Sector
Telecommunications
State
National
Records affected
41728
Threat actor
Human Error

Source

smh.com.au ↗
← Back to all incidents