Police arrest 46-year-old over ClubsNSW data breach

police arrest 46-year-old over clubsnsw data breach

Pubs and clubs in NSW caught up in major data breach

A 46-year-old man has been arrested after an investigation into the massive breach of ClubsNSW data.

Detectives searched a home in Fairfield West about 4.20pm today, after a data breach exposed the identity of more than 1 million people.

The man was taken to Fairfield Police Station and was expected to be charged with blackmail.

Earlier this afternoon, police said they “were alerted to a website that had published the personal information of patrons who signed in using their drivers’ licences at specific premises across NSW”.

2GB Breakfast host Ben Fordham told the station this morning the breach was “causing a lot of worry in the NSW parliament”.

He said the leak involved the data scanned when people signed into the clubs, including facial recognition, driver licence details, signatures and addresses.

https://omny.fm/shows/ben-fordham-full-show/exclusive-major-data-breach-involving-prominent-po/embed

West Tradies in Mt Druitt, City of Sydney RSL and Fairfield RSL are among up to 15 clubs thought to be affected.

Police earlier said they’d identified “persons of interest” in their investigation into the breach.

“We will investigate a number of different types of offences, including the offence of blackmail under the Crimes Act, and possession of personal information for unlawful purposes,” Detective Chief Superintendent Grant Taylor said.

Taylor said police believed the leak was “a breach of a third party provider in relation to their ability to obtain that information and release it unlawfully”.

police arrest 46-year-old over clubsnsw data breach

Detective Chief Superintendent Grant Taylor

A little over an hour later, cybercrime detectives arrested the 46-year-old man in Sydney’s west.

Police said they were working to contain the data breach and have the site taken offline “as a matter of priority”.

On the risk of senior NSW politicians being exposed in the data breach, Taylor said: “within a million people’s names, no doubt there are individuals of some prominence”.

Anyone who suspects their identity was exposed in the broach was advised to wait to be contacted by authorities for further information.

This morning, ClubsNSW said it was “deeply concerned” after discovering a third-party data breach that could expose the details of Australians who have visited a range of clubs and RSLs in NSW, including prominent politicians.

“ClubsNSW has been made aware of a cybersecurity incident involving a third-party IT provider commonly used by hospitality venues, including fewer than 20 clubs,” the peak body said in a statement.

“The clubs concerned are working towards notifying all impacted patrons.”

The website claiming to expose the data carried a statement from the people behind it alleging they were “cut off” and not paid.

It says it had data including “facial recognition biometric, driver licence scan, signature, club membership data, address, birthday, phone number, club visit timestamps, slot machine usage”.

The site claims the system provider was hired to “build a suite of software systems” for casinos and clubs in Asia, Australia and the US.

“The developers were given access into back-end systems at these gaming venues and were given responsibility to maintain the systems and instructed to backup the data into the cloud,” it says.

“Developers were given access to raw data without any oversight …

“Then [the company] suddenly cut the developers off and refused to pay for a year and a half of work.”

Earlier reports had suggested venues owned by Merivale had been affected in the breach but the hospitality group has denied those claims.

“We are taking this matter seriously and do not believe that our customer data has been compromised in this third-party data breach, based on the information available to us at this time,” a Merivale spokesperson said.

Outabox, the IT provider working with ClubsNSW, said it was “aware and responding to a cyber incident potentially involving some personal information”.

“We have been in communication with a group of our clients to inform them and outline our strategy to respond. Due to the ongoing Australian police investigation, we are not able to provide further information at this time,” a company spokesperson said.

“We are aware of a malicious website carrying a number of false statements designed to harm our business and defame our senior staff. We believe this is linked and urge people not to repeat false and reputationally damaging misinformation.”

OTHER NEWS

4 minutes ago

Yngwie Malmsteen traces his Stratocaster story

4 minutes ago

Call for money seized by authorities to fund Invictus Games-style police event

4 minutes ago

The Last of Us Season 2 video shared online

5 minutes ago

PGA Championship cut line 2024: Projected cut, rules, updates for Friday's leaderboard

5 minutes ago

J.T. Miller's late goal lifts Canucks past Oilers to take a 3-2 series lead

5 minutes ago

K-pop group Stray Kids confirm 2024 tour dates, perform on Good Morning America

5 minutes ago

S’pore-listed Eagle Hospitality Trust CEO seeks to contest four disclosure-related criminal charges

5 minutes ago

Craig David says that Bo' Selecta 'bullying' forced him out of the UK

5 minutes ago

North Korea fires missile toward sea, South Korean media report

5 minutes ago

Minnesota Timberwolves crush Denver Nuggets to stay alive in NBA play-offs

5 minutes ago

Dazzling eagle gets Scheffler on right track at PGA Championship

5 minutes ago

Reddit forges pact with OpenAI to bring content to ChatGPT

5 minutes ago

What Portland chef Kevin Jones would eat for his last meal

5 minutes ago

South Africa's election could bring a defining moment — and new complications. Here's what to know

5 minutes ago

Massive Ukrainian drone attack on Crimea leaves Sevastopol without power

5 minutes ago

Modifications expected for proposed mask legislation

6 minutes ago

IPL 2024: LSG Assistant Coach Says 'Haven't Allowed KL Rahul to Play His Natural Game

6 minutes ago

Australian Fashion Week is over for another year - but not without delivering some of the most outrageous outfits yet: Take a look at the wild runway moments that had everyone talking in 2024

6 minutes ago

D-Day for PNG as NRL bid not a done deal: V'landys

6 minutes ago

USC paid nearly $20 million in Lincoln Riley's first season after poaching coach from Oklahoma, per report

6 minutes ago

Tyson Fury makes massive claim about Tyson v Paul fight

6 minutes ago

Mercedes has reportedly cancelled an entire EV platform

6 minutes ago

King’s wealth jumps £10 million to £610 million, Sunday Times Rich List reveals

6 minutes ago

Bodkin (2024) – Cast and Character Guide

6 minutes ago

GTA Online update for the week of May 16

6 minutes ago

Private schools claim Labour’s tax plan will trigger a special needs ‘catastrophe’

6 minutes ago

It's Not Every Day You Get to See Sachin Tendulkar and Brian Lara Playing Golf Together

6 minutes ago

Kyle Larson growing frustrated as Indianapolis 500 prep goes slower than anticipated

6 minutes ago

Stonewall’s list of top employers to be reviewed amid backlash over trans lobbying

6 minutes ago

'Young Sheldon': How Sheldon and Amy Came Back in the Series Finale

6 minutes ago

Canadian National Railway makes new contract offer to Teamsters union

6 minutes ago

Bulldogs out to fight for Beveridge in GWS clash

6 minutes ago

Lightning Re-Sign Forward Mitchell Chaffee to a Two Year, One Way Contract

6 minutes ago

Toby Keith inspired Jason Aldean to be 'unapologetic' about speaking his mind

6 minutes ago

Is Supercars facing an exodus? What NASCAR trend means

6 minutes ago

OPINION: Evan Roos is not ‘that guy’ for the Springboks

6 minutes ago

Sunak urges China to 'encourage Russia' to end the war in Ukraine

6 minutes ago

Buy, hold or sell these 3 ASX 200 healthcare shares: Experts

6 minutes ago

Sad reason young people driven from sport

6 minutes ago

In Georgia, Russian émigrés see familiar Kremlin tactics