Optus hack ‘not highly sophisticated’

Australia’s telecommunications watchdog has alleged Optus could have fixed a simple coding error four years before hackers were able to steal personal details of millions of customers.

In a claim published by the Federal Court on Wednesday, the Australian Telecommunications and Media Authority (ACMA) outlined how it alleged the September 2022 cyber attack took place and the failures of Optus to notice or fix the vulnerability.

About 9.5 million current and former customers were caught up in the breach, with personal information including names, dates of birth, phone numbers and email addresses exposed over three days.

The personal details of about 10,200 people were subsequently published on the dark web.

optus hack ‘not highly sophisticated’

Optus hack ‘not highly sophisticated’

The ACMA, which launched legal action against Optus in May this year, alleges a coding error in September 2018 left a dormant web API vulnerable when it became internet acceptable in June 2020.

It’s alleged Optus identified it’s main website was vulnerable and fixed the error in August the following year, but did not notice the same issue affected the second system.

“The target domain was permitted to sit dormant and vulnerable to attack for two years and was not decommissioned despite the lack of any need for it,” the filing reads.

“The cyber attack was not highly sophisticated or one that required advanced skills … it was carried out through a simple process of trial and error.”

optus hack ‘not highly sophisticated’

The Authority alleges Optus had the opportunity to identify the coding error at several stages in the preceding four years before the breach.

The ACMA is seeking penalties, alleging Optus breached the Telecommunications Act at least 3.6 million times — the estimated number of active Optus subscribers at the time.

If proven, each breach carries a penalty of up to $250,000, resulting in a theoretical maximum of $900 million.

Optus has previously declared its intent to defend the proceedings, saying it had previously apologised to customers and reimbursed the cost of new identity documents.

The case will next return before Justice Jonathan Beach in September for a case management hearing.

OTHER NEWS

22 minutes ago

Jamie Carragher suffers Twitter hack during England game as tweets cause confusion

22 minutes ago

TV legend quits iconic Neighbours role as Toadie after 30 years

22 minutes ago

Marko warns Red Bull: 'Even Verstappen can't drive like this for a whole season'

22 minutes ago

Dogs sweat in the summer, too, but can a haircut cool them off?

22 minutes ago

UAE to announce petrol prices for July: will rates drop further?

27 minutes ago

‘Planet Killer’ asteroid will be one of the closest asteroids to plunge past planet Earth this year

27 minutes ago

How “A Quiet Place: Day One” director incorporated his love of “Lord of the Rings”

27 minutes ago

Luke Littler to miss World Cup of Darts as Phil Taylor weighs in on snub

27 minutes ago

Massive $75million side-by-side mansions are sold days before auction

27 minutes ago

John McEnroe makes stance crystal clear about working with Andy Murray at Wimbledon

28 minutes ago

Iceland's Volcanic Eruptions Could Continue For Decades, Study Finds

28 minutes ago

Victorian nurses secure 'once in a generation' pay rise

28 minutes ago

John McEnroe lays into Wimbledon crowd over Novak Djokovic reaction

28 minutes ago

MLB Roundup: Mariners beat Rays to avoid sweep

28 minutes ago

Australia in tennis at the Olympics: Has Australia ever won a medal in singles or doubles?

28 minutes ago

Sharjah Ruler's Court mourns Sheikha Noura bint Saeed Al Qasimi

28 minutes ago

Shohei Ohtani, Gavin Stone help Dodgers shut down White Sox

29 minutes ago

Genesis taunts us with another mid-engine V6 supercar concept

29 minutes ago

Spears has spoken to sons but no reconciliation soon

32 minutes ago

‘A disastrous event for the region': why an Israel-Hezbollah war would be devastating to both sides

35 minutes ago

From Luna to Alfie and Teddy, MailOnline's new interactive map reveals the most popular dog names in YOUR area

35 minutes ago

Prince Harry opens up about pain of losing Princess Diana in new video

36 minutes ago

Mexico announce squad for 2024 U-20 CONCACAF Championship

36 minutes ago

Prospect of low-priced Chinese EVs reaching US from Mexico poses threat to automakers

36 minutes ago

Euro 2024’s eliminated teams prove the controversial format is working

36 minutes ago

‘Are you two really the best we’ve got?’: Election summed up with excruciating question to Sunak and Starmer

36 minutes ago

Glastonbury 2024 live: Latest weather updates as thousands more arrive at festival

36 minutes ago

Neil Young cancels remainder of Crazy Horse tour for ‘big unplanned break’

36 minutes ago

Homes Under the Hammer star shares health update after cancer diagnosis

36 minutes ago

Magpies set to take flight with flag stars returning

36 minutes ago

Saudi Arabian taekwondo standout Donia Abu Taleb 'dreams' of gold at Paris Olympics

36 minutes ago

Why Adil Rashid will be India’s toughest challenge in T20 world cup semifinal

36 minutes ago

Could the World Cup signal goodbye for India's batting legends?

36 minutes ago

Levi sisters pondering jump from sevens to Wallaroos

36 minutes ago

Yesterday was the hottest day of the year in the UK, Met Office says

36 minutes ago

T-wolves jump in for Dillingham and draft exonerated Shannon, after Blazers go big with Clingan

36 minutes ago

Paris Hilton tells Congress how she was ‘sexually abused and force-fed meds’ during child welfare hearing

36 minutes ago

Motorist fined for parking on own driveway

36 minutes ago

Birthday card could be considered harassment, tribunal rules

36 minutes ago

10 Best The Far Side Comics About Cats