Cyber Security: We won't just do better. We'll do best.
Latest updates
Updated 11 November 2022 — 1.00pm | First published 22 September 2022 — 6:57am
8 March 2023 Introducing our Cyber Panel
11 November 2022 Optus update on Equifax SMS phishing sent to customers
8 November 2022 Optus update on Equifax Protect for most affected customers
17 October 2022 Optus update on Passport Document numbers
Introducing our Cyber Panel
08 March 2023
Further to our Cyber Commitment to share learnings and new expertise to raise the bar in Australian cyber security, we have appointed a panel of global cyber experts. This Panel will act as advisors to Optus on Cyber Security, Information Security, and Identity Protection and will engage with our teams and our Enterprise and Business customers. We commit to sharing key learnings from this panel with the community to help keep more Australians digitally safe.
Eva Galperin (USA) Director of Cyber Security – Electronic Frontier Foundation, Technical Advisor, Freedom for Press Association Eva has conducted research on malware and nation-state spyware for vulnerable populations, written privacy and security training materials including Surveillance Self Defence and the Digital First Aid Kit and championed the development and implementation of antivirus software that detects stalkerware on mobile phones.
Jeff Lanza (USA) Retired FBI Agent – White Collar Crime and Cyber, The Lanza Group Jeff was a leading FBI Special Agent for over 20 years, investigating cybercrime, fraud, organized crime, human trafficking and terrorism. Today, Jeff provides training to organisations and government agencies around the world to help them stay safe from cybercrime and fraud.
Nigel Phair (Australia) Retired AFP – Detective Superintendent, Professor of Cyber Security, Monash University Nigel has extensive experience in cybercrime during his time with the Australian Federal Police. Today, Nigel conducts research and provides commentary into the cyber landscape within Australia and around the world, including trends, governance, attitudes, skills shortages, and emerging technologies, all with an ambition to help organisations design their technology strategies.
Optus update on Equifax SMS phishing sent to customers
11 November 2022
Optus and Equifax have been made aware of an ongoing SMS phishing (also known as smishing) campaign targeting individuals impacted by the recent cyberattack. The message claims to be from Equifax, advising individuals that they are entitled to a free Equifax subscription as a customer of Optus which can be accessed by clicking on a malicious link within the SMS. The link asks for individuals to verify their identity using their credit card information.
Please note that Optus has not sent out any SMS relating to Equifax Protect. Optus will not send links or request information, like passwords, in the communications we send our customers about the cyberattack. All text messages to customers from Optus will be sent from OPTUS, OPTUS MSG, OPTUSMSG or OPTUS_MSG. In addition, Equifax has advised it does not verify customer details using credit card information.
We remind you to remain vigilant and keep an eye out for phishing attempts and scams. For more information visit our cyber security resources page for guidance on protecting yourself against cyber security risks.
Optus update on Equifax Protect
Updated 8 November, originally posted 26 September 2022
Optus is offering Optus account holders, the option to take up a 12-month subscription to Equifax Protect at no cost.
Equifax Protect is a credit monitoring and identity protection service that helps reduce the risk of identity theft or financial loss.
For information on how to activate Equifax Protect please visit Equifax Protect Eligibility (optus.com.au)
Optus update on Passport Document numbers
17 October 2022
As a result of discussions with the Department of Foreign Affairs and Trade, Department of Home Affairs and New Zealand Internal Affairs, Optus has now communicated to all contactable customers whose passport number was exposed in the cyberattack. The advice for Australian Passports holders is that you do not need to replace your passport. For New Zealand Passport holders, International Passport holders and more context around this advice visit our Passport information page.
Optus chief executive Kelly Bayer Rosmarin told the ABC on Friday it was thanks to a number of government agencies that people could now "continue with their travel plans and feel safe and secure". View Ms Rosmarin’s interview with the ABC here at Optus customers affected by data breach do not need new passports, chief executive says - ABC News
Optus update on contacting our customers
Updated 17 October, originally posted 14 October 2022
Optus confirms that we have now contacted impacted customers that have with up-to-date email or SMS contact information, in relation to the following:
- Driver Licence number and/or card number in all states and territories
- Proof of Age/Proof of identity* in all states and territories
- Australian & International Passport holders
- Medicare card numbers
- Customers with invalid/incomplete ID document numbers (relating to the above listed forms of ID)
If Optus did not have valid email or SMS contact details for any impacted customers in the above categories, these customers will be contacted as soon as possible via post using the last mailing address we have on file.
In addition to the above we are in the process of contacting impacted customers with other lesser-known forms of identification used to make up 100 points of ID.
*This card may go by another name, as they vary from state to state.
Optus update: Federal government and Optus form joint working group
7 October 2022
Optus welcomes the Government announcement on proposed changes to data sharing regulations. This proposal will enable businesses to share information with approved financial institutions and government agencies, enabling them to apply enhanced monitoring and safeguards to the accounts of customers affected by the current and future cyber incidents. Optus’ Vice President of Regulatory and Public Affairs Andrew Sheridan welcomes the proposal, stating it is "about protecting Australians".
Optus is also pleased the Federal Government has taken the initiative to form a joint working group with Optus to enhance the coordinated response to the cyberattack. Optus looks forward to ongoing collaboration with the working group and all governments.
Optus update on Medicare ID Number
Updated 7 October, originally posted 28 September 2022
Of the 9.8 million customer records exposed, we have identified 17,000 valid Medicare ID numbers that have not expired. There are also a further 26,000 expired Medicare card numbers exposed. Optus can confirm that we have communicated with all contactable customers who have had their Medicare card number exposed. If we did not have valid contact details for impacted customers, those customers will be contacted via direct mail using the last mailing address we have on file, as soon as possible.
Please be assured that people cannot access your Medicare details with just your Medicare number. If you are concerned or have been affected, you can replace your Medicare card as advised by Services Australia. Our call centres will not have further information to assist on this matter. We are in contact with Services Australia and we will be letting all affected customers know the guidance on the steps they can take.
For more information you can visit www.servicesaustralia.gov.au/optusbreach
Optus commissions independent external review of cyberattack
3 October 2022
Deloitte to lead forensic review of cyberattack.
Optus is appointing international professional services firm Deloitte to conduct an independent external review of the recent cyberattack, and its security systems, controls and processes.
The review was recommended by Optus Chief Executive Officer, Kelly Bayer Rosmarin, and was supported unanimously by the Singtel Board, which has been closely monitoring the situation with management since the incident came to light.
As part of the review, Deloitte will undertake a forensic assessment of the cyberattack and the circumstances surrounding it.
Ms Bayer Rosmarin said the forensic review would play a crucial role in the response to the incident for Optus, as it works to support customers.
“We’re deeply sorry that this has happened and we recognise the significant concern it has caused many people. While our overwhelming focus remains on protecting our customers and minimising the harm that might come from the theft of their information, we are determined to find out what went wrong.”
She added, “This review will help ensure we understand how it occurred and how we can prevent it from occurring again. It will help inform the response to the incident for Optus. This may also help others in the private and public sector where sensitive data is held and risk of cyberattack exists.
“I am committed to rebuilding trust with our customers and this important process will assist those efforts.”
Deloitte’s global specialists will work with the Singtel and Optus teams and other international cyber experts. Optus will continue also to engage with relevant stakeholders.
Optus Update on Medicare card and Driver Licence numbers
2 October 2022
Optus confirms we have now sent an email or SMS from Optus and/or Optus MSG to customers that we have a Driver Licence on record in NSW, ACT, SA, NT, WA and Tas, confirming their driver licence number and card number were exposed in the cyberattack. We have also contacted customers to advise if their Medicare card number has been exposed.
We continue to work with the State governments for individuals that hold Driver Licences in Victoria & Queensland and will provide advice as soon as possible.
If we did not have valid contact details for any impacted customers, these customers will be contacted via post using the last mailing address we have on file, as soon as possible.
We continue to reach out to customers who have had other details exposed.
A reminder that there were no direct debit or credit card details compromised in the cyberattack. Additionally, all customer My Account login details including username and password remain secure.
Customers are encouraged to remain vigilant and check written communications carefully. We will not send links or request information, like passwords, in the communications we send our customers about the cyberattack. Scammers will often send from legitimate-looking email addresses, so if in doubt, customers should double check by clicking on the name and checking the sender address.
Optus update: Operation Guardian delivers specialised protection for Optus customers
30 September 2022
As per the joint media release issued by the Australian Federal Police, all State and Territory Police, Australian Cyber Security Centre, Australian Banking Association, IDCARE and Customer Owned Banking Association.
The AFP and state and territory police have set up Operation Guardian to supercharge the protection of more than 10,000 customers whose identification credentials have been unlawfully released online under the Optus data breach.
Customers affected by the breach will receive multi-jurisdictional and multi-layered protection from identity crime and financial fraud. The 10,000 individuals, who potentially had 100 points of identification released online, will be prioritised.
Under the AFP-led partnership between law enforcement, the private sector and industry to combat the growing threat of cybercrime, Operation Guardian will focus on key measures to help shield affected customers, including:
- Identifying the 10,000 individuals across Australia now at risk of identity fraud and alerting industry to enable further protection for those members of the public
- Monitoring online forums, the internet and the dark web for other criminals trying to exploit the personal information released online
- Engaging with the financial service industry to detect criminal activity associated with the data breach - Analysing trends from ReportCyber to determine whether there are links between individuals who have been exploited, and To identify and disrupt cyber criminals.
Operation Guardian will use collective legislative powers, experience, investigative and intelligence capabilities of all Australian policing jurisdictions.
If you believe you are a victim of Cybercrime, please report it to ReportCyber at cyber.gov.au
Optus update on contacting our customers
26 September 2022
Optus has now sent email or SMS messages to all customers whose id document numbers, such as licence or passport number, were compromised because of the cyberattack.
We continue to reach out to customers who have had other details, such as their email address, illegally accessed.
We understand and apologise for the concern that this has caused for our customers.
Payment detail and account passwords have not been compromised as a result of this attack.
Optus update on protecting our customers
26 September 2022
Optus is working with a number of organisations to protect customers whose information was compromised because of a cyberattack.
The Australian Cyber Security Centre has provided advice for those current and former customers who have been impacted on their website, cyber.gov.au. The ACSC’s 1300 CYBER1 hotline also provides advice and referral information to those impacted.
Those impacted by the incident are also advised to contact reputable sources for information such as Moneysmart, ID Care and the Office of the Australian Information Commissioner.
Optus wishes to reiterate to customers that our email and SMS notifications will not have hyperlinks. If customers receive an email or SMS with a link claiming to be from Optus, they are advised that this is not a communication from Optus. Please do not click on any such links.
The attack is being investigated by the Australian Federal Police, and they have advised Optus not to provide comment on certain aspects of the investigation, including verifying the authenticity of customer information published on the internet.
If customers feel they’ve suffered any loss as a result of the cyberattack, they should contact us 133 937.
Optus update on contacting our customers
24 September 2022
Optus is contacting all customers to notify them of the previously announced cyberattack’s impact, if any, on their personal details. We will begin with customers whose ID document number may have been compromised, all of whom will be notified by today. We will notify customers who have had no impacts last.
No passwords or financial details have been compromised.
We are not sending links in SMS or emails. If customers receive an email or SMS with a link claiming to be from Optus, they are advised that this is not a communication from Optus. Please do not click on any links.
If you have any queries regarding your account or about any email or SMS you might have received, please reach out to Optus via your My Optus App or on 133 937.
As the cyberattack is now under investigation by the Australian Federal Police, Optus cannot comment on certain aspects of the incident. We are cooperating with all relevant authorities to find the criminals behind it.
Optus shut down the attack as soon as it was discovered.
We have been advised that our announcement of the attack is likely to trigger a number of claims and scams from criminals seeking to benefit financially, including through:
Phishing scams via calls, emails and SMS.
Offering illegitimate customer details for sale.
Given the investigation, Optus will not comment on the legitimacy of customer data claimed to be held by third parties and urges all customers to exercise caution in their online transactions and dealings.
Once again, we apologise. We will provide further updates as new information comes to hand.
Optus notifies customers of cyberattack compromising customer information
22 September 2022
Following a cyberattack, Optus is investigating the possible unauthorised access of current and former customers’ information.
Upon discovering this, Optus immediately shut down the attack. Optus is working with the Australian Cyber Security Centre to mitigate any risks to customers. Optus has also notified the Australian Federal Police, the Office of the Australian Information Commissioner and key regulators.
"We are devastated to discover that we have been subject to a cyberattack that has resulted in the disclosure of our customers’ personal information to someone who shouldn’t see it," said Kelly Bayer Rosmarin, Optus CEO.
"As soon as we knew, we took action to block the attack and began an immediate investigation. While not everyone maybe affected and our investigation is not yet complete, we want all of our customers to be aware of what has happened as soon as possible so that they can increase their vigilance. We are very sorry and understand customers will be concerned. Please be assured that we are working hard, and engaging with all the relevant authorities and organisations, to help safeguard our customers as much as possible."
Information which may have been exposed includes customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver's licence or passport numbers. Payment detail and account passwords have not been compromised.
Optus services, including mobile and home internet, are not affected, and messages and voice calls have not been compromised. Optus services remain safe to use and operate as per normal.
“Optus has also notified key financial institutions about this matter. While we are not aware of customers having suffered any harm, we encourage customers to have heightened awareness across their accounts, including looking out for unusual or fraudulent activity and any notifications which seem odd or suspicious.”
To help protect against fraud, customers are encouraged to look to reputable sources such as:
moneysmart.gov.au/banking/identity-theft Identity fraud - Home (oaic.gov.au)
For customers believed to have heightened risk, Optus will undertake proactive personal notifications and offer expert third-party monitoring services.
The most up to date information will be available via optus.com.au. For customers who have specific concerns, they can contact Optus via the My Optus App (which remains the safest way to interact with Optus) or by calling 133 937. Optus will not be sending links in any emails or SMS messages.
Media queries please contact Optus Corporate Affairs on media@optus.com.au
Still have questions?
Contact us via My Optus app (safest way to contact Optus)
Don't have My Optus App?
Or call us on 133 937
