Back to the archive
Incident file · 2022
Optus
Telecommunications · Australia · Threat actor: Unattributed individual
Data breach
Ransom refused
- US$1.0m
- Ransom demanded
- No
- Ransom paid
- 2 days
- Estimated downtime
- US$90m
- Est. revenue lost
What happened
An unauthenticated public-facing API endpoint exposed identity documents and contact details for current and former customers.
How it ended
Ransom demand withdrawn by the attacker; Optus funded passport replacement costs and a class action followed.
Data affected
9.8 million customers
Would your business survive this incident?
We stress-test detection, response and recovery so a ransom demand is never your only option.