Skip to main content
Back to the archive

Incident file · 2022

Optus

Telecommunications · Australia · Threat actor: Unattributed individual

Data breach
Ransom refused
US$1.0m
Ransom demanded
No
Ransom paid
2 days
Estimated downtime
US$90m
Est. revenue lost

What happened

An unauthenticated public-facing API endpoint exposed identity documents and contact details for current and former customers.

How it ended

Ransom demand withdrawn by the attacker; Optus funded passport replacement costs and a class action followed.

Data affected

9.8 million customers

Would your business survive this incident?

We stress-test detection, response and recovery so a ransom demand is never your only option.