Public incident case study · Financial services · Australia / New Zealand

Latitude Financial Case Study

2023 cyber incident · Remediation and investigations ongoing

A$68.3M2023 cyber-related costs and provisionsPre-tax, reported in Latitude’s 2023 Annual Report
7.9M
drivers' licence numbers stolen
6.1M
additional partial records
5–6 weeks
platform restoration
A$49.6M
provision at 31 Dec 2023
Executive summary

Incident sequence

  1. Third-party credential compromised

    Latitude reported that the adversary obtained privileged credentials through a third-party vendor and used them to access Latitude’s systems.

  2. Platforms were isolated

    Latitude took technology platforms offline, reset passwords, and engaged external cybersecurity specialists to contain the incident.

  3. Large-scale identity data theft

    Latitude reported the theft of about 7.9M drivers' licence numbers and a further 6.1M partial records, plus other application and financial data.

  4. Business and remediation impact

    Latitude reported weeks of operational disruption and A$68.3M in 2023 pre-tax cyber-related costs and provisions. Remediation continued in 2025, and the OAIC's current register records its joint investigation with New Zealand's privacy regulator as ongoing.

Full incident chronology

Incident timeline

Incident chronology.

  1. Date not disclosed

    Initial access

    A third-party privileged credential was compromised

    Latitude reported that an attacker obtained privileged credentials through a vendor and used them to access Latitude systems; the exact access date remains unpublished.

  2. Containment

    Technology platforms were taken offline

    Latitude isolated affected platforms, reset passwords, engaged external specialists, and accepted operational disruption while containing the incident.

  3. Mar–May 2023

    Breach assessment

    The confirmed data scope expanded materially

    Company updates established theft of millions of driver-licence numbers, partial application records, and other identity and financial information.

  4. Regulatory response

    Australian and New Zealand regulators opened a joint investigation

    The OAIC and New Zealand privacy regulator commenced a coordinated investigation into the handling and protection of affected personal information.

  5. FY2023

    Business impact

    Operational disruption became a material cost

    Latitude reported weeks of disruption and A$68.3 million in pre-tax cyber-related costs and provisions for the financial year.

  6. 2025–2026

    Long-tail remediation

    Remediation and regulator investigations remained active

    Latitude continued remediation work while the OAIC’s current register retained the joint investigation as an ongoing matter.

Lykos analysis

What organisations should learn.

Why this matters to executives and boards

The operational impact extended beyond data theft: customer acquisition, pricing actions, and collections were disrupted while systems were offline, turning an access-control incident into a business-resilience event.

Readiness gaps visible in the public record

The record highlights third-party credential risk, privileged access, retained historical data, and recovery planning. Australian and New Zealand privacy investigations and related remediation remained relevant after the immediate recovery.

How Lykos helps

Turn the lesson into tested capability.

Privacy and data lifecycle

Prepare evidence-led scoping, notification, and executive decisions for sensitive-data exposure.

Explore Digital Forensics

Not sure where to begin? Start with Capability Validation.

Public record

Sources

Public record reviewed 21 Aug 2026.

  1. Cybercrime Update — May 2023Latitude Group Holdings Limited · 26 May 2023 · Company update
  2. Annual Report 2023Latitude Group Holdings Limited · 22 Mar 2024 · Company report
  3. Annual Report 2025Latitude Group Holdings Limited · 20 Feb 2026 · Company report
  4. Joint Australia–New Zealand investigation into Latitude groupOffice of the Australian Information Commissioner · 10 May 2023 · Regulator
  5. Commissioner-initiated investigationsOffice of the Australian Information Commissioner · Undated · Regulator status update