Public incident case study · Financial services · Australia / New Zealand
Latitude Financial Case Study
2023 cyber incident · Remediation and investigations ongoing
- 7.9M
- drivers' licence numbers stolen
- 6.1M
- additional partial records
- 5–6 weeks
- platform restoration
- A$49.6M
- provision at 31 Dec 2023
Executive summary
Incident sequence
Third-party credential compromised
Latitude reported that the adversary obtained privileged credentials through a third-party vendor and used them to access Latitude’s systems.
Platforms were isolated
Latitude took technology platforms offline, reset passwords, and engaged external cybersecurity specialists to contain the incident.
Large-scale identity data theft
Latitude reported the theft of about 7.9M drivers' licence numbers and a further 6.1M partial records, plus other application and financial data.
Business and remediation impact
Latitude reported weeks of operational disruption and A$68.3M in 2023 pre-tax cyber-related costs and provisions. Remediation continued in 2025, and the OAIC's current register records its joint investigation with New Zealand's privacy regulator as ongoing.
Full incident chronology
Incident timeline
Incident chronology.
- Date not disclosed
Initial access
A third-party privileged credential was compromised
Latitude reported that an attacker obtained privileged credentials through a vendor and used them to access Latitude systems; the exact access date remains unpublished.
Containment
Technology platforms were taken offline
Latitude isolated affected platforms, reset passwords, engaged external specialists, and accepted operational disruption while containing the incident.
- Mar–May 2023
Breach assessment
The confirmed data scope expanded materially
Company updates established theft of millions of driver-licence numbers, partial application records, and other identity and financial information.
Regulatory response
Australian and New Zealand regulators opened a joint investigation
The OAIC and New Zealand privacy regulator commenced a coordinated investigation into the handling and protection of affected personal information.
- FY2023
Business impact
Operational disruption became a material cost
Latitude reported weeks of disruption and A$68.3 million in pre-tax cyber-related costs and provisions for the financial year.
- 2025–2026
Long-tail remediation
Remediation and regulator investigations remained active
Latitude continued remediation work while the OAIC’s current register retained the joint investigation as an ongoing matter.
Lykos analysis
What organisations should learn.
Why this matters to executives and boards
The operational impact extended beyond data theft: customer acquisition, pricing actions, and collections were disrupted while systems were offline, turning an access-control incident into a business-resilience event.
Readiness gaps visible in the public record
The record highlights third-party credential risk, privileged access, retained historical data, and recovery planning. Australian and New Zealand privacy investigations and related remediation remained relevant after the immediate recovery.
How Lykos helps
Turn the lesson into tested capability.
Third-party risk
Exercise provider failure, alternate workflows, notification, and safe reconnection decisions.
Explore Tabletop ExercisesIdentity and access
Validate privileged access, MFA, and account-control decisions across response-critical systems.
Explore Capability ValidationPrivacy and data lifecycle
Prepare evidence-led scoping, notification, and executive decisions for sensitive-data exposure.
Explore Digital ForensicsNot sure where to begin? Start with Capability Validation.
Public record
Sources
Public record reviewed 21 Aug 2026.
- Cybercrime Update — May 2023Latitude Group Holdings Limited · 26 May 2023 · Company update
- Annual Report 2023Latitude Group Holdings Limited · 22 Mar 2024 · Company report
- Annual Report 2025Latitude Group Holdings Limited · 20 Feb 2026 · Company report
- Joint Australia–New Zealand investigation into Latitude groupOffice of the Australian Information Commissioner · 10 May 2023 · Regulator
- Commissioner-initiated investigationsOffice of the Australian Information Commissioner · Undated · Regulator status update