Public incident case study · Technology and communications · Australia
Optus Data Breach Case Study
Data breach 17–20 September 2022 · regulatory and class-action litigation ongoing
- 9.5M+
- former and current customer records accessed
- 2.47M
- active subscribers had identity information accessed
- 4 years
- access-control coding error existed before the breach
- ~10,200
- customer records allegedly published on the dark web
Executive summary
Incident sequence
A dormant API domain retained a latent access-control weakness
ACMA alleges that a coding error introduced in September 2018 caused an access control protecting Optus API domains to become ineffective. Optus identified and corrected the same coding error on its main domain in August 2021 but did not detect or correct it on the target domain. That domain hadn't been operationally required since 2017 but remained internet-facing and wasn't decommissioned before the breach.
The attacker exploited the API rather than compromising the network
Between 17 and 20 September 2022, the attacker bypassed the ineffective access control and sent requests to the exposed APIs, which returned customer information. ACMA alleges the attack didn't require advanced skills or proprietary knowledge and was conducted through trial and error. Optus has confirmed that the attacker exploited a previously unknown vulnerability arising from a historical coding error, while disputing aspects of the regulator’s case.
Identity data was exposed at national scale
The breach exposed names, contact information, dates of birth, addresses, and, for substantial numbers of customers, government identity information including passport, driver licence, Medicare, and other identification details. ACMA’s court filing states that approximately 10,200 customer records were subsequently published on the dark web and that Optus reimbursed more than 20,000 customers for replacement identity documents where those costs hadn't otherwise been waived.
The regulatory consequence remains unresolved
ACMA commenced Federal Court proceedings in May 2024 alleging that Optus failed to protect customer information as required by telecommunications law. The Australian Information Commissioner commenced separate civil penalty proceedings in August 2025, alleging serious interferences with the privacy of approximately 9.5 million Australians. Both regulatory proceedings remain unresolved. A separate consumer class action is also continuing in the Federal Court, with trial scheduled to commence on 7 June 2027 and a further mediation required by 12 February 2027. As of 29 September 2026, no final liability or penalty outcome has been determined in the regulatory proceedings.
Full incident chronology
Incident timeline
Incident chronology.
- Sep 2018
Latent defect
A coding error weakened API access control
ACMA alleges that a 2018 change rendered an access control ineffective across Optus API domains, creating the weakness later used in the breach.
- Aug 2021
Incomplete correction
The same defect was fixed on the main domain but remained elsewhere
Optus corrected the coding error on its principal domain without identifying the dormant target domain, which remained internet-facing despite no longer being operationally required.
Exploitation begins
The attacker began querying exposed APIs
Requests bypassed the ineffective control and returned customer records without requiring compromise of the broader Optus network.
Extraction period ends
The documented API-request activity concluded
The three-day extraction window closed after customer information had been returned at national scale.
- Sep–Oct 2022
Customer response
Government identity replacement became part of containment
Optus notified customers and reimbursed replacement-document costs where passports, driver licences, Medicare details, and other identifiers were exposed.
Telecommunications proceeding
ACMA commenced Federal Court action
The regulator alleged that Optus failed to protect customer information as required by telecommunications law; liability and penalty remained unresolved.
Privacy proceeding
The OAIC opened separate civil-penalty litigation
The privacy regulator alleged serious interferences affecting approximately 9.5 million Australians, adding another unresolved legal track to the breach.
Lykos analysis
What organisations should learn.
Why this matters to executives and boards
Optus demonstrates how security debt in an apparently dormant technology asset can create enterprise-scale consequence years later. The breach didn't require ransomware, destructive malware, or compromise of the telecommunications network. An overlooked Internet-facing API was enough to expose identity information belonging to a substantial proportion of the Australian population, creating customer-protection costs, regulatory exposure, litigation, and long-lived identity risk.
Readiness gaps visible in the public record
The regulatory record highlights the importance of maintaining a complete inventory of Internet-facing APIs and domains, decommissioning unused assets, ensuring security fixes are propagated across systems sharing the same code or controls, testing authentication and authorisation independently of normal application flows, detecting abnormal enumeration and bulk access, and treating security findings as potentially systemic rather than localised. The scale and sensitivity of the exposed information also reinforce the need to minimise retained identity data and understand how quickly compromised government identifiers can be replaced or protected after a breach.
How Lykos helps
Turn the lesson into tested capability.
Secure configuration and development
Validate how configuration and application weaknesses enter incident scenarios and response decisions.
Explore Capability ValidationAsset and vulnerability management
Establish whether critical assets, exposures, and remediation priorities are known before response begins.
Explore Capability ValidationMonitoring and detection
Use threat hunting and compromise assessment to test what existing telemetry can actually prove.
Explore Threat OperationsNot sure where to begin? Start with Capability Validation.
Public record
Sources
Public record reviewed 29 Sept 2026.
- Singtel posts net profit of S$1.17 billion for H1 FY23Singtel · 10 Nov 2022 · Company financial statement
- Financial Results for the Half Year Ended 30 September 2022Optus · 10 Nov 2022 · Company financial report
- A letter to our customersOptus · 25 Oct 2022 · Company incident response statement
- OAIC opens investigation into Optus over data breachOffice of the Australian Information Commissioner · 11 Oct 2022 · Regulator statement
- ACMA statement on 2022 Optus data breachAustralian Communications and Media Authority · 22 May 2024 · Regulator enforcement statement
- Australian Communications and Media Authority v Optus Mobile Pty Limited — Redacted Concise Statement, VID429/2024Australian Communications and Media Authority / Federal Court of Australia · 19 Jun 2024 · Regulator court filing
- Optus cyber attack could have been prevented four years prior, says telecoms watchdogABC News · 20 Jun 2024 · Reporting with company response
- Australian Information Commissioner takes civil penalty action against OptusOffice of the Australian Information Commissioner · 8 Aug 2025 · Regulator enforcement statement
- Handling privacy complaints – a new approach for a new eraOffice of the Australian Information Commissioner · 2 Mar 2026 · Regulator status update
- Optus Data Breach Class ActionSlater and Gordon · 29 Sept 2026 · Court record