Public incident case study · Technology and communications · Australia

Optus Data Breach Case Study

Data breach 17–20 September 2022 · regulatory and class-action litigation ongoing

A$140Mcustomer response and recovery provisionSingtel recorded an A$140 million exceptional provision following the breach for customer protection and response measures, including identity document replacement, third-party credit monitoring, and an independent external review.
9.5M+
former and current customer records accessed
2.47M
active subscribers had identity information accessed
4 years
access-control coding error existed before the breach
~10,200
customer records allegedly published on the dark web
Executive summary

Incident sequence

  1. A dormant API domain retained a latent access-control weakness

    ACMA alleges that a coding error introduced in September 2018 caused an access control protecting Optus API domains to become ineffective. Optus identified and corrected the same coding error on its main domain in August 2021 but did not detect or correct it on the target domain. That domain hadn't been operationally required since 2017 but remained internet-facing and wasn't decommissioned before the breach.

  2. The attacker exploited the API rather than compromising the network

    Between 17 and 20 September 2022, the attacker bypassed the ineffective access control and sent requests to the exposed APIs, which returned customer information. ACMA alleges the attack didn't require advanced skills or proprietary knowledge and was conducted through trial and error. Optus has confirmed that the attacker exploited a previously unknown vulnerability arising from a historical coding error, while disputing aspects of the regulator’s case.

  3. Identity data was exposed at national scale

    The breach exposed names, contact information, dates of birth, addresses, and, for substantial numbers of customers, government identity information including passport, driver licence, Medicare, and other identification details. ACMA’s court filing states that approximately 10,200 customer records were subsequently published on the dark web and that Optus reimbursed more than 20,000 customers for replacement identity documents where those costs hadn't otherwise been waived.

  4. The regulatory consequence remains unresolved

    ACMA commenced Federal Court proceedings in May 2024 alleging that Optus failed to protect customer information as required by telecommunications law. The Australian Information Commissioner commenced separate civil penalty proceedings in August 2025, alleging serious interferences with the privacy of approximately 9.5 million Australians. Both regulatory proceedings remain unresolved. A separate consumer class action is also continuing in the Federal Court, with trial scheduled to commence on 7 June 2027 and a further mediation required by 12 February 2027. As of 29 September 2026, no final liability or penalty outcome has been determined in the regulatory proceedings.

Full incident chronology

Incident timeline

Incident chronology.

  1. Sep 2018

    Latent defect

    A coding error weakened API access control

    ACMA alleges that a 2018 change rendered an access control ineffective across Optus API domains, creating the weakness later used in the breach.

  2. Aug 2021

    Incomplete correction

    The same defect was fixed on the main domain but remained elsewhere

    Optus corrected the coding error on its principal domain without identifying the dormant target domain, which remained internet-facing despite no longer being operationally required.

  3. Exploitation begins

    The attacker began querying exposed APIs

    Requests bypassed the ineffective control and returned customer records without requiring compromise of the broader Optus network.

  4. Extraction period ends

    The documented API-request activity concluded

    The three-day extraction window closed after customer information had been returned at national scale.

  5. Sep–Oct 2022

    Customer response

    Government identity replacement became part of containment

    Optus notified customers and reimbursed replacement-document costs where passports, driver licences, Medicare details, and other identifiers were exposed.

  6. Telecommunications proceeding

    ACMA commenced Federal Court action

    The regulator alleged that Optus failed to protect customer information as required by telecommunications law; liability and penalty remained unresolved.

  7. Privacy proceeding

    The OAIC opened separate civil-penalty litigation

    The privacy regulator alleged serious interferences affecting approximately 9.5 million Australians, adding another unresolved legal track to the breach.

Lykos analysis

What organisations should learn.

Why this matters to executives and boards

Optus demonstrates how security debt in an apparently dormant technology asset can create enterprise-scale consequence years later. The breach didn't require ransomware, destructive malware, or compromise of the telecommunications network. An overlooked Internet-facing API was enough to expose identity information belonging to a substantial proportion of the Australian population, creating customer-protection costs, regulatory exposure, litigation, and long-lived identity risk.

Readiness gaps visible in the public record

The regulatory record highlights the importance of maintaining a complete inventory of Internet-facing APIs and domains, decommissioning unused assets, ensuring security fixes are propagated across systems sharing the same code or controls, testing authentication and authorisation independently of normal application flows, detecting abnormal enumeration and bulk access, and treating security findings as potentially systemic rather than localised. The scale and sensitivity of the exposed information also reinforce the need to minimise retained identity data and understand how quickly compromised government identifiers can be replaced or protected after a breach.

How Lykos helps

Turn the lesson into tested capability.

Secure configuration and development

Validate how configuration and application weaknesses enter incident scenarios and response decisions.

Explore Capability Validation

Asset and vulnerability management

Establish whether critical assets, exposures, and remediation priorities are known before response begins.

Explore Capability Validation

Monitoring and detection

Use threat hunting and compromise assessment to test what existing telemetry can actually prove.

Explore Threat Operations

Not sure where to begin? Start with Capability Validation.

Public record

Sources

Public record reviewed 29 Sept 2026.

  1. Singtel posts net profit of S$1.17 billion for H1 FY23Singtel · 10 Nov 2022 · Company financial statement
  2. Financial Results for the Half Year Ended 30 September 2022Optus · 10 Nov 2022 · Company financial report
  3. A letter to our customersOptus · 25 Oct 2022 · Company incident response statement
  4. OAIC opens investigation into Optus over data breachOffice of the Australian Information Commissioner · 11 Oct 2022 · Regulator statement
  5. ACMA statement on 2022 Optus data breachAustralian Communications and Media Authority · 22 May 2024 · Regulator enforcement statement
  6. Australian Communications and Media Authority v Optus Mobile Pty Limited — Redacted Concise Statement, VID429/2024Australian Communications and Media Authority / Federal Court of Australia · 19 Jun 2024 · Regulator court filing
  7. Optus cyber attack could have been prevented four years prior, says telecoms watchdogABC News · 20 Jun 2024 · Reporting with company response
  8. Australian Information Commissioner takes civil penalty action against OptusOffice of the Australian Information Commissioner · 8 Aug 2025 · Regulator enforcement statement
  9. Handling privacy complaints – a new approach for a new eraOffice of the Australian Information Commissioner · 2 Mar 2026 · Regulator status update
  10. Optus Data Breach Class ActionSlater and Gordon · 29 Sept 2026 · Court record