Optus, and the Data You Didnt Know You Handed Over

Optus, and the Data You Didnt Know You Handed Over

Tech News data breach optus privacy security telecom

I've been half-following the Optus breach story out of Australia all week, and it took a turn a couple days ago that I havent been able to stop thinking about. Quick recap for anyone who missed it: Optus, one of the big three telcos over there, disclosed a breach that exposed data on something like 9.8 million customers. Not just phone numbers and emails either — names, birthdates, home addresses, and for a chunk of people, actual ID document numbers. Drivers license numbers. Passport numbers. The stuff you'd normally only hand over to a bank or a government office, sitting in a telco's database because at some point regulations required them to verify who you are before selling you a SIM card.

Then a few days ago someone popped up on a hacking forum claiming to be behind it, posted a sample of records to prove they had the goods, and demanded a payout (reports put it somewhere around a million dollars) or they'd start leaking more data every day until it was paid. Pretty standard extortion playbook at that point, ugly but familiar.

What wasnt familiar is what happened next. The account deleted the post, said sorry, claimed they'd destroyed the only copy of the file, and basically vanished. No follow-through on the threats, no data dump, just a retraction and an apology dressed up as remorse.

I dont buy the apology, for what its worth. Maybe it's real. Maybe the heat got too intense once the Australian Federal Police got involved and it stopped feeling like free money and started feeling like actual prison time. But "I deleted it, promise" is exactly what you'd say whether or not it's true, and there's no way to verify it either way. The data could be sitting on a drive somewhere getting quietly resold in six months and none of us would know until it started showing up in some other breach's credential stuffing list.

Anyway, the apology isnt really the interesting part to me. The interesting part is that this breach ever should've been possible in the first place, and that's not really an Optus-specific problem, it's a "why does a phone company have my passport number at all" problem. I get that KYC rules exist for good reasons, fraud prevention and whatnot, but once that data is collected it just sits there forever, in some database, attached to a company whose actual core competency is cell towers and billing software, not information security. Every org that touches your ID becomes a target whether it wants to be one or not. Multiply that by every telco, bank, insurer, and airline you've ever given a scan of your license to, and it's honestly kind of amazing this doesnt happen every single week.

I had my own mini version of this anxiety a few months back when I got one of those "your information may have been involved in a data incident" letters from an old insurance provider I hadnt used in like four years. Nothing came of it as far as I can tell, but it's a genuinely lousy feeling, sitting there wondering if some rando now has enough to open a credit card in your name because you needed dental coverage in 2019.

If you're an Optus customer, or honestly even if you're not, this is as good a nudge as any to go set up a credit freeze if your country has that option, and to actually read what data a company is asking for before you hand it over. I know "just be more careful with your data" is thin advice when the leak happens on the company's end and not yours, but it's still the only lever most of us actually get to pull. The bigger fix, mandatory data minimization, shorter retention windows, real penalties for hoarding more than you need, is not something any individual user is going to solve by tweaking their own settings. That one's on regulators, and I'm not holding my breath.