logo

Coding error in forgotten API blamed for massive data breach

ID: c72e78a2-ac56-52a6-8a6b-a5ba06548e50

STIX ID: report--c72e78a2-ac56-52a6-8a6b-a5ba06548e50

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-06-21

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

An ACMA court filing alleges Optus exposed personal information of approximately 9.5 million customers after a 2018 coding error broke API access controls on an internet-facing 'Target' domain that was left online and not remediated when the corresponding fix was applied only to the 'Main' domain in 2021; an attacker exploited the weakness in September 2022 and ACMA is pursuing civil penalties.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.