5 Lessons from the Optus Data Breach for Telecom and Third-Party Risk
ID: d82424c2-1f3d-5550-b8da-7fb3180e7da8
STIX ID: report--d82424c2-1f3d-5550-b8da-7fb3180e7da8
Feed Name: SecurityScorecard Blog
In September 2022 Optus experienced a major data breach that exposed PII for over 9.5 million customers (including passports, driver licenses, dates of birth, addresses, and contact details) due to a misconfigured, unauthenticated API and a coding error that persisted for years; the attacker used basic tactics such as IP rotation and behavior mimicry to avoid detection, and the report outlines root causes and five CISO takeaways for improved API inventory, secure SDLC, data retention, anomaly detection, and asset discovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
