May 19, 2019

May 17, 2019

Subscribe to Latest Legal News and Analysis

Australian Government Contractor Data Breach

The personal details of almost 50,000 Australians have been published online by a third party government contractor, who is yet to be identified. And I guess you would feel a little shy about owning up to this one!

The subjects of the breach are employees of government agencies, banks and the utility UGL.

The breach occurred due to a misconfigured Amazon S3 bucket, which is a type of internet cloud storage.

The misconfiguration was discovered by a Polish security researcher, who found full names, passwords, IDs, phone numbers, email addresses, credit card numbers and details on staff salaries and expenses.

The leak is one of the largest data breaches in Australia. Insurer AMP has been the most impacted, with 25,000 staff records leaked, while UGL had 17,000 records exposed. Other organisations affected include Rabobank with 1,500 leaked records, the Department of Finance with 3,000, the Australian Electoral Commission with 1470, and the National Disability Insurance Agency with 300.

The information included full names, emails, expenses and payment details, and was publicly available online until October, when the Australian Cyber Security Centre (ACSC) was alerted to the breach. The ACSC worked with the contractor to secure the information and remove the vulnerability.

This is not the first government contractor to experience a cybersecurity incident – earlier this month we blogged that an Australian defence contractor was hacked, exposing 30 gigabytes of data.

Read more here and here.

Olivia Coburn also contributed to this article.

Copyright 2019 K & L Gates


About this Author

Cameron Abbott, Technology, Attorney, Australia, corporate, KL Gates Law Firm

Mr. Abbott is a corporate lawyer who focuses on technology, telecommunications and broadcasting transactions. He assists corporations and vendors in managing their technology requirements and contracts, particularly large outsourcing and technology procurements issues including licensing terms for SAP and Oracle and major system integration transactions.

Mr. Abbott partners with his clients to ensure market leading solutions are implemented in to their businesses. He concentrates on managing and negotiating complex technology solutions, which...

Allison Wallace, KL Gates, Commercial Technology and Sourcing lawyer, Australia

Allison Wallace is a lawyer in the Melbourne, Australia office of K&L Gates, working in the Commercial Technology and Sourcing Practice.