Question
Optus: How a massive data breach has exposed Australia Last week, Australian telecommunications giant Optus revealed about 10 million customers - about 40% of the
Optus: How a massive data breach has exposed Australia
Last week, Australian telecommunications giant Optus revealed about 10 million customers - about 40% of the population - had personal data stolen in what it calls a cyber-attack.
Some experts say it may be the worst data breach in Australia's history.
But this week has seen more dramatic and messy developments - including ransom threats, tense public exchanges and scrutiny over whether this constituted a "hack" at all.
It's also ignited critical questions about how Australia handles data and privacy.
The alarm was sounded last Thursday
Optus - a subsidiary of Singapore Telecommunications Ltd - went public with the breach about 24 hours after it noticed suspicious activity on its network.
Australia's second-largest telecoms provider said current and former customers' data was stolen - including names, birthdates, home addresses, phone and email contacts, and passport and driving licence numbers. It stressed that payment details and account passwords were not compromised.
Those whose passport or licence numbers were taken - roughly 2.8 million people - are at a "quite significant" risk of identity theft and fraud, the government has since said.
Optus said it was investigating the breach and had notified police, financial institutions, and government regulators. The breach appears to have originated overseas, local media reported.
In an emotional apology, Optus chief executive Kelly Bayer Rosmarin called it a "sophisticated attack", saying the company has very strong cybersecurity.
Then a ransom threat was made
Early on Saturday, an internet user published data samples on an online forum and demanded a ransom of $1m (A$1.5m; 938,000) in cryptocurrency from Optus.
The company had a week to pay or the other stolen data would be sold off in batches, the person said.
Investigators are yet to verify the user's claims, but some experts quickly said the sample data - which contained about 100 records - appeared legitimate.
'Potentially Australia's most serious breach'
Optus has been inundated with messages from angry customers since last week.
People have been warned to watch out for signs of identity theft and for opportunistic scammers, who are said to be already cashing in on the confusion.
A class-action lawsuit could soon be filed against the company. "This is potentially the most serious privacy breach in Australian history, both in terms of the number of affected people and the nature of the information disclosed," said Ben Zocco from Slater and Gordon Lawyers.
The government has called the breach "unprecedented" and blamed Optus, saying it "effectively left the window open" for sensitive data to be stolen.
Security experts have also suggested reforming data retention laws so telecommunication companies don't have to keep sensitive information for so long. Ex-customers should also have the right to request companies delete their data, experts say.
Optus says it is required to keep identity data for six years under the current rules.
Other industry figures have argued consumers should be able to take companies that lose control of their information to court, instead of the industry regulator.
Source: https://www.bbc.com/news/world-australia-63056838
Required:
a. Identify and apply the PAPA framework for ethical issues related to the cyber attack (5 marks each category = 20 points).
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started