Optus, 2022: 9.5 million Australians, and a case still before the court.
A threat actor accessed personal data on millions of current and former Optus customers. The Australian Information Commissioner has taken Optus to the Federal Court. What the regulator has said, and the lessons it drew for every organisation.
Last updated Published by TryTrustableNot legal advice
Optus disclosed on 22 September 2022 that it had been the subject of a cyberattack in which a threat actor accessed personal information of millions of current and former customers, including passport, driver's licence and Medicare numbers. In August 2025 the Australian Information Commissioner began civil penalty proceedings in the Federal Court, alleging Optus seriously interfered with the privacy of about 9.5 million Australians between October 2019 and September 2022. The allegations have not been decided.
What happened
| Date | What happened |
|---|---|
| 17 October 2019 to 20 September 2022 | The period in which the Commissioner alleges Optus failed to take reasonable steps to protect personal information. |
| September 2022 | Optus is the subject of a cyberattack; a threat actor accesses customers' personal information. |
| 22 September 2022 | Optus makes the breach public. |
| August 2025 | The Australian Information Commissioner files civil penalty proceedings in the Federal Court of Australia against Singtel Optus Pty Limited and Optus Systems Pty Limited. |
Root cause
The Commissioner's announcement of the proceedings alleges that Optus failed to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, as the Privacy Act 1988 requires. The investigation looked at whether Optus managed cybersecurity and information security risks in a way proportionate to the volume of personal data it held and its size.
The announcement does not set out the technical method of the attack, and the allegations are before the court, so this page does not describe one. What the OAIC does publish is a list of lessons for every organisation, which indicates where it sees the risk. It says organisations should:
- implement procedures that ensure clear ownership and responsibility over internet-facing domains;
- ensure that requests for customers' personal information are authorised to access that information;
- layer security controls to avoid a single point of failure;
- implement robust security monitoring so vulnerabilities are detected and incidents responded to in time;
- appropriately resource privacy and cyber security, including when outsourced to third parties; and
- regularly review practices and systems, including critical and sensitive infrastructure.
The first two points are specific: someone must own every internet-facing domain, and every request for personal data must be checked for authorisation, not just authentication.
Impact and regulatory outcome
- People affected: about 9.5 million current, former and prospective customers, as alleged by the Commissioner.
- Data: names, dates of birth, home addresses, phone numbers and email addresses, and for some people passport numbers, driver's licence numbers, Medicare card numbers, and other identity document information. Some of the data was published on the dark web.
- Proceedings: the Commissioner alleges one contravention for each of the 9.5 million people. The Federal Court can impose a penalty of up to A$2.22 million per contravention for the period concerned; whether a penalty is ordered, and how much, is for the court.
This page will not describe the outcome until the court has ruled. It covers the OAIC proceedings only: action by other regulators is not described because their official pages could not be read when the page was checked.
The controls that address it
| Control | SOC 2 criteria | ISO 27001:2022 Annex A |
|---|---|---|
| Inventory and ownership of every internet-facing domain and service | CC6.6, CC7.1 | A.5.9, A.8.20 |
| Authorisation checks on every request for personal data (not just authentication) | CC6.1, CC6.3 | A.5.15, A.8.3, A.8.26 |
| Security testing of internet-facing applications and APIs | CC7.1, CC8.1 | A.8.29 |
| Layered controls: no single point of failure | CC5.2, CC6.6 | A.8.20, A.8.22 |
| Security monitoring and timely incident response | CC7.2, CC7.3, CC7.4 | A.8.16, A.5.24, A.5.26 |
| Retention limits on identity document data | C1.2, P4.2 | A.8.10, A.5.34 |
SOC 2 references are the 2017 Trust Services Criteria (points of focus revised 2022); Annex A references are ISO/IEC 27001:2022. These are the usual mappings: agree yours with your auditor.
How TryTrustable checks these controls
- Domains you may have forgotten: attack surface monitoring finds your subdomains from Certificate Transparency logs and flags expiring and expired certificates, so an internet-facing host without a known owner becomes a finding to assign.
- Testing what is exposed:
trytrustable dastruns OWASP ZAP and Nuclei against your own applications and APIs (web security testing), and the SDK's static analysis runs in CI. - Exposure in the cloud: GCP checks that only intended Cloud Run services are public and that Cloud SQL is not open to the internet; AWS checks that RDS instances are not publicly accessible and that S3 Block Public Access is on.
- Monitoring: AWS CloudTrail, GuardDuty and Security Hub; GCP Data Access audit logs and Security Command Center.
- Response: the incident management module tracks each incident's timeline and regulatory deadlines.
Automated testing finds many access-control flaws but not all: whether a given caller should see a given customer's record is business logic, and needs code review and tests written for it.
These are the checks TryTrustable runs today. None of them is a claim about what would have happened in this incident: they test whether the control is in place in your environment, continuously, and record the result as audit evidence.
Sources
Every figure on this page is taken from the official documents listed here, read in October 2026. Regulatory findings quoted are the regulator's; where a company neither admitted nor denied them, or where proceedings are still open, the page says so. Not legal advice.
More case studies: all breach case studies · Research
The things people ask us
How many people were affected by the Optus breach?
The Australian Information Commissioner alleges about 9.5 million current, former and prospective customers. The data included names, dates of birth and addresses, and for some people passport, driver's licence and Medicare numbers.
What action has the OAIC taken against Optus?
In August 2025 the Australian Information Commissioner started civil penalty proceedings in the Federal Court, alleging Optus failed to take reasonable steps to protect personal information between October 2019 and September 2022. The court has not yet decided.
What is the maximum penalty in the Optus case?
Up to A$2.22 million per contravention, according to the OAIC, which alleges one contravention per affected person. Whether any penalty is ordered, and its amount, is a matter for the court.
What lessons did the OAIC draw from the Optus breach?
Clear ownership of internet-facing domains, authorisation checks on requests for customers' personal information, layered security controls, robust monitoring, adequate resourcing and regular review of systems.
Check these controls in your own environment.
We connect GitHub and one cloud account in a demo and show which of these checks pass, with the evidence an auditor would ask for.