Amnesty International Australia disclosed a December 2022 hack four months later

Organization
Amnesty International Australia
Exploit
Hacking
Industry
Non-Profit

Amnesty International Australia published a statement on 28 April 2023 confirming that an unauthorized third party had gained temporary access to its IT environment the previous year. The charity said it identified potential anomalous activity working with the Australian Cyber Security Centre and became aware of it on 3 December 2022, at which point it activated its incident response plan and engaged external cyber security and forensic IT advisers.

Amnesty said it secured and contained its IT environment, added security measures and opened an investigation. That investigation, now complete, found that some low-risk information relating to individuals who made donations in 2019 had been accessed. The charity did not itemize which fields were involved. It said the event was limited to the Australian branch and did not affect other parts of the wider organization.

Amnesty stated that none of the accessed information met the criteria for notification under the Notifiable Data Breaches scheme in Australia's Privacy Act, and that it found no evidence any information had been or would be misused. Under that scheme a breach must be reported where it is likely to cause serious harm that remedial action cannot prevent.

The Sydney Morning Herald, which first reported the incident, noted that the statement appeared five days after the masthead put questions to the charity, and described the charity as having waited four months to disclose the attack.

Sources