Meriton breach exposes staff financial records and guest incident reports

Organization
Meriton
Exploit
Hacking
Industry
Hospitality and Property

Meriton, one of Australia's largest apartment developers and the operator of the Meriton Suites hotel chain, disclosed in late March 2023 that attackers had accessed its systems in mid January and that its forensic analysis team had identified 35.6 gigabytes of data as potentially impacted. Meriton said it first became aware of the incident on 14 January. The company notified 1,889 guests and current and former staff.

Guest exposure was comparatively narrow. Meriton said its hotel guest database for past, present and future guests was not compromised and that no credit card details were taken. What the attackers reached instead were internal incident reports, which contained guest names, contact details and health information such as records of injuries sustained at Meriton properties or ambulance callouts.

Employees fared worse. Reporting by Information Age and iTnews indicated that staff records caught in the breach included bank account information, tax file numbers, health information and employment records covering salary details, disciplinary histories and performance appraisals.

Meriton said it had engaged cybersecurity and forensic professionals, introduced enhanced security measures and put extensive network monitoring in place. It stated it had no evidence the incident was directed at any particular individual and no evidence that affected people's information had been misused or released publicly. The company notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. The OAIC closed its file on the matter on 20 March 2023, before the breach became public.

Sources