Nine exposed 16,000 Australian newspaper subscribers through a supplier lapse
- Organization
- Nine Entertainment
- Exploit
- Third-Party Data Breach
- Industry
- Media
Crikey reported on 27 March 2025 that subscriber records belonging to Nine's newspaper mastheads had been left readable on the public internet. The exposure covered readers of The Sydney Morning Herald, The Age and The Australian Financial Review, with roughly 16,000 subscribers affected.
The records sat in an Amazon S3 cloud storage repository operated by a third-party supplier that Nine did not name. An independent security researcher using the handle Kaspar found the open bucket on 19 March 2025 while scanning for misconfigured storage, according to Mediaweek, which reported that the data was not locked down until Crikey put its findings to Nine on 26 March.
Accounts of exactly what was exposed varied. Names, postal addresses and email addresses were consistently described as accessible, and Nine said payment details and passwords were not involved. Crikey's report also referred to payment information among the records.
Nine attributed the lapse to an unauthorised change made by an external service provider and said the information had not been protected to the level of its internal data protocols. As of the end of March 2025 the company had not said how long the repository had been open, whether anyone other than the researcher had retrieved the data, or how many people it intended to notify.