Pareto Phone breach leaked Australian charity donor data to the dark web
- Organization
- Pareto Phone
- Exploit
- Ransomware
- Industry
- Telemarketing
Pareto Phone, a Brisbane telemarketing company that ran fundraising calls for Australian charities, suffered a data breach in April 2023 that became public in August, when donor records began appearing on the dark web. Threat intelligence platform Falcon Feeds attributed the leak to the LockBit ransomware group, and Cyber Daily reported that LockBit posted about 150 gigabytes of Pareto Phone files on its leak site.
The company told some of its charity clients on August 14, 2023 that data had been taken from its systems. More than 70 charities had used Pareto Phone, and organisations that confirmed exposure included Cancer Council, Amnesty International Australia, Médecins Sans Frontières, the Australian Conservation Foundation, WWF-Australia and the Children's Cancer Institute. The Australian Conservation Foundation alone said about 13,500 of its supporters were affected.
Exposed donor details included names, addresses, email addresses, mobile numbers and dates of birth. Charities said financial information was not involved. Several complained that Pareto Phone had retained supporter records long after they should have been destroyed, with some of the exposed data dating from 2012 to 2015 or earlier.
Cancer Council said in a statement dated August 22, 2023 that it had stopped using Pareto Phone, that its own systems were not affected in any way, and that it was still waiting on the telemarketer for clarity on how many donors and what categories of data were involved. According to iTnews, Pareto Phone initially told charities there was no evidence donor data had been downloaded and later revised that position. Multiple charities suspended or ended their relationships with the firm.