Tangerine Telecom breach exposed data on 232,000 Australian customers
- Organization
- Tangerine Telecom
- Exploit
- Credential Compromise
- Industry
- Telecommunications
Australian internet and mobile provider Tangerine Telecom told customers in February 2024 that a legacy customer database had been accessed by an unauthorised party, exposing personal details belonging to about 232,000 current and former account holders.
The company said the unauthorised access occurred on Sunday, February 18, 2024 and was reported to management on Tuesday, February 20. It traced the access to the login credentials of a single person engaged by Tangerine on a contract basis. Affected customers were emailed on Wednesday, February 21.
The exposed records related to accounts held between June 2019 and July 2023 and contained full names, dates of birth, mobile numbers, email addresses, postal addresses and Tangerine account numbers. Tangerine said no credit or debit card numbers, driver's licence numbers, identity document details, banking details or passwords were disclosed, noting that it does not store identity documents or payment card data.
In response the company revoked the compromised credentials, changed usernames and passwords across its team, closed access to the affected legacy database and engaged an external cybersecurity specialist to investigate. It notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner, and said multi-factor authentication on customer accounts remained active and was unaffected by the incident.