Breadcrumb

  • Home
  • AUS: Little-Big data breach at Latitude

Search form

Main navigation

  • Home

HOME | ALL NEWS

AUS: Little-Big data breach at Latitude

Tuesday, 28 March, 2023 - 01:33

On 16th March, Australian financial services group Latitude Financial announced to the Australian Stock Exchange, ASX, "unusual activity on its systems over the last few days that appears to be a sophisticated and malicious cyber-attack. "

That was only the beginning of the story.

Latitude said that, as has happened with several attacks recently, it was not an attack directly on its own systems but rather was "believed to have originated from a major vendor used by Latitude."

" The attacker was able to obtain Latitude employee login credentials" before Latitude became aware of the intrusion. Once in possession of those credentials, the attacker used those "to obtain information that was held by two other service providers."

Latitude, essentially, pulled the plug on several of its systems while it took action to address the problems.

"As of today, Latitude understands that approximately 103,000 identification documents, more than 97% of which are copies of drivers’ licences, were stolen from the first service provider. Approximately 225,000 customers' records were also stolen from the second service provider"

On 20th March, in a media release, Latitude said

"So far, Latitude can confirm that:

As previously disclosed, approximately 330,000 customers and applicants have had their personal information stolen
Approximately 96% of the personal information stolen was copies of drivers’ licences or driver licence numbers
Less than 4% was copies of passports or passport numbers
Less than 1% was Medicare numbers"

But that wasn't the end of the problem. A forensic review with external advisers including "the Australian Cyber Security Centre, the Australian Federal Police and other relevant Government agencies" was continuing and "We have taken the prudent action of isolating some of our technology platforms which means that we are currently not onboarding new customers. Because the attack remains active, we have taken our platforms offline and are unable to service our customers and merchant partners. "

Latitude said it had already started contacting customers "impacted" (it means "affected") by the incident.

On 20th March, a further media release said "While to the best of our knowledge no compromised data has left Latitude’s systems since Thursday 16 March 2023, regrettably our review has uncovered further evidence of large-scale information theft affecting customers (past and present) and applicants across Australia and New Zealand."

Yesterday, the scale of the problem became more clear with the announcement that "approximately 7.9 million Australian and New Zealand driver licence numbers were stolen, of which approximately 3.2 million, or 40%, were provided to us in the last 10 years. In addition, approximately 53,000 passport numbers were stolen. We have also identified less than 100 customers who had a monthly financial statement stolen."

And there's more: "A further approximately 6.1 million records dating back to at least 2005 were also stolen, of which approximately 5.7 million, or 94%, were provided before 2013. These records include some but not all of the following personal information: name, address, telephone, date of birth."

A little over an hour ago, the Australian Federal Police posted a notice saying that affected Latitude customers would be protected under Operation Guardian. The AFT said "Operation Guardian, a joint initiative with state and territory police run through the AFP-led Joint Policing Cybercrime Coordination Centre (JPC3), was set up in September 2022 to protect more than 10,000 customers whose personal information was unlawfully released online after the Optus data breach. It was also extended to Medibank Private customers. There is no evidence to date that the personal details of Latitude Services customers are available, or being sold on online or dark web forums."

The AFP is not messing about "It is an offence to buy stolen personal information online, which could include a penalty of up to 10 years’ imprisonment. It is also an offence to blackmail or menace customers. The AFP will take immediate action - through disruption capability or charges - if individuals or groups are selling stolen personal information online. A Sydney man was convicted in Sydney Downing Centre District Court on 7 February, 2023, for trying to blackmail Optus customers. He was charged by the AFP last year under Operation Guardian."

It appears, from all of the above, that the information that was stolen was not, in fact, on Latitude's own servers but was within its control. It also appears that data security for the actual locations was outsourced to the service providers and that the attack on Latitude's data did was using an attack vector that is becoming increasingly popular.

As yet, those third parties have not been identified.

Latitude acknowledges that it has primary responsibility to its customers and has set up a range of support systems.

Latitude's has just under 1,040 thousand shares issued and its trading volumes average just under 140,000 per day, according to ASX. According to MarketIndex.co.au, the volume yesterday was much lower and the price dropped by three cents to AUD1.18, a fall of 2.5% approx. Latitude has announced that it is insured against the consequences of cyber attacks.

     

Footer menu

  • Weekly Digest (opens in new tab)
  • Images attribution (opens in new tab)
  • Corporate, privacy, intellectual property and access (opens in new tab)
  • Advertising and Recommendations (opens in new tab)
  • Promote your business (opens in new tab)
  • Enquiries (opens in new tab)


 

BOT AND SCRAPER ACCESS DENIED

 


 

Built with Drupal     |     Hosted by Siteground     |     Template by Alaa Haddad     

Design by Vortex Centrum Limited    |     Some services provided by Google Workspace    

Posters and other merch by ProjectLXX   |   Privacy and security services by Surfshark and Firetrust. 


Nothing in this website is intended to be or shall be taken as legal advice. 

You should always seek advice from a practitioner experienced in this area. 


Everything on this website is copyright Nigel Morris-Cotterill and/or Vortex Centrum Limited for itself or one of its business units. No downloading, printing or other means of replicating or reusing is permitted. In particular, all bot access is denied and all scraping of content will result in the legal action set forth in the terms and conditions in this site. For legal, cookies and privacy see vortexcentrum.com.

Copyright 1999- © 2026 Vortex Centrum Limited - All rights reserved. Bot access denied.