EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/optus-singtel-data-breach-2022
150/430

File EL-0281HighResolvedData Breach / API Vulnerability Exploitation

Optus Singtel Data Breach

Also filed as Optus/Singtel Customer Data Leak · Australian Telecom Data Breach

The breach involved the unauthorized exfiltration of personal data belonging to approximately 9.8 million Australian customers. The vulnerability was traced to an unauthenticated API endpoint, allowing attackers to scrape large volumes of customer records. The leaked data included sensitive personal identifying information (PII) and account details.

  • #optus
  • #singtel
  • #data-breach
  • #api-flaw
  • #pii
  • #australia
  • #credential-theft
Notoriety7/10
Event
22 Sept 2022
Disclosed
22 Sept 2022
Target
Optus Singtel
Scale
9.8M people
Status
Resolved

01Summary

The incident occurred in September 2022, affecting Optus and Singtel, two major telecommunications providers in Australia. Security researchers and subsequent investigations revealed that a specific, unauthenticated API endpoint was exposed, which allowed unauthorized parties to systematically query and download vast amounts of customer data. The attackers did not require credentials or specific user permissions to access the data. The leaked dataset contained comprehensive PII, including names, phone numbers, email addresses, and account details for millions of customers. The scale of the breach was significant, prompting immediate regulatory scrutiny and forcing the companies to issue public apologies and remediation plans.

02Background

The telecommunications sector relies heavily on interconnected digital services and APIs for customer management and service delivery. Historically, API security flaws have been a major vector for data breaches globally. This incident highlighted the critical need for robust authentication and rate-limiting mechanisms on all public-facing APIs.

03Key revelations

  1. 01The sheer scale of the data leak, affecting nearly 10 million customers.
  2. 02The vulnerability was not a traditional network breach but a flaw in an exposed, unauthenticated API.
  3. 03The data contained enough PII to facilitate identity theft and targeted phishing campaigns.

04Technical analysis

The vulnerability was an API flaw, specifically an unauthenticated endpoint that lacked proper rate limiting and access controls. This allowed for automated scraping (data scraping) of records. The attackers likely used automated scripts to query the endpoint repeatedly, maximizing the data extraction volume without triggering standard security alerts.

Attack vector
Unauthenticated API Endpoint
Attack method
Data Scraping / Enumeration
Initial access
Publicly exposed, unauthenticated API endpoint
Exfiltration
Automated API calls/scraping
Malware type
Data Exfiltration

Vulnerabilities exploited

  • API Authentication Flaw
  • Lack of Rate Limiting

MITRE ATT&CK techniques

  • T1537: Tunneling
  • T1046: Network Service Scanning

05Threat actor

The perpetrators remain unidentified, suggesting the attack was either opportunistic, highly automated, or conducted by a group focused purely on data exfiltration rather than political messaging.

Aliases

  • Unauthenticated API Exploiter

MITRE groups

  • T1046

Attribution sources

  • Media Reports
  • Security Advisories

06Victims and impact

Countries affected

  • Australia

07Data exposed

Data types

  • Names
  • Phone Numbers
  • Email Addresses
  • Account IDs
  • Service Details

Notable documents

  • Leaked Customer Database Dump

08Financial damage

Damage estimate is complex, involving regulatory fines, remediation costs, and potential class-action lawsuits.

09Timeline

  1. 2022-09-22Breach discovered and publicly disclosed

10Reaction and fallout

Public reaction

The public reaction was one of widespread alarm and anger, leading to immediate calls for stronger data protection regulations in Australia. Consumer advocacy groups mobilized, demanding accountability from the major telco providers.

Political impact

The breach triggered intense political scrutiny of Australia's digital infrastructure and data governance laws. It fueled debates regarding the necessity of mandatory, industry-wide API security standards and increased pressure on the government to update privacy legislation.

11Legal

The incident led to multiple regulatory inquiries and class-action lawsuits. While specific criminal charges against the attackers were not filed, the companies faced significant reputational and financial penalties from regulatory bodies.

Civil lawsuits

  • Class-action lawsuits filed by affected consumers

12Aftermath

Policy changes

  • Increased focus on API security standards in Australian critical infrastructure
  • Calls for mandatory data breach reporting and remediation plans

Regulatory changes

  • Increased scrutiny from the Office of the Australian Information Commissioner (OAIC)

Security improvements

  • Implementation of robust API authentication (OAuth 2.0)
  • Mandatory rate limiting and throttling on all public endpoints
  • Data minimization practices for stored PII

13Significance and legacy

Significance

This breach is a prime example of how modern, interconnected digital services can create systemic vulnerabilities. It demonstrated that sophisticated data theft does not always require complex malware or network intrusion, but can result from simple, unauthenticated API design flaws, setting a new standard for API security best practices.

Legacy

The incident accelerated the industry's shift toward 'Security by Design' principles, particularly concerning API development. It forced major corporations to treat their APIs as critical security boundaries, leading to significant investment in API Gateway management and continuous security testing.

14Disclosure and media

Authentication
Technical analysis of API logs and data structure

Media partners

  • The Guardian
  • ABC News
  • Reuters

Publishing organisations

  • Security Researchers
  • Media Outlets

15Field notes

  1. 01The vulnerability was reportedly due to a combination of poor API design and insufficient internal security checks.
  2. 02The incident highlighted the difficulty of securing massive, interconnected data ecosystems in the modern telco environment.

16Resolution

The companies issued public apologies, promised comprehensive security overhauls, and implemented technical fixes, including restricting API access and enhancing authentication layers.

17Sources

Official documents

  • OAIC Investigation Reports

References

  1. [1]The Guardian reporting on the breach
  2. [2]Australian cybersecurity advisories
Fact sheetEL-0281

Dates

Event
22 Sept 2022
Started
22 Sept 2022
Ended
22 Sept 2022
Duration
1 days
Discovered
22 Sept 2022
Disclosed
22 Sept 2022
Ongoing
No

Target

Organisation
Optus/Singtel (Joint Venture)
Type
Corporation
Sector
Telecommunications
Country
Australia

Actor

Motivation
Financial gain, data sale, or reconnaissance
Arrested
No
Convicted
No

Data

People
9,800,000
Records
9,800,000
Volume
Millions of records
Sensitivity
Confidential
Published
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.