In one of the more remarkable data breaches of late, details of more than a million visitors to clubs in New South Wales have been posted on the web, including those of senior state government officials.
The incident took place after what appears to be a payment dispute between an IT provider and developers in the Philippines.
When the developers didn’t get paid, they are said to have set up a searchable web site, on which anyone could look up names of the people involved in the data breach.
The devs have now stood up “Have I Been Outaboxed” that allows you to search by name and see the club the person signed into along with partially redacted DoB and home address
— Troy Hunt (@troyhunt) May 1, 2024
In NSW, clubs are required to scan patrons’ faces and match them to their drivers’ licences.
The representational body for clubs in the state, ClubsNSW with 1200 members, has confirmed the breach, saying:
“ClubsNSW has been made aware of a cybersecurity incident involving a third-party IT provider commonly used by hospitality venues, including 17 licensed clubs. While limited information is currently known, we understand that some personal information of patrons of the clubs that use this IT provider may have been compromised.”
The NSW Premier Chris Minns, Deputy Premier Prue Car and Police Minister Yasmin Catley, had their details breached in the incident.
NSW Police acted fast to set up a task force to investigate the data breach, and have already arrested and charged a 46-year-old man for blackmail, and searched his premises. The bad news is that once the data has been posted on the internet, it’ll likely remain there and could be abused for identity theft and harassment.
Drivers’ licences exposed in the data breach will need to be replaced.
I asked Troy Hunt who runs the HaveIBeenpwned website that helps people discover if their credentials have been compromised, if the Outabox data should’ve been allowed to leave Australia:
"With the caveat that this is really a question for a data sovereignty lawyer: it depends on various factors, for example health data has some of the strictest data sovereignty and residency requirements in Australia," Hunt said.
"My Health Records and all associated data, including back-ups, must never be processed, held, taken, or handled outside of Australia," he added.
"As far as I know, there are no controls on the classes of data Outabox collected as far as sovereignty is concerned, nor are there controls on where the people managing it are located. As for whether there should be or not, were the same thing to happen if the developers were located in Australia it really wouldn’t change the outcomes we’re dealing with today," Hunt said.
Meanwhile, Australian authorities are warning people that dealing with information in data breaches is illegal, and are asking people to refrain from doing so.
We welcome your comments below. If you are not already registered, please register to comment
Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.