Most Recent
Optus had four years to fix coding error behind massive cyberattack, says ACMA
The Australian Communications and Media Authority says a coding error on a dormant website that went undetected for four years was behind a massive data breach that exposed the information of close to 10 million Optus customers, with the regulator saying the hack was “not highly sophisticated”. 
In high-stakes breach case, OAIC says Medibank failed to implement ‘basic’ security controls
Medibank failed to put in place baseline security measures, including multi-factor authentication, to safeguard sensitive information from a hacker in 2022, who stole an IT contractor's credentials and logged in to the health insurer's private network three months before the company learned its data was compromised, the OAIC says.
Judge mulls joint trial of ACMA case, class action against Optus
A judge overseeing several cases against Optus over a September 2022 data breach has raised the possibility of hearing a class action against the telco alongside new proceedings brought by the Australian Communications and Media Authority.
OAIC takes Medibank to court over 2022 data breach
After an 18-month investigation, the Office of the Australian Information Commissioner has lodged civil penalty proceedings against Medibank over its October 2022 data breach, accusing the health insurer of breaching the Privacy Act.
Latitude defeats customer’s $1M lawsuit over data breach
A judge has thrown out a self-represented customer’s lawsuit against non-bank lender Latitude Financial after he defaulted on court orders and refused to join tech giants DXC Technology and Crowdstrike to his case over a cyberattack that compromised 14 million customer records. 
Medibank can’t ‘have it both ways’ with Deloitte report, class action says
A class action has argued Medibank cannot claim legal professional privilege over three Deloitte reports after disclosing them to reassure the market and customers after a massive 2022 data breach.
X could have done more to shield users, including kids, from stabbing videos, court told
The e-Safety Commissioner has expanded its case seeking to have X Corp remove posts that depict a stabbing of a bishop at a Sydney church, arguing X could have done more to prevent Australian users, including children and VPN users, from viewing the videos.
Medical cannabis distributor wins injunction after suspected hack
Medicinal cannabis company Vitura Health has won its bid for orders restricting the access of a software partner to its IT systems after an alleged hack.
Optus loses second bid to shield Deloitte report from class action
Optus has lost its appeal of a decision that found the telco could not claim legal professional privilege over a Deloitte report into a major data breach, with an appeals court highlighting the lack of evidence from former CEO Kelly Bayer Rosmarin.
Medibank board engaged KWM, Deloitte for review after class action rumours, court told
The chair of the Medibank board has given evidence that he engaged King & Wood Mallesons to commission expert reviews in the wake of a cyberattack, including three reports by Deloitte, after hearing rumours of class action investigations in October 2022.