A 63-year-old layman was been able to access a Telstra database containing the contact details of their customers.
Once he signed in, he put in the search term “email” and it returned 66,500 results containing names, addresses, email addresses and phone numbers.
Telstra has also since identified two other customers who were able to access the database.
TPRM report: https://scoringcyber.rankiteo.com/company/telstra
"id": "tel025101122",
"linkid": "telstra",
"type": "Breach",
"date": "07/2018",
"severity": "60",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 66500,
'industry': 'Telecommunications',
'name': 'Telstra',
'type': 'Telecommunications Company'}],
'attack_vector': 'Unauthorized Access',
'data_breach': {'number_of_records_exposed': 66500,
'personally_identifiable_information': True,
'type_of_data_compromised': ['Personal Information']},
'description': 'A 63-year-old layman was able to access a Telstra database '
'containing the contact details of their customers. Once he '
"signed in, he put in the search term 'email' and it returned "
'66,500 results containing names, addresses, email addresses, '
'and phone numbers. Telstra has also since identified two '
'other customers who were able to access the database.',
'impact': {'data_compromised': ['Names',
'Addresses',
'Email Addresses',
'Phone Numbers'],
'systems_affected': ['Telstra Database']},
'threat_actor': ['Layman'],
'title': 'Telstra Database Breach',
'type': 'Data Breach'}