Telstra suffers 'sizeable' data breach, mandates two-step security upgrade
The breach affected around 30,000 past and present employees, with their information being posted in the same forum that the Optus attackers used


Australia’s largest telecoms operator Telstra has been hit by a data breach and has told customers they will have to enable two-step identity protection on their accounts within a month.
The policy will come into effect on 5 October, a new website banner shows. The announcement of enhanced security measures has arrived just two weeks after rival telco Optus also suffered a similar attack.
RELATED RESOURCE
Telstra confirmed the incident involved the access of employee details, although it wasn’t a breach of a Telstra system. The company said a third-party platform was attacked instead and was used to access the telco's data.
The company confirmed the data involved in the breach belonged only to Telstra employees and included first and last names as well as email addresses. The data itself dates back to 2017 and no customers are believed to be affected.
Around 30,000 past and present employees were affected, as reported by 7News, with the information being posted on Breach Forum, the same forum on which data involved in the Optus attack was posted two weeks ago.
The hack related to information handled by a third company party for the telco’s WorkLife NAB rewards programme for staff, run by Pegasus Group Australia/MyRewards International.
The details had been leaked on the forum last week but there isn’t any personal information contained in it, only professional details, the same kind that can be found on Google or LinkedIn, a source told the local news outlet.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The rewards programme is a platform the company no longer uses and hasn’t used for a number of years, they added. They claimed the hacker is trying to sell off the data as new information, too.
“The data released is very basic in nature – limited to full names and email addresses used to sign up to the platform,” a Telstra spokesperson said. “No customer account information was included. We believe it’s been made available now in an attempt to profit from the Optus breach.”
Telstra has notified the relevant authorities as well as current employees. It added that while the data is of minimal risk to former employees, it will attempt to notify them too.
"This latest breach at Telstra is a stark reminder that just managing your own security posture isn’t good enough," said Markus Strauss, head of product management at Runecast to IT Pro.
"Far too often companies are focused on their own internal security efforts, all while forgetting the third-party providers that potentially have access to their environments or their data. The end result is what we see at Telstra, the unauthorised access to data. Companies need to wake up to the very real threat of third-party tools and partners and demand better security and attestation of their security measures as part of the onboarding of any new third-party provider."
The data breach occurred right after Optus was hit by a cyber attack last month, resulting in the leaking of sensitive customer data. The telco said that it potentially exposed data including customer names, phone numbers, email addresses, and dates of birth. Some customers may also have had their passport and driving licence numbers exposed in the attack.
New two-step security for all customers
The new two-step policy was introduced to help ensure that Telstra is talking to the customer instead of someone pretending to be them, it said.
User on an Australian forum indicated that Telstra customers first encountered the new banner informing them of the two-step authentication policy last week.
Instead of a traditional two-factor authentication (2FA) model, it will involve adding an additional security layer to accounts whereby users log in using their phone number and a personal identification number (PIN), according to users who were served the banner.
“As of October, this will become a mandatory step for our customers following the introduction of new customer identity verification rules by the Australian Communications and Media Authority (ACMA),” said Telstra.
The ACMA imposed the new rules as of 30 June 2022 but according to reports that month, Telstra had not revealed a date by which it planned to implement the necessary protections to meet the regulator's new standards.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
LaunchDarkly to "double down" on observability with Highlight acquisition
News Highlight's observability tools will be integrated into LaunchDarkly's Guarded Releases software deployment service
By Daniel Todd
-
Samsung Galaxy Tab S10 FE review
Reviews The Tab S10 FE retains the feel and core capabilities of Samsung's high-end S10 tablets, but compromises on the display and the performance
By Stuart Andrews
-
Latitude Financial's data policies questioned after more than 14 million records stolen
News Some of the data is from at least 2005 and includes customers’ name, address, and date of birth
By Zach Marzouk
-
Latitude hack now under state investigation as customers struggle to protect their accounts
News The cyber attack has affected around 330,000 customers, although the company has said this is likely to increase
By Zach Marzouk
-
IDCARE: Meet the cyber security charity shaping Australia and New Zealand's data breach response
Case Studies IDCARE is recruiting a reserve army to turbocharge the fightback against cyber crime not just in the region, but in the interests of victims all over the world
By Zach Marzouk
-
Australia commits to establishing second national cyber security agency
News The country is still aiming to be the most cyber-secure country in the world by 2030
By Zach Marzouk
-
Medibank bleeds $26 million in cyber costs following hack
News The company believes this figure could rise to $45 million for the 2023 financial year
By Zach Marzouk
-
TikTok's two new European data centres to address data protection concerns
News The company is under pressure to prove its user data isn’t being accessed by the Chinese state
By Zach Marzouk
-
Cyber attack on Australia’s TPG Telecom affects 15,000 customers
News It is the third cyber attack on a major Australian telco since October
By Zach Marzouk
-
Telstra blames IT blunder for leak of 130,000 customer records
News Australia’s biggest telco said that the error was due to a mismanagement of databases and not a cyber attack
By Zach Marzouk