TPG Telecom Investigates Cybersecurity Incident Affecting 300,000 iiNet Customers
TPG Telecom has announced an investigation into a cybersecurity incident affecting its iiNet system, where an unauthorized third party gained access to its order management system. The breach resulted in the exposure of sensitive customer data, including 280,000 active email addresses and 20,000 active landline phone numbers. Additionally, approximately 10,000 iiNet user names, street addresses, phone numbers, and some passwords were compromised. The incident is believed to have been facilitated by stolen employee credentials, and TPG Telecom has removed the intruders' access and engaged external IT and cybersecurity experts to investigate and bolster security measures.
Key Takeaways:
- The cybersecurity incident affected 300,000 iiNet customers, including 280,000 active email addresses and 20,000 active landline phone numbers.
- Approximately 10,000 iiNet user names, street addresses, phone numbers, and some passwords were compromised.
- The breach was facilitated by stolen employee credentials, and TPG Telecom has removed the intruders' access.
- The company is working to assess the full impact of the breach, notify affected customers, and implement additional safeguards to prevent future incidents.
- This incident underscores the ongoing cybersecurity challenges facing ISPs in protecting customer data against increasingly sophisticated attacks.
- TPG Telecom previously experienced a cyberattack in December 2022 that compromised the email accounts of up to 15,000 corporate customers.
- The company has emphasized that the order management system does not store identity documents or banking information.
Statistics:
- 300,000 iiNet customers were affected by the cybersecurity incident.
- 280,000 active email addresses were exposed in the breach.
- 20,000 active landline phone numbers were exposed in the breach.
- Approximately 10,000 iiNet user names, street addresses, phone numbers, and some passwords were compromised.
- The incident was facilitated by stolen employee credentials.
Sources:
- TPG Telecom press release (no date provided)
- Reuters (no date provided)