AP

Australia flags tough new data protection laws this year

Sep 28, 2022, 7:04 PM | Updated: Sep 30, 2022, 3:12 am

CANBERRA, Australia (AP) — Australia could have tough new data protection laws in place this year in an urgent response to a cyberattack that stole from a telecommunications company the personal data of 9.8 million customers, the attorney-general said Thursday.

Attorney-General Mark Dreyfus said the government would make “urgent reforms” to the Privacy Act following the unprecedented hack last week on Optus, Australia’s second-largest wireless carrier.

Dreyfus said “I think it’s possible” for the law to be changed in the four remaining weeks that Parliament is scheduled to sit this year.

“I’m going to be looking very hard over the next four weeks at whether or not we can get reforms to the Privacy Act into the Parliament before the end of the year,” Dreyfus told reporters. Parliament next sits on Oct. 25.

Dreyfus said penalties for failing to protect personal data had to be increased so that corporate boards could not dismiss fines as a “cost of doing business.”

The “absolutely huge amounts” of customer data companies held for years would have to be justified under the amended law, Dreyfus said.

“Companies need to look at data storage not as an asset, but as a liability or a potential liability,” Dreyfus said. “For too long we have had companies solely looking at data as an asset that they can use commercially.”

The government blames lax cybersecurity at Optus, a subsidiary of Singapore Telecommunications Ltd., also known as Singtel, for the theft of current and former customers’ personal information.

Singtel apologized in a statement issued Wednesday by its management saying, “We are deeply sorry to everyone affected by the data theft.”

“Since the incident, our focus has been on supporting Optus’ efforts to help impacted customers and strengthen their security controls,” the statement said.

“Information security is of paramount importance to the Singtel Group and a top priority across all of its business units and we invest significant resources to continually strengthen our defenses against emerging threats,” the statement added.

The data included passport, driver’s license and national health care identification numbers which could be used for identity theft and fraud.

Authorities are critical of Optus’ initial failure to disclose that Medicare numbers were among the stolen data. That became apparent Tuesday when the hacker dumped the records of 10,000 customers on the dark web — six days after Optus discovered the cyberattack.

The urgent legislative response is separate from a broader review of the Privacy Act that began three years ago. The law was passed in 1988 and critics argue it badly needs to be adapted to the digital age.

Optus could potentially be fined a maximum 2 million Australian dollars ($1.3 million) for breaching the Privacy Act, the government said.

It could be fined hundreds of millions of dollars over a similar security breach under European Union laws, the government said.

Submissions to the Privacy Act review have suggested penalties for breaches equivalent to 10% of revenue from Australian operations.

Optus CEO Kelly Bayer Rosmarin has argued against increased fines, telling the Australian Broadcasting Corp. on Tuesday: “Honestly, I’m not sure what penalties benefit anybody.”

Optus maintains it was the target of a sophisticated cyberattack that penetrated several layers of security.

After an emergency meeting with banking and consumer regulators, Financial Services Minister Stephen Jones said “fraudsters” and “scammers” were already beginning to use the stolen data, which includes phone numbers and email addresses.

With personal information stolen from 38% of Australia’s population of 26 million in the hack, “you can’t overestimate the impact of this breach on consumer issues,” Jones said.

He warned compromised Optus customers against activating URLs they receive by text or email because they could be from criminals attempting to steal more information.

“We’re all working as best as we can to try and work our way through the long tail of problems that is going to be a consequence of this massive data breach,” Jones said.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Republican presidential candidates, former New Jersey Gov. Chris Christie, left, talking with forme...

Associated Press

The GOP debate field was asked about Trump. But most of the stage’s attacks focused on Nikki Haley

The four Republican presidential candidates debating Wednesday night mostly targeted each other instead of Donald Trump.

5 hours ago

Law enforcement officers head into the University of Nevada, Las Vegas, campus after reports of an ...

Associated Press

Police say 3 dead, fourth wounded and shooter also dead in University of Nevada, Las Vegas attack

Police said a suspect was found dead Wednesday as officers responded to an active shooter and reports of multiple victims at UNLV.

7 hours ago

President Joe Biden's son, Hunter Biden, leaves after a court appearance, July 26, 2023, in Wilming...

Associated Press

Republicans threaten contempt proceedings if Hunter Biden refuses to appear for deposition

House Republicans are threatening to hold Hunter Biden in contempt if he does not show up this month for a closed-door deposition.

9 hours ago

Sen. Tommy Tuberville, R-Ala., listens to a question during a news conference, March 30, 2022, in W...

Associated Press

Tuberville is ending blockade of most military nominees, clearing way for hundreds to be approved

Sen. Tommy Tuberville announced Tuesday that he's ending his blockade of hundreds of military promotions, following heavy criticism.

1 day ago

An employee works inside the Hanwha Qcells Solar plant on Oct. 16, 2023, in Dalton, Ga. On Tuesday,...

Associated Press

US job openings fall to lowest level since March 2021 as labor market cools

U.S. employers posted 8.7 million job openings in October, the fewest since March 2021, in a sign that hiring is cooling.

1 day ago

An employee works inside the Hanwha Qcells Solar plant on Oct. 16, 2023, in Dalton, Ga. On Tuesday,...

Sponsored Content by

U.S. employers posted 8.7 million job openings in October, the fewest since March 2021, in a sign that hiring is cooling.

Sponsored Articles

(KTAR News Graphic)...

KTAR launches online holiday auction benefitting Boys & Girls Clubs of the Valley

KTAR is teaming up with The Boys & Girls Clubs of the Valley for a holiday auction benefitting thousands of Valley kids.

Follow @KTAR923...

Valley residents should be mindful of plumbing ahead of holidays

With Halloween in the rear-view and more holidays coming up, Day & Night recommends that Valley residents prepare accordingly.

Follow @KTAR923...

The best ways to honor our heroes on Veterans Day and give back to the community

Veterans Day is fast approaching and there's no better way to support our veterans than to donate to the Military Assistance Mission.

Australia flags tough new data protection laws this year