Incident Of The Week: Australian Government Directory Breached In First Cyberattack of 2019

Phishing Attack Kicks Off The New Year

Add bookmark
CSIQ

The first data breach of 2019 came less than 24 hours into the new year when the private data of 30,000 Australian civil servants was stolen in a phishing attack. The breach occurred when a directory was downloaded by an unauthorized third party after a government employee in the state of Victoria received a phishing email.

The stolen data included details such as work emails, phone numbers and job titles. Staff were told no banking or financial information was held in the directory, according to ABC Network Australia.

University of Melbourne cyber security and privacy researcher Suelette Dreyfus told the network that although it did not appear the stolen data was highly personal or sensitive, the dataset as a whole could prove valuable for a more targeted attack.

"If you take even small snippets of information and you aggregate them into a dataset, you can then get an image of the entire state government because you know all the different people, their positions, their phone numbers … and you can figure out where the power center is and who you would target if you were going to try to hack someone's email," the network quoted Dreyfus as saying.

"Whether that's for commercial reasons about winning a contract or whether you were an international state player who might have an interest — financial or policy wise — all of these types of people could be advantaged by the information that was actually hacked," she said.

The Premier's Department said it referred the breach to police, the Australian Cyber Security Centre and the Office of the Victorian Information Commissioner for an investigation. "The Government will ensure any learnings from the investigation are put in place to better protect against breaches like this in the future," a spokesperson for the department said in a statement, ABC News Australia reported.

Adnan Dakhwe, head of security and compliance at data security provider Vera, told Infosecurity Magazine that even when corporations have security measures and policies in place, they are often challenged when it comes to keeping pace with employee turnover, a common innocent mistake that can jeopardize the integrity of data.

“Too often organizations stall in revoking access to sensitive files and corporate folders, once employees have parted ways with the organization,” Dakhwe said. “Keeping access permission updated in real time is essential to ensure private data isn’t jeopardized.”


Upcoming Events

Automotive Cyber Security, Connectivity & SDV Week 2025

18th - 20th November, 2025

Van der Valk Hotel Berlin Brandenburg, Germany

Automotive Cyber Security, Connectivity & SDV Week 2025

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended