Optus data breach

If you have a mobile phone, landline phone or NBN service with Optus you may have been caught up in the recent breach of Optus customer account records. This can leave you exposed to identity theft or other personalised scams, so you should take urgent action to protect yourself.

This article has good advice about what to do. You should read that article carefully, but below are some summary points that may help. The Government has also issued advice on the Optus data breach

U3A Nunawading is offering some classes to assist you with this. Check the enrolment database for current offerings. The presentation information is available here:

What are the main risks?

The leaked information apparently includes information that may make it easier for scammers to:

  • send you plausible-looking scam messages – be even more careful with messages and emails. Avoid clicking links or responding in any way unless you are absolutely sure of the sender.
  • call you and address you by your name so you think it is a legitimate call. Hang up and call the supposed service on a number you find yourself.
  • attempt to ‘port’ your phone number to a scammer’s phone – and you lose access to your phone number. If you get your provider to lock your SIM card this will be much harder to do.
  • pretend to be you – using some of the stolen information to then change passwords on accounts or otherwise obtain services in your name. This is termed ‘Identity theft’ and can be very difficult to undo. Contact IDCare if you suspect this has happened.

How to protect yourself

  • Change the password on the email addresses listed with Optus. You can do this at https://www.optus.com.au/my-account-login. Check what other information they have about you while you are there.
    For any other email addresses you probably don’t need to worry, but it never hurts to change a password as long as you follow the safe password rules:
    1. choose a password that has never been used elsewhere – by you or anyone else
    2. make it LONG
    3. avoid including names or dates of anyone associated with you
    4. ideally include numbers, upper and lower case characters.
  • Set up 2-factor authentication on your email address(es). If possible use an app rather than use a message sent to your phone (in case your phone number is “ported”)
  • Change the password and set up 2-factor authentication on any other potentially vulnerable accounts, such as:
    • bank accounts
    • superannuation or other financial accounts
    • MyGov, Medicare, Centrelink logins
    • any location where your credit card details or banking details are stored eg PayPal, Amazon, eBay
  • Lock your SIM card to your current network – This prevents your phone number being “ported” to a different provider. Optus has locked SIM cards temporarily but that lock probably won’t last. You will need to talk to your provider to do this.
  • Freeze your credit if you can – see the article
  • Keep a watch on your bank accounts for any unexpected transactions
  • Register all your email addresses at HaveIBeenPwned. This breach may not be included there, though, since it appears passwords have not been stolen.

If you do become a victim

If you become aware of unexplained transactions on your bank or financial accounts:

  • call the institution and clarify the situation
  • contact IDCare for guidance
  • report cyber crimes through CyberReport
  • act quickly – the faster you act the less damage the scammers will be able to do.

Helen Smith
U3A Nunawading webmaster
webmaster@u3anunawading.org.au