A cyber incident under investigation by TPG Telecom Ltd (ASX:TPM) has resulted in the extraction of sensitive iiNet customer data, including about 280,000 active email addresses, 20,000 landline numbers, 10,000 user names, street addresses and phone numbers, and 1,700 modem set-up passwords.
TPG told the ASX the breach involved “unauthorised access to an iiNet order management system by an unknown third party” using stolen employee credentials.
The incident, detected on Saturday, August 16, activated TPG’s incident response plan, which removed the unauthorised access. External IT and cybersecurity specialists are assisting the company’s investigation.
The compromised iiNet system is used to create and track broadband service orders and contains limited personal details. TPG stressed that no identity documents, credit card or banking data were stored on the system.
“We unreservedly apologise to our iiNet customers impacted by this incident,” the company said. “We will be taking immediate steps to contact impacted iiNet customers, advise of any actions they should take and offer our assistance.”
Non-impacted customers will also receive confirmation that their details were not affected. TPG added there is no evidence its wider systems or other customers have been impacted.