Security Affairs
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

230K individuals impacted by a data breach suffered by Telco provider Tangerine

Australian telecommunications provider Tangerine disclosed a data breach that impacted roughly 230,000 individuals. Tangerine suffered a data breach that exposed the personal information of roughly 230,000 individuals. The security breach occurred on Sunday 18 February 2024, but Tangerine management became aware of the incident on Tuesday 20 February 2024.   The telco notified the Australian Cyber Security […]

Tangerine

Australian telecommunications provider Tangerine disclosed a data breach that impacted roughly 230,000 individuals.

Tangerine suffered a data breach that exposed the personal information of roughly 230,000 individuals.

The security breach occurred on Sunday 18 February 2024, but Tangerine management became aware of the incident on Tuesday 20 February 2024.  

The telco notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner.  

The telecommunications provider pointed out that no financial information (credit or debit card numbers, banking details) has been compromised. The company also confirmed that the attack did not affect the availability or operation of their nbn® or mobile services. 

“We can confirm that no credit or debit card numbers have been compromised, as we do not store this information. No driver’s licence numbers, ID documentation details, banking details or passwords have been disclosed as a result of this incident.” reads the statement published by the company. 

The exposed information includes full name, date of birth, mobile number, email address, postal address and Tangerine account number. 

Upon becoming aware of the security breach, the company launched an investigation, which is still ongoing, into the incident.

The company hired cyber specialists to investigate the incident, the experts discovered that attackers gained access to an unsecured legacy database. 

“We have taken precautionary steps to fully revoke network and systems access for the individual user’s credentials and we have also changed all other team usernames and passwords. Access to the affected legacy database has also been closed.”continues the statement.

The company already notified impacted individuals by email on Wednesday 21 February 2024. 

The incident did not impact customer accounts, which are protected with multi-factor authentication (MFA).

Follow me on Twitter: @securityaffairs and Facebook

Pierluigi Paganini

(SecurityAffairs – hacking, Tangerine)