Account details and phone numbers of Telstra customers were potentially compromised The Privacy Commissioner, Timothy Pilgrim, has launched an investigation into Telstra’s data breach which occurred on Friday when its customer service website was openly accessible on the Web.The telecommunications company said it was made aware of a privacy breach about 4pm (AEDT) on 12 December and disabled its online billing, BigPond self-care and My Account functions on its website an hour later.Account details including account numbers, phone numbers and credit card details of just fewer than one million Telstra customers were potentially compromised by the breach.As a precaution, the company reset the passwords of around 60,000 customers and notified the Privacy Commissioner. Pilgrim said in a statement that Telstra had assured his office that the immediate problem had been rectified and that personal data was no longer accessible.“I have asked that Telstra also provide me with a detailed written report on the incident, including how it occurred, what information, if any, was compromised and what steps they have taken to prevent a reoccurrence,” he said. “I will consider all the information provided by Telstra and hope to be in a position to issue an investigation report in late January 2012.”Telstra is not the only telco to experience a data breach this year. In January, Vodafone attributed an alleged security breach to an employee or dealer which meant that anyone with a login to Vodafone’s website could have gained access to customer information including credit card numbers, home addresses and driver licence numbers.A Privacy Commissioner report was critical of Vodafone’s use of shared logins but also praised it for undertaking an internal investigation of the incident and reviewing its data security practices.Got a security tip-off? Contact Hamish Barwick at hamish_barwick at idg.com.auFollow Hamish Barwick on Twitter: @HamishBarwickFollow Computerworld Australia on Twitter: @ComputerworldAU Related content news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Regulation Regulation news UK data regulator warns that data breaches put abuse victims’ lives at risk The UK Information Commissioner’s Office has reprimanded seven organizations in the past 14 months for data breaches affecting victims of domestic abuse. By Michael Hill Sep 28, 2023 3 mins Electronic Health Records Data Breach Government news EchoMark releases watermarking solution to secure private communications, detect insider threats Enterprise-grade software embeds AI-driven, forensic watermarking in emails and documents to pinpoint potential insider risks By Michael Hill Sep 28, 2023 4 mins Communications Security Threat and Vulnerability Management Security Software news SpecterOps to use in-house approximation to test for global attack variations The new offering uses atomic tests and in-house approximation in purple team assessment to test all known techniques of an attack. By Shweta Sharma Sep 28, 2023 3 mins Penetration Testing Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe