Digital privacy group Electronic Frontiers Australia (EFA), said more needed to be done to protect sensitive data.
“People are now at constant risk of identity fraud—and worse—because organisations collect too much information, keep it too long, and store it insecurely,” said EFA’s chair Justin Warren.
Harvey Norman customers who signed up to their interest free loans are among those impacted by the Latitude cyberattack. Credit:Scott Barbour
“It’s clear that existing privacy protections are ineffective and must be changed. Organisations have had more than enough time to take action on their own, and have chosen not to. They must now be forced to change their ways.”
Anti-money laundering and counter-terrorism financing laws require certain financial service provider to keep customer identification records for seven years after they have stopped using its services.
In related news, casino operator Crown Resorts said it was investigating a cyberattack, but added its customer data had not been impacted.
Loading
Crown said it was one of many organisations that used the third-party file transfer service, GoAnywhere, which has been hit by a data breach globally.
“We were recently contacted by a ransomware group who claim they have illegally obtained a limited number of Crown files. We are investigating the validity of this claim as a matter of priority,” Crown said in a statement.
“We can confirm no customer data has been compromised, and our business operations have not been impacted.
“We are continuing to work with law enforcement and have notified our gaming regulators as part of the ongoing investigation and will provide relevant updates, as necessary.”
Other Australian companies impacted by the GoAnywhere incident include Rio Tinto, which said last week that data on former and current employees, including payroll details, may have been stolen.
The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.









Add Category