• long running

Free Replacement of Passport for Eligible Optus Data Breach Customers @ Australian Department of Foreign Affairs and Trade

3223

For those affected by the Optus data breach.

Announcement by Anthony Albanese on Facebook.

An important update for all Australians on the Optus security breach.

After actions taken by myself, Penny Wong - Senator for SA and Clare O'Neil MP, Optus has agreed to pay for replacement passports for those affected by the data breach.

From DFAT page:

If I decide to get a new passport, will I need to cover the cost?

Optus has indicated it will cover the costs of replacing affected customers’ passports. On 30 September, the Prime Minister confirmed that Optus will cover costs for affected customers wishing to receive a new passport due to the breach. The APO is working with Optus to finalise these arrangements. Optus will contact customers that are affected.

Update 14-Oct-2022

Information copied from the Optus Website regarding passport information

Do I need to replace my Passport?

For Australian passport holders, the advice from the Department of Foreign Affairs and Trade (DFAT) is that you do not need to replace your passport.

For New Zealand passport holders with concerns, contact New Zealand Internal Affairs (NZIA).

For International Passport holders, Optus is working with the Department of Home Affairs to provide advice to these customers. You will be contacted if you need to take any action.

To help you identify the numbers this article refers to, please visit our ID Document Number reference guide.

Australian Passport Holders

There are four groups of customers with Australian passport information exposed. If Optus contacts you, we will notify you of the group to which your circumstances relate.

If you remain concerned, for Australian Passport holders there are specific circumstances where we will provide reimbursement to eligible customers to replace their passport. This process will be formalised in the coming week. Please contact us then for more information.

Please read the website for more information at https://www.optus.com.au/support/cyberattack/passport-inform…

Related Stores

Australian Passport Office
Australian Passport Office
Optus
Optus

Comments

        • He left a month ago so it's harder to hold him accountable.

          https://www.itnews.com.au/news/data-breach-puts-heat-on-new-…

          • @Clear: Lucky guy.

            Well the good news is if anyone is looking for a job in cyber security there should be some senior roles opening up soon.

            • @dust: Given Optus is a subsidiary of Singtel he would have answered to the CISO there and he's not going to be in Australia.

              Bad time to have worked to have IT/Cybersecurity at Optus in your resume.

  • +4

    I called Optus to see if i was impacted as i was a former customer. They told me, all user data is deleted when you leave.

    I just checked via the whirlpool method and can see my name, address, email, phone number…all currently valid but was never contacted by them.

    Wtf?

    • +1

      How do i check if inam affected?

      • you can check what info Optus has about you, if you are able to login to their website with an account.
        My account isn't valid anymore but i was able to login and obtain the customer ID.
        Instructions here - https://whirlpool.net.au/wiki/optus_sept_2022_breach

        • +1

          Wished I had access this a few days ago. Now that the details are hashed out, I can't see what ID I provided to Optus!

          (As of 30th September 2022, identity document information has been sanitised and no longer shows when looking at the below API endpoints – they now show 'XXXXXX' against indentType and indentValue instead of 'Driving Licence' and license number for example)

    • +2

      Thats bullshit, i got an email and im a former customer. They def didnt delete my info when i left

      • +1

        KBR the CEO said they are required by law to hold customer records for 7 years.

    • I am a former customer - only used for porting / prepaid - and I received the data breach email apology.
      So clearly not deleted upon leaving.

  • +1

    mine expired in 2017…am i eligible??

    • replacement <> renewal :D

  • To retain existing customer
    Apart from paying those replacement fee like passport or driving license
    Optus should waive at least 1 month fee for postpaid customers
    and apply some credits to prepaid customers

  • How do i check if i am affected?

  • Based Albanese

  • +1

    What if you've provided an overseas passport? Especially a Russian one

  • -1

    But there really shouldn't be that many people that have used their passport in order to purchase a product from Optus…. When I was doing Telco for 100 points ID most common was licence, bank cards ,medicare cards. i can't recall in 10 years of Telco entering Passport for ID……

    • +1

      Absolutely - most people would have their cards in their wallet, and that's what they'll grab to do an ID check.

      If you want to use your passport, you have to seek it out - it's not in your back pocket 😎

    • +3

      Have you considered that not everyone in Australia has an Australian driver's licence? Bank and medicare cards are also secondary forms of ID.

      • Yes I have, But as stated my time in Telco as very rare. Most parents would put on plans for their kids so of course, they drove.. I would love to know the statistics on people using passport. I would say less than 10%

  • +1

    How can I find out if optus has my passport details or drive license details? It was a long time ago, and I can't remember what I provided.

    • I think they're supposed to notify you if your details were in the breach.

      • +2

        Haven't emailed or SMS'd me anything. Not even something generic, only seen news in media.

        I've spoken to 12 live chat agents trying to figure out what they have on me, one of them said my account is involved in the breach, but wouldn't tell me which documents they keep on me, and now I've finally been escalated to someone who can look into this for me.

        But they've been "investigating" for 3 days now.

  • +6

    My birthdate was leaked too. Can I get a new brithdate also.

  • How to get the process started to apply for a new passport if your data has been breached?

    • -2

      by reading from page 1 of this post

      • +1

        i read it…cant find any info…where specifically?

  • I have mobile broadband with Optus, am I eligible? How do I know if I’m affected or not? My data isn’t on the 10k file.

  • +1

    free passport for getting your data leaked hardly seems a bargain.

    • +1

      Cheaper than updating all your doxxed identification yourself.

  • can we just assumed everyone get affected and move on…

  • Yeah. If you could just complete the renewals I sent you 6 weeks ago for my kids first, that'd be great. Tick Tock ffs.

  • Is this why the cheapest plan Optus have right now is $49 a month?

    So expensive.

  • +2

    Here's the link to register for the up and coming class action:
    https://www.slatergordon.com.au/class-actions/current-class-…

    • +2

      signed up by providing my personal information and ticked the 'acknowledgement' box for them to keep my data… lol

      • your data is worthless now probably sold by bulk to some European countries

  • I've always used my driving license for ID to get a broadband or a pre-paid plan. Unless you don't have a driving license, when do you need a passport with a telco?

    • Yeah ive only used it before getting a licence (>10 yrs ago for me)

    • +2

      It's actually worse to use your driver's licence, as the road authorities don't change the document number at renewal, whereas the document number of passports gets changed at renewal.

      • It kind of depends what is more important to you. A passport will take ages to replace right now, and it gets cancelled once you try to replace it. So no travel no nothing until you get the new one. A drivers licence number doesnt normally get changed, but for this Optus drama they are letting people get new licence numbers easily (Qld at least) and you can still drive while waiting for it as you get a paper one right away, so smaller impact. (especially if you have overseas travel plans)

  • +1

    So how would you apply for a free new passport? Do you have to prove your optus customer?

    • +1

      you need to wait for the hacker to confirm to optus that they have your data

  • -5

    Will just make the queue for passports longer

    • Invalid use of negative vote

  • +6

    Called Optus and they said they are not aware of free Passport replacement.

  • +3

    (profanity) Optus

  • I could be blind but where's the link to apply for a new passport, or hasn't it been released yet? Couldn't see it on the Passports.gov.au or on Anthony Albanese' post

  • +3

    Who gave Optus their passport though???

    • Sometimes when applying I found the D/L method didnt work so used alternate forms such as medicare and passport. Since they wont tell us which have been compromised we can only assume all 3 forms and update accordingly.

    • +2

      Those who don’t drive - me! Passport has been my primary ID for more than 30 years.

  • Where does it say on the passports.gov.au web page that Optus will cover the cost of replacement passports ?

      • Thanks, but it looks like they are still working out this detail

        -
        If I decide to get a new passport, will I need to cover the cost?

        Optus has indicated it will cover the costs of replacing affected customers’ passports. On 30 September, the Prime Minister confirmed that Optus will cover costs for affected customers wishing to receive a new passport due to the breach. The APO is working with Optus to finalise these arrangements. Optus will contact customers that are affected.

        -

  • I really hope Optus is going to cover at least some of costs for replacing all these licences/passports!
    I think we have enough government debt to sustain current inflation for at least a decade we don't need any extra assistance.

    • +1

      Isn't that what this post is about?
      Albanese: …After actions taken by myself, Penny Wong - Senator for SA and Clare O'Neil MP, Optus has agreed to pay for replacement passports for those affected by the data breach.

      • Sorry for being Captain Obvious I guess I should've read the details.
        Glad to hear Optus are covering costs.

        • +2

          Are Optus truly covering the cost?
          Telecommunications customers (ie. all Australians) will be covering the costs for years through higher phone plan costs.
          You won't be spared as a Telstra or Vodafone customer.

  • I was a Optus customer a few years ago.
    How do I know if my data has been leaked?

    • I got an email stating my details were leaked. I also called them to confirm what exactly was leaked.

      • The email said that my personal details were exposed (like ), but

        No ID document numbers or details have been affected.

        Guess I am not eligible for the replacement passport/license?
        Address, dob, & personal details expose is still a risk?

  • +1

    will this add any time to my passport expiry?

  • +1

    Does this depend on whether your document numbers have been affected or is it for anyone who has only had name, address dob affected?

    Most people i know got an optus email saying
    "No financial information or passwords have been accessed. The information which has been exposed is a combination of your name, date of birth, email, phone number and/or address associated with your account. No ID document numbers or details have been affected."
    Think that means they dont qualify for the free NSW license replacement.

    • +2

      Mine says the first part but also says “and the numbers of the ID documents you provided such as drivers licence number or passport number”.

      I know it was my passport and Medicare as those are the two ID’s I use for the 100 point ID’s.

  • I cant figure out if ive been done or not.

  • So many people here appearing to be confused. This article from ABC might help clarify:
    https://www.abc.net.au/news/2022-09-30/how-do-i-replace-my-p…

    • +1

      That article doesn't state how a person will get a reimbursement from Optus.

      Just a generic article on getting a replacement driver licence/passport.

      • The article seems to be pretty straight forward and informative.

        Have you been directly impacted and have evidence of that?
        Which of your documents are impacted?
        Which state are you in?

        • +3

          Yep I have 2 accounts. Provided passport on one account and driver license on the other account. Received email for both accounts from Optus stating details leaked including any driver license/passport that were previously provided to Optus. Can view the details on the Optus API search.

          I'm in NSW and don't think I will be able to get a reimbursement for the driver license since its only for those that got the license number and card number leaked. There's no way to find out if these details were leaked anymore.

          Have not received any other emails regarding reimbursement or 12months free credit checks as yet. Live chat tells me they will email me if they deem that I will need a replacement. So as of right now. there is no way of getting any reimbursement or funds from Optus.

          • @linkii: Ok,
            The ABC article spells out the info for passport replacement (if needed), noting that:
            *…it's unclear at this stage whether impacted customers will be able to replace their passports free of charge or if they'll be reimbursed after paying the fee…The APO website says it's still "working with Optus to finalise these arrangements". *

            Similarly, the info in the ABC article re NSW drivers license seems clear:
            "The cost to replace your drivers licence is $29 and will be charged by Service NSW at the time of application — reimbursement advice will be issued by Optus to customers in the coming days…"

  • +1

    I received the Optus email saying I was impacted, including IDs.

    Finally received this reply from Optus chat when asking about replacing my passport (I’m in QLD) -

    “We’ve been working closely with your state government. We’ll be in touch with specific guidance over the coming days if we consider there is a need to change your driver’s licence and Passport details. When we get in touch, we’ll place a credit on your account to cover the replacement cost, if any. We’ll do this automatically, so you will not need to contact us.

    If you don’t hear from us, it means that your driver’s licence and Passport doesn’t need to be changed. You can refer to your state’s official statement for more information”.

    • +7

      Bullshit response

    • i got exactly the same template.

      I really don't trust them in contacting me to let me know exactly what was compromised. Heck… the speed they have been… i wouldn't be surprised if the data is put to use already !

    • That only works if you have a current account with Optus.

      • I can still log into Optus but haven't had an account since feb 2021.

        I assume that email came after the more broader email? Neither really tell you much ..

    • +1

      If you don’t hear from us, it means that your driver’s licence and Passport doesn’t need to be changed.

      BS indeed. I contacted them asking about a code for Equifax Protect and after about 24 hours I had a reply that stated they had checked my account and none of my ID details were involved in the breach.

      I then replied and said that I'd received two separate emails from Optus (I have two profiles with different email addresses) stating that all of my details including passport/drivers licence ID numbers had been exposed.

      They this new agent suddenly turned around and said he'd checked and that I had indeed had my details exposed, so he emailed me a code for Equifax. I haven't decided if I'm going to use it or not, but at least I have it… and now I have an admission/confirmation that my details are out there in the wild.

      The guy on chat could barely string a sentence together without spelling something wrong or missing a letter out of every 3rd word, it really does not give me a lot of confidence to be honest.

      The next issue I have is that right now, I only have a single prepaid service with Optus, and it's purely just to keep a phone number active. It's on the flex plan and I activate it for $1 every 6 months and that's it. If they are going to replace my passport (which was leaked on 2 different profiles), then a $308 credit on my Optus account is totally useless to me.

      There needs to be a way to get that back into my bank account for it to be meaningful.

  • if just having optus internet/nbn will i get affected ?

    • If you used ID to sign up then maybe

      • i wish like in asian countries we can just use $ to open mobile account, bank account and basically anything you can imagine of

        • Had to show passport for a Thai mobile Sim..

  • Weird, i still havent received any email from optus. I am not sure if replacing the IDs is enough, i.e. if someone takes my old id and sign up for something, would the provider check it for validity.

    • probably not, but hey they can blame that it could be another hacker hack your other utilities providers

  • +6

    Only the 10,200 in the leaked data are entitled to this. They seem to be taking the word of the hacker that the remaining of the 9.8 million records stolen have been deleted.

    So if your not one of the 10,200 notified, you need to pay for it yourself, or hope that your data doesn’t pop up down the track as it inevitably will.

    Your not even entitled to data monitoring, I just tried.

    • +2

      and … you trust a hacker?

      • +2

        Optus is the one saying that, by refusing to assist everyone with stolen data. I’m say you can pretty much guarantee that data is going to stay out there and appear at some point.

    • Your not even entitled to data monitoring, I just tried.

      That seems highly unlikely. I've received a code and my details aren't in the 10,xxx leaked so far.

      Further, when doing the whole equifax sign up, it offered the service for $0/month and asked for no financials. It did ask for a coupon code but was optional (I didn't needto use the code optus sent me, but that could be because the code is automatically linked to my email address or some such nonsense).

      • Where did you sign up ?

        This FAQ is pretty clear. It’s limited to the specific few contacted by Optus.

        How do I know if I am eligible for Equifax Protect at no cost?
        Current and former customers that have been contacted to tell them that they have had their ID number/s disclosed, in addition to other personal details such as name, phone number, date of birth and email, will be provided with the option to take up a 12-month subscription of Equifax Protect at no cost.

        • +1

          Contact Optus and demand they provide a code for consumer credit monitoring and protection (via chat or phone).
          Invariably they will have to provide it to everyone who was compromised I think. I was not specifically notified I was entitled to it - I just went into chat and asked two questions. 1 - what document types of mine were compromised and 2 - how do I get consumer credit protection as I am suspicious that someone might attempt to take out loans/make credit applications.

          They will provide an alpha-numeric code that is around 15 characters long. When I signed up on link below (which they will provide) - it did not ask for a code, however it may be linked by Optus to their particular customer anyway.

          https://equifax.com.au/optus

    • Where did you get that info from? Got a link?

      I’m so confused about all these replacement options. They all say “affected customers”, well I got an email on Saturday saying my details were taken. But since then news has come out in the media that there was 11k customers whose details were leaked. But I haven’t heard anything from Optus. I’ve heard of others getting some other email from Optus. Subsequent to that original one.

      We need clarity on this. Am I entitled or not? We need to be told clearly.

      This is worse than the vaccination shenanigans last year.

      • https://www.optus.com.au/support/cyberattack

        Affected means data leaked, not data stolen, according to Optus. If it’s leaked already you’ll hear from them. If it hasn’t leaked yet, then it’s up to you to take precautions for when it does

  • +1

    does this mean free passport renewal for 10 yrs?

  • How come Optus haven't contacted me yet? I'm clearly very affected as I checked my personal info they store and it's ALL there with address, phone, dob, drivers licence etc..

    Are they prioritising current customers or something? Which would be discrimination too right?

    • its like lottery chill man…

    • +1

      Are you actually expecting good customer service from Optus?

  • +5

    I am flabbergasted that some big companies and financial institutions still expect people to send their IDs by emails for verification! E.g Telstra when they wanted to verify me with my Telstra account during Telstra day sales. I pointed out to them and asked for a secured portal to send, they did not have, so I asked to go into the store to show the ID myself. No doubt the store photocopied my ID and emailed to their Telstra office. Next time you sign up a phone plan at JB, ask them how they send your ID to Telstra.

Login or Join to leave a comment