Tech

Latitude Financial begins notifying customers of data breach – up to 328,000 customers affected

Australia’s biggest non-bank personal finance lender Latitude Financial this morning advised the ASX that it had been the victim of a cyber attack, and this afternoon began contacting customers.

Following the massive Medibank and Optus breaches late last year Latitudes breach is on a similar level of severity while not as extensive in number.

Latitude has almost 3 million customers, so with 10% affected, it’s a massive problem for the company.

Critically, and for me most concerning – Latitude says that 103,000 ID documents were stolen. The concerning thing is they say that 97% of them were “copies of drivers’ licences”. Those words make me feel like they have literal photos or photocopies of drivers’ licences, which means both the Card Number and Licence number would be accessible to the hacker, meaning new drivers licences for 100,000 people.

It appears Latitude doesn’t keep much data of their own – with the original source of the hack happening at a “major vendor used by Latitude”. In that hack, a Latitude employee login credentials were obtained by the hacker.

What’s amazing is that those credentials were then used to steal personal information held by two other service providers. It’s at one of those providers where the 103,000 ID documents were stolen, and at the other 225,000 customer records were stolen.

We have no information about what was in those records.

Latitude this afternoon commenced contacting customers, saying “We’re writing to you directly to update you on a recent cyber-attack that Latitude Financial is actively responding to. Regrettably, the attack has resulted in the theft of some customer data”

“Latitude apologises to its customers, particularly those who were impacted. Please be assured we will contact you directly if your personal information has been disclosed.”

It’s an important first step for Latitude, taking the lead from Medibank’s approach to over communicating with customers, and doing the opposite of what Optus did which was to fail to communicate directly with customers.

The next step needs to be to clarify just what information was obtained by the hackers, and then to let individual customers know in which of the three groups they sit.

  1. Unaffected
  2. ID Document Obtained
  3. Customer Data Obtained

EFTM has asked Latitude the following questions which at this stage seem important to customers:

  1. Will you be offering identity protection services to your customers – if so how?
  2. How is one employee credential able to download so much customer data ?

Trevor Long

Trev is a Technology Commentator, Dad, Speaker and Rev Head. He produces and hosts two popular podcasts, EFTM and Two Blokes Talking Tech. He also appears on over 50 radio stations across Australia weekly, and is the resident Tech Expert on Channel 9’s Today Show each day and appears regularly on A Current Affair. Father of three, he is often found down in his Man Cave. Like this post? Buy Trev a drink!

Recent Posts

  • Reviews

Logitech G Astro A50 X Wireless Gaming Headset Review: A multi-device gamers dr

I can’t remember how many wired gaming headsets I’ve been through over the years -…

3 hours ago
  • Lifestyle

Podcast: Cocktail – The Best Movies You’ve Never Seen

While he hasn't seen the movie, Trev has some views on Cocktail, so watch it…

4 hours ago
  • Motoring

BYD Shark plug-in hybrid ute lands in Australia, due here early next year

The BYD Shark plug-in hybrid pick-up from China has been spotted in a car park…

6 hours ago
  • Motoring

Road test: 2024 Ford F-150 Lariat LWB. Twin-turbo V6 trumps V8 performance

What is it:  This is the top-of-the-range Ford F-150 in Australia. We drove from Sydney…

7 hours ago
  • Motoring

Polestar does U-turn on fixed prices in Australia, now planning a dealer expansion

The Chinese-owned electric offshoot of Volvo – Polestar – is poised to ditch fixed prices…

23 hours ago
  • Motoring

Road test: 2024 Toyota HiLux GR Sport. Not a Ford Ranger Raptor rival, but here’s why it’s still epic

What is it:  This is the new performance flagship of the Toyota HiLux range.  It…

1 day ago