Select Page

Incident: Sumo slammed by data breach, as energy and internet customers have details leaked | SHM

Incident: Sumo slammed by data breach, as energy and internet customers have details leaked | SHM

Australian Energy Privacy Breach, 15 May 2024

Victorian energy provide Sumo Energy slammed by data breach, as energy and internet customers have details leaked

Personal details of approximately 40,000 customers were compromised, including approximately 3,000 Australian passport numbers

Company Statement: Sumo Data Breach
Source: Sumo slammed by data breach, as energy and internet customers have details leaked | SHM

View more incidents relating to the Utilities sector and from Victoria.

Australian utility provider Sumo has suffered a data breach, the company has confirmed, with customers’ personal information, including credit scores and licence numbers, posted online.

Sumo executive chairman Kel Fitzalan emailed customers on Wednesday, apologising and informing them that an issue with a “third-party file storage application” had caused the breach. According to Fitzalan, information taken included full names, addresses, dates of birth, mobile phone numbers, credit scores and licence numbers. Sumo, which is headquartered in Victoria, is thought to have more than 60,000 customers across its electricity, gas and internet products.

“On Monday 13 May 2024, Sumo became aware of an incident where customer data was accessed by an unknown person via a third-party file storage application used by Sumo. We can confirm that none of Sumo’s systems were affected.

Sumo has sent email notification to just over 40,000 people that Sumo has identified so far who have been impacted. If Sumo does not have an email address or the email address Sumo has is invalid, Sumo will send a letter.”

A poster – who goes by the forum name “OriginalCrazyOldFart” – also linked to a site hosting details of a vast number of accessible Amazon web buckets, where the bulk of the data was stored.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.


Subscribe to my weekly Australian Cyber Security News email

No advertisements, marketing, sales, or unsolicited emails. Your email address is ONLY used to send the publications listed above.

More Australian News

Shares
Share This

Discover more from Australian Information Security Awareness and Advisory

Subscribe now to keep reading and get access to the full archive.

Continue reading