Select Page

Incident: Thousands of donors to Australian charities, including Cancer Council and Canteen, have data leaked to dark web | ABC News (Australia)

Incident: Thousands of donors to Australian charities, including Cancer Council and Canteen, have data leaked to dark web | ABC News (Australia)

Australian Telemarketer Breach, 23 August 2023

Pareto Phone, a Brisbane-based telemarketing company that contacts potential donors on behalf of charities, was hacked by cybercriminals in April

Amnesty International Australia, Australian Conservation Foundation, Wilderness Society, Cancer Council Cancer, The Fred Hollows Foundation, Canteen, Heart Foundation Heart Foundation, Medecins Sans Frontieres

Company Statements:

View more incidents from Charities and Not For Profit sector and incidents relating to Queensland


Pareto Phone, a Brisbane-based telemarketing company that contacts potential donors on behalf of charities, was hacked by cybercriminals in April.

In a statement on Wednesday, Pareto Phone’s CEO, Chris Smedley apologised for the distress the breach had caused and said the company was working “urgently” with forensic specialists to analyse affected files. He did not respond to The Fred Hollows Foundation’s claim.

More than 320,000 files stolen from Pareto servers by cybercriminals in April were made public on the dark web last month, including tens of thousands of charity donor details.

Staff Information: Highly sensitive documents like police checks, child support documents, pay negotiations, HR incidents, immigration sponsorship details, COVID vaccination credentials, tax file numbers, passports and licences were also swept up in the wide-reaching leak.

Donor information including full names, date of birth, addresses, email addresses and phone numbers had been released, but not financial information.

The ABC understands more than 70 Australian charities used Brisbane-based Pareto Phone, but not all had been affected.

The Cancer Council, Canteen and Fred Hollows Foundation have confirmed donor information has been published on the dark web.

The Fred Hollows Foundation said 1,700 of its donors were affected, and claimed the data had been held without the charity’s knowledge.

In a statement on Wednesday morning, Médecins Sans Frontières (MSF) said it had not engaged the third-party fundraiser since 2018.

“Under the Australian Privacy Principles, organisations must take reasonable steps to destroy personal information data that is no longer required.

“MSF has not worked with Pareto Phone for almost five years.

“Pareto Phone has informed the regulators, the Office of the Australian Information Commissioner (OAIC) and the NZ Privacy Commissioner of their data breach.

Australian Conservation Foundation

“ACF can regretfully confirm some of our supporters’ personal information has been compromised in the Pareto data breach. We have notified 13,500 supporters who have been affected. We understand no ACF supporters’ credit card information or identifying documents are involved.

We trusted Pareto with our supporters’ personal information so the company could help us raise funds to continue our environmental protection and advocacy work. We are concerned Pareto kept old data it should have destroyed. We are suspending our relationship with Pareto immediately.

Wilderness Society

Unfortunately the identified files include some Wilderness Society supporter data. Pareto Phone has informed us that they have not identified any compromised data files related to Wilderness Society supporters that contain credit card or bank account details.
Please note that the Wilderness Society’s own systems have not been impacted by this incident in any way.

 

Australian Conservation Foundation Statement on Pareto data breach

Wilderness Society – Statement Pareto Phone data incident

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

Labor’s privacy reforms are the boldest we’ve had in years. But there’s a hole to plug

Shifting the emphasis from individuals upholding privacy standards to harmful and invasive business practices is the right move. But an existing … [...]

In brief: cyberthreat detection and reporting in Australia

Threat detection and reporting Internal policies and procedures What policies or procedures must organisations have in place to protect data or … [...]

Telstra sowed seeds for its July mobile outage in 2020. Six years on they sprouted.

When Telstra engineers embarked on a simple server chassis replacement exercise in 2020, they could barely have contemplated the complex chain of … [...]

Exclusive: NSW Health denies Medusalocker data breach claims

Ransomware actor claims hack of government department, but evidence suggests no malicious activity has occurred… But patient data from multiple … [...]

NT gov starts path to digital driver's licence

Key points The Northern Territory government plans to offer digital driver's licences built to internationally recognised standards by the end of the … [...]

Privacy Act overhaul to tighten 72-hour breach reporting deadline

Key points Draft legislation would give Australian organisations 72 hours to notify the Information Commissioner of an eligible data breach, replacing … [...]

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even … [...]

Treasury warned Government not to rush new school assessment tool before data breach

Treasury warned the Government not to rush its new school assessment tool – months before a security flaw made the records of 276 students accessible. … [...]

Expired anti-spam domain bites NZ's national stadium, Eden Park

Key points Eden Park's DNS configuration referenced an expired domain, spamcontrol.co.nz, letting consultant Alex Shakhov capture DMARC reports for a … [...]

Facial recognition technology 'scope creep' is upon us, experts warn

A shopper walks into a supermarket and grabs a basket. By that time, a camera has scanned their face. That is what experts warn could be the new … [...]

The Australian Financial Complaints Authority (AFCA) is inviting feedback from stakeholders on proposed changes to its Rules, that will enable it to … [...]

What changes will be made under federal government’s privacy law reform? | ABC NEWS

The federal government has unveiled plans to strengthen privacy laws. The proposed reforms take aim at identity fraud and give people the right to erase their data from online platforms. [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading