Select Page

Incident: The Iconic promises refunds after a spate of fraudulent transactions on customer accounts | ABC News Australia

Incident: The Iconic promises refunds after a spate of fraudulent transactions on customer accounts | ABC News Australia

Australian Retail Breach, 09 January 2024

Australian retailer The Iconic, promises refunds after a spate of fraudulent transactions on customer accounts

While not directly hacked, the unauthorised third party used a technique known as ‘credential stuffing’

Company Statement: SUSPECTED UNAUTHORISED ACCESS
Source: The Iconic promises refunds after a spate of fraudulent transactions on customer accounts | ABC News Australia

View more incidents relating to Retail sector.

Update 11 Jan 2024: Customers of The Iconic at risk of being defrauded due to lack of payment verification measures | ABC News Australia
the online retailer also confirmed that a transaction “may be made” as it does not require a customer to verify their CVC numbers.

 

YouTube player

 

Online retailer The Iconic has vowed to refund customers who have been left out of pocket by thousands of dollars after their accounts were compromised and fraudulent orders were made without their permission.

Many customers have been left out of pocket by thousands of dollars and have struggled to contact The Iconic and get a timely response. The Iconic confirmed affected customers would be compensated.

The Iconic’s response stated says it has not been the victim of a cyber attack, but rather a credential stuffing attack, where hackers use leaked email and password combinations from other sites. The company vows to refund affected customers.

Credential stuffing attacks are possible because many users reuse the same username/password combination across multiple sites. This type of cyberattack in which the attacker collects stolen account credentials, typically consisting of lists of usernames or email addresses and the corresponding passwords (often from a data breach), and then uses the credentials to gain unauthorized access to user accounts on other systems through large-scale automated login requests directed against a web application.

As part of this investigation, we are working closely with expert cyber security partners to assess the impact of the incident. We have notified law enforcement authorities including the Police and the Australian Cyber Security Centre, as well as the Office of Australian Information Commission (OAIC). This investigation remains ongoing.

The Iconic Breach Statement

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

Cyber Threat Landscape - Australia and New Zealand - CYFIRMA

Published On : 2026-09-25 EXECUTIVE SUMMARY A regional pattern with sector-specific expression Identity and access, not novel exploitation, is the … [...]

OAIC’s action in relation to the 2023 Latitude Data Breach and information to update and assist individuals

On 10 May 2023, the OAIC commenced an investigation into the personal information handling practices of the Latitude group of companies[1] (Latitude). … [...]

China seizes sensitive F-35 parts diverted from Australia

Washington | The Chinese government has taken possession of potentially sensitive F-35 stealth aircraft parts that were inexplicably diverted to Hong … [...]

NAB restores systems following online outage impacting customers

Major Australian bank NAB has restored systems following online outages that prevented customers from using their services. • Thu, 24 Sep 2026 • … [...]

OpenAI breach strengthens Australia's case for tougher AI safety rules

An unprecedented breach of a government website by a rogue OpenAI agent will sharpen Australia's push to impose stricter safety, transparency and … [...]

Quest tells customers to replace passports after security breach | ABC NEWS

The hotel company, Quest, is warning customers they may need to replace their driver's licences and passports. It comes after a cyber hack last month exposed swathes of personal information, [...]

Why did it take OpenAI three months to report the Medicare hack? | ABC NEWS

The federal government has raised concerns about uncontrolled and unauthorised AI activity after an AI model infiltrated a Medicare platform owned by Services Australia. The OpenAI agent accessed data not [...]

OpenAI agent hacked into Medicare to access data, prime minister says | ABC NEWS

Prime Minister Anthony Albanese has revealed an AI agent hacked into an Australian Medicare portal earlier this year. The OpenAI agent reportedly gained unauthorised access to private and public data [...]

Health data attack the 'first' government hack by autonomous AI, researchers say

A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say … [...]

Australian Medicare data portal "infiltrated" by OpenAI agent

Key points An OpenAI agent gained unauthorised access to both public and non-public files on a Medicare statistics reporting portal, Anthony Albanese … [...]

OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says

Prime Minister Anthony Albanese has revealed an AI agent hacked into an Australian Medicare data portal earlier this year. Speaking in New York, Mr … [...]

Quest Apartment Hotels tells customers to replace passports and licences after security breach

Quest Apartments has advised customers affected by a data breach in August to replace their passports and driver's licences after its investigation … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading