---
title: Breaches at Australian Firms Highlight Need for Data-centric Security
description: The three firms in question were telco Optus, wine merchant Vinomofo and retail marketplace MyDeal. Here’s what happened:
image: https://insights.comforte.com/hubfs/Back%20view%20of%20businessman%20reading%20documents%20in%20hand.jpeg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![data breach](https://insights.comforte.com/hubfs/Back%20view%20of%20businessman%20reading%20documents%20in%20hand.jpeg)](https://insights.comforte.com/breaches-at-several-australian-firms-highlight-need-for-data-centric-security)

[Mirza Salihagic](https://insights.comforte.com/author/mirza-salihagic) l Nov 3, 2022 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Data Breaches](https://insights.comforte.com/tag/data-breaches), [Asia-Pacific](https://insights.comforte.com/tag/asia-pacific)

# Breaches at Australian Firms Highlight Need for Data-centric Security

In the security industry we often talk about industry trends with a detached, generalist viewpoint. It’s only when real incidents happen and follow-on fraud starts occurring that the impact of soaring cybercrime really hits home. This is an underground economy still on an explosive growth trajectory, welcoming new participants, and causing pain for countless victims, every single day.

Three recent incidents in Australia reminded local residents of this new reality. In all three cases, encryption appears not to have been used to protect critical personal information. Those companies may be feeling the financial and reputational impact of these breaches for many years to come. It’s another unfortunate example of what happens to organizations that don’t put data-centric security front-and-center of their risk management strategies.

## What happened?

The three firms in question were telco Optus, wine merchant Vinomofo and retail marketplace MyDeal. Here’s what happened:

[Optus suffered](https://www.singtel.com/content/dam/singtel/investorRelations/stockExchange/2022/MR-20221003-OptusMediaAlert.pdf) perhaps the most damaging breach. Over two million customers were impacted by a September cyber-attack after a threat actor took advantage of major security gaps to steal a wealth of personal and identity information. This included 150,000 passport and 50,000 Medicare numbers, although 900,000 of the total were subsequently found to have expired. Such details can be a valuable starting point for multiple identity fraud attempts. Given that thousands of these records have already been posted online by the presumed hacker, it’s [extremely unlikely](https://www.afr.com/technology/not-feasible-to-crack-properly-encrypted-data-20220927-p5blda) they were encrypted. The Australian government has subsequently said that the telco should [pay for the replacement of victims’ passports.](https://www.zdnet.com/article/australia-government-wants-optus-to-pay-for-data-breach/)

[MyDeal suffered](https://www.woolworthsgroup.com.au/au/en/media/latest-news/2022/mydeal-data-breach-notification.html) a cyber-attack just weeks later, when an attacker breached its CRM systems to steal information on 2.2 million customers. Customer names, email addresses, phone numbers, delivery addresses, and dates of birth were among the haul – more than enough to craft convincing phishing and other follow-on fraud scams. There was no mention again by the company that these details had been scrambled, meaning they probably have not.

Vinomofo rounds out the trio. Although it has refused to issue a public statement on the matter, [reports suggest](https://www.infosecurity-magazine.com/news/breaches-expose-millions-at-aussie/) as many as 500,000 customers could be impacted. Names, gender, dates of birth, home and email addresses and phone numbers could be among the details stolen from a database accessed from a testing platform. The firm did not confirm to customers whether the information was encrypted, only that it was unlawfully accessed and that they should take precautionary steps going forward.

## Mitigating risk with data-centric security

Today’s IT environments are comprised of a complex blend of legacy and digital systems, and security doesn’t always work as intended, or else is implemented and configured incorrectly. In the case of Optus, best practice API security measures like [user authentication were apparently overlooked](https://nakedsecurity.sophos.com/2022/09/28/optus-breach-aussie-telco-told-it-will-have-to-pay-to-replace-ids/). In the case of MyDeal, a single compromised employee credential gave attackers the keys to the kingdom – access to a huge trove of customer data. To fully mitigate the risk of data loss, organizations must therefore go back to basics, and protect what really matters – not just the system surrounding the data, but also the data itself.

This is the rationale behind data-centric security. It’s all about delivering continuous and comprehensive discovery and classification of data, wherever it resides in the enterprise, and then applying protection in the form of format-preserving encryption, tokenization or other controls. In this way, organizations can benefit from:

- Limited fallout from data breaches – because even if the bad guys get hold of the data, it will be rendered useless
- Enhanced compliance with a range of legislation and regulations (GDPR, PCI DSS, etc.) at reduced operational cost
- Reduced financial and reputational risk stemming from serious breach incidents like the ones above
- The ability to continue using data to drive competitive advantage, safe in the knowledge it is protected

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/breaches-at-several-australian-firms-highlight-need-for-data-centric-security&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/breaches-at-several-australian-firms-highlight-need-for-data-centric-security&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/breaches-at-several-australian-firms-highlight-need-for-data-centric-security&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/breaches-at-several-australian-firms-highlight-need-for-data-centric-security&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/breaches-at-several-australian-firms-highlight-need-for-data-centric-security&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Want to learn more?

Click the button below to download the solution brief for comforte's Data Security Platform:

[![Download Solution Brief](https://no-cache.hubspot.com/cta/default/4026697/7962e9ff-2c50-4207-910f-fc5fd97083e7.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/7962e9ff-2c50-4207-910f-fc5fd97083e7)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>