Unnamed company blamed for NSW driver's licence leak

By Dylan Bushell-Embling
Thursday, 03 September, 2020

Unnamed company blamed for NSW driver's licence leak

Cyber Security NSW has confirmed a data breach involving around 54,000 driver's licences being leaked online, blaming an unnamed commercial entity.

ABC News reported yesterday that a storage folder on AWS containing over 100,000 images including front and back scans of NSW licences had been discovered by a security researcher in an easily discoverable public-facing folder.

The leaked images revealed names, photos, dates of birth and addresses of drivers, making it a potentially serious data leak.

Transport for NSW had denied that the collection of files involved in the leak was related to any government system, an assertion Cyber Security NSW has now confirmed.

“The data referred to in media coverage has been exposed via a commercial entity and is understood to include scanned copies of driver licences collected directly by the commercial entity from its customers,” Cyber Security NSW Chief Cyber Security Officer Tony Chapman said.

“The information was not provided by, nor sourced from NSW Government agencies. We do not know how long this commercial entity had this data open for and we do not know whether anybody other than the security researcher quoted in media coverage has accessed the information.”

According to the agency, it is the responsibility of the commercial entity to investigate the leak and notify any customers if their data has in fact been breached.

“Amazon Web Services has so far not provided information on the identity of the commercial entity, nor the customers that may have been affected by the breach,” Chapman said.

“There are mandatory reporting requirements under the Office of the Australian Information Commissioner that the commercial entity needs adhere to.”

Chapman added that Cyber Security NSW will continue to work with other organisations to seek more information about the commercial entity involved and encourage them to meet their disclosure obligations.

These organisations could include government agencies, emergency management, law enforcement and members of the private sector.

According to reports, the Australian Cyber Security Centre is also on the case and had contacted Amazon to have the data taken offline within hours of being alerted.

Image credit: ©stock.adobe.com/au/kichigin19

Related Articles

Study: Employee personal devices pose risk to corporate data

A Trend Micro survey has highlighted the risks posed by smart home devices to the corporate...

Aussie hackers targeting Facebook, Wi-Fi, says NordVPN

Research from NordVPN found that 43% of Australians looking to break into something were...

ACSC receives one cybercrime report every 10 min

The Australian Cyber Security Centre's inaugural Annual Threat Report for 2020 found that...

  • All content Copyright © 2020 Westwick-Farrow Pty Ltd