Australian Government department exposed in PageUp personal data breach

Earlier this month, it was revealed that human-resources service provider PageUp had experienced a data breach that could potentially put at risk many of its clients across the globe, which includes companies such as Coles, Australia Post and Telstra. And now, the Australian Attorney-General’s Office has confirmed that its staff are also among the potentially affected users.

As initially reported at the beginning of June, the Australia-based software maker found malware on company systems which were used to store private data, such as Tax File Numbers, bank details and other personally-identifying details.

It's since been revealed that the malware was indeed used to access this data and, while the company assures its users and clients that the systems are currently secure enough to continue using, it “sincerely regrets that some data may be at risk”.

Who copped it?

PageUp is responsible for HR software that helps manage the recruitment process for many major companies, alongside organising and running payroll duties. As such, the software has access to a raft of sensitive information for both existing employees and prospective job seekers.

The HR provider's client list is extensive and apparently covers companies across 190 countries, although it appears that Australian organisations are predominantly the ones at risk due to the breach. Along with the aforementioned Attorney-General’s Department, other employers include the likes of Telstra, Australia Post, Medibank, Wesfarmers and more.

While the investigation is still ongoing, the latest statement – which was made in partnership with the Australian Cyber Security Centre (ACSC) – claims that “no Australian information may actually have been stolen” as there is only evidence of it being accessed rather, than exfiltrated. 

New cybersecurity laws in action

It was only recently that Australia instated laws that forced companies to report data breaches in a timely fashion and to the appropriate authorities, and in the instance of PageUp, they have responded diligently.

The head of the ACSC, Alastair MacGibbon, praised the company's response, saying that “PageUp has demonstrated a commendable level of transparency in how they’ve communicated about, and responded to, this incident: they came forward quickly and engaged openly with affected organisations.”

As was the case with the previous report, it's recommended that users should change any passwords in use on PageUp-supplied services, as well as any unrelated accounts that may be using the same password.

Harry Domanski
Harry is an Australian Journalist for TechRadar with an ear to the ground for future tech, and the other in front of a vintage amplifier. He likes stories told in charming ways, and content consumed through massive screens. He also likes to get his hands dirty with the ethics of the tech.
Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
A phone showing a ChatGPT app error message
ChatGPT is down for many – here's what's going on
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
US flags
US government IT contracts set to be centralized in new Trump order
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping