Department of Social Services says it has contained data breach 'vulnerability'
Department of Social Services says it has contained data breach 'vulnerability'.
The Australian Department of Social Services (DSS) has confirmed the third-party breach of its previous credit card management system, with data reportedly exposed by Business Information Services over an 11-year period containing the names, usernames, work phone numbers, work email addresses, and system passwords of department employees.
As first reported by the Guardian, DSS CFO Scott Dilley had written to 8,500 current and former employees warning them of the breach back in early November, explaining there was "a data compromise relating to staff profiles within the department's credit card management system prior to 2016".
It is reported that Business Information Services advised the department the data was "open" from the period spanning June 2016 through October 2017, and related back as far as 2004 through to 2015.
The letter from Dilley, according to the Guardian, blames "the actions of the department's third-party provider" and says the compromise "is not a result of any of the department's internal systems".