Desk live·
ForensicPost
Breaches/Identity/File 22-0922

An API That Asked for Nothing, and 9.8 Million Customer Records

The endpoint required no authentication and reporting says it was reachable for up to three months. At least 2.1 million Optus customers had a government identity document number exposed — around 150,000 passports and 50,000 Medicare numbers.

Constructed geometry · not a chart of case data
JurisdictionAustraliaSydneythe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetOptus
ActorUnattributed
D. Kennedy12 min readConfidence: high2 sources reviewed

On 22 September 2022 the Australian carrier Optus disclosed a breach affecting more than 9.8 million customer records. The cause reported is an internet-facing API that required no authentication — anyone who found it could retrieve customer data directly.

Reported categories include names, addresses, email addresses and dates of birth, and for a subset, government identity document numbers. At least 2.1 million account holders had at least one form of identity document exposed, including around 150,000 passport numbers and 50,000 Medicare numbers. Optus later agreed to pay for passport replacement and offered credit monitoring to the most affected.

No Authentication Is Not A Vulnerability

There was no flaw to exploit in the ordinary sense — no memory corruption, no injection, no stolen credential. The endpoint answered questions it was asked, to anyone who asked, because nothing was configured to ask who was calling.

The corpus records at 26-0802 that a quarter of its files establish no entry route at all, and treats "the door was open" as its own category rather than as a subtype of exploitation. A missing control leaves no exploit artefact, which is also why it can persist for months without producing a single alert.

Passports Are Not Passwords

A password is invalidated by changing it. A passport number is the identifier on a physical document with a ten-year life, and it is the thing identity verification processes are built to accept.

Optus agreeing to fund passport replacement is a better remedy than the corpus usually records — the desk criticises credit monitoring at 25-1031 precisely because it monitors rather than fixes. It is still reimbursement of an administrative cost rather than a fix for the exposure, and the corpus files the same asymmetry at 26-0726 and 26-0721b, where the remedy was 24 months of monitoring against a document valid for a decade.

A Carrier Holds Identity Because The State Requires It

Optus held passport and Medicare numbers because identity verification obligations require a carrier to collect them. The data was not gathered for commercial advantage; it was gathered to satisfy regulation, and then retained.

Telecom operators hold identity-grade data because billing and regulation require it, and the corpus records the consequences at 26-0715 and 23-0119. A rule that mandates collection without a matching rule on retention produces exactly this: a carrier holding a decade of identity documents for customers who left years ago.

How we reported this

Built on contemporaneous reporting and subsequent technical analyses. The 22 September 2022 disclosure, the >9.8 million record figure, the unauthenticated internet-facing API as the reported cause, the ~2.1 million with at least one identity document exposed, the ~150,000 passport and ~50,000 Medicare figures, and the passport-replacement and credit-monitoring remedies are as reported. The claim that the endpoint was reachable for up to three months is reported by analysts and is carried as a reported figure, not an established one. Regulatory proceedings that followed are outside the scope of this file. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. How Did the Optus Data Breach Happen?UpGuard
  2. API Vulnerabilities in the News: Optus Data BreachSecurity Boulevard
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary