Desk live·
ForensicPost
Breaches/Identity/File 23-0316

Latitude Financial Breach Grew From 328,000 Records to 14 Million

An employee login taken from a service provider reached 7.9 million driver licence numbers and 53,000 passport numbers across Australia and New Zealand. The first figure the company published was under a fortieth of the final one.

Constructed geometry · not a chart of case data
JurisdictionAustraliathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetLatitude Financial
ActorUnattributed
S. Rosler11 min readConfidence: high2 sources reviewed

Latitude Financial disclosed a cyber incident on 16 March 2023. Reporting describes an employee login being stolen and used to reach two service providers holding Latitude customer data.

The company initially put the exposure at around 328,000 records. On further investigation it revised that to approximately 14 million customers and applicants across Australia and New Zealand, including roughly 7.9 million driver licence numbers and around 53,000 passport numbers.

A Forty-Fold Revision

The corpus records initial figures moving at 23-1117, where Welltok went from 8.5 million to nearly 15 million, and at 24-0620, where Change Healthcare took eleven months to settle. This is the largest proportional revision it holds.

It is worth being fair about why. The first number was published days into an investigation, because the alternative was saying nothing. The desk’s standing position is that early disclosure with a wrong number is better than late disclosure with a right one — but a reader comparing incidents by their first published figure is comparing almost nothing.

The Credential Came From Somewhere Else

The reported route was an employee login used to reach service providers holding the data. The organisation the customers dealt with, the organisation whose credential was used and the organisations actually holding the records were not the same.

The corpus files this three-party structure at 23-0331 for Capita, 23-0728 for Maximus and 26-0731 for Conduent. Where the data sits with a processor, a single credential can cross a boundary that appears on no architecture diagram the customer will ever see.

Identity Documents Are The Aggravating Factor

Driver licence and passport numbers are what makes this SEV 5 rather than SEV 4. They are used to establish identity at other institutions, they are expensive and slow to replace, and reporting noted a large proportion of the licence numbers had been provided within the previous decade — meaning current, not historical.

Latitude said it would reimburse customers replacing stolen identity documents. That is a better remedy than the credit monitoring the corpus criticises at 25-1031, and it is still a reimbursement for an administrative cost rather than a fix for the exposure.

How we reported this

Built on contemporaneous reporting of Latitude Financial’s disclosures and subsequent revisions. The 16 March disclosure, the initial 328,000 figure, the revised 14 million figure, the 7.9 million licence numbers, the approximately 53,000 passport numbers and the reimbursement commitment are the company’s own statements as reported. The route via a stolen employee login and two service providers is as reported and is not independently established by this desk. No actor attribution is made; none was established publicly. Characterisations of this as the largest identity document theft in Australian history appear in reporting and are not asserted here as a finding. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Latitude Financial data breach now impacts 14 million customersBleepingComputer
  2. 14 Million Records Stolen in Data Breach at Latitude Financial ServicesSecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary