IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

NSW government database leaks more than 500,000 addresses

The Australian state’s premier has admitted the data breach "shouldn’t have happened”

The New South Wales (NSW) government has admitted to a data breach that saw more than 500,000 addresses leaked through a government website.

Hundreds of thousands of locations were collected by the NSW Customer Services Department through its QR code registration system before being made public through a government website, as reported by 9News.

The locations belonged to organisations that registered as a COVID-safe business, an option that was available to all NSW businesses, as well as those in other states that had interests in NSW.

The leak was discovered by whistleblower Skeeve Stevens who identified the dataset in September and said he alerted cyber security experts, who then told the government.

Locations included defence sites, missile maintenance units, domestic violence shelters, critical infrastructure networks, and correctional facilities. Also included in the database were locations in the states of Western Australia, Victoria, Queensland, South Australia and the Australian Capital Territory.

The government said it had referred the matter to the privacy commissioner last October and was told the incident didn’t constitute a privacy breach. NSW premier Dominic Perrottet said he was advised of the issue this week, admitting that the information had been uploaded in error.

Related Resource

Vulnerability and patch management

Keep known vulnerabilities out of your IT infrastructure

Whitepaper cover with dark red smoke-like graphic on black backgroundFree Download

"That was worked through [the] privacy commissioner. My understanding is they were satisfied that the matter was resolved and that information was taken down. It shouldn't have happened," said Perrottet.

A spokesperson from the Department of Customer Service told IT Pro that a decision was made to publish a list of registered COVID-Safe businesses and that it stands by that decision. The spokesperson added that the issue wasn't related to QR code data, and that at no time were personal details published or QR code data of any kind.

"In a small number of cases, those businesses who self-registered were of a sensitive nature. In hindsight, their addresses should not have been published. These workplaces were subsequently contacted and the details of all businesses were removed," said the spokesperson.

The NSW Department of Customer Services told 9News it classed less than 1% of the 566,318 locations as sensitive.

There is a notice on the NSW data website from 12 October 2021 stating that the COVID-Safe Businesses and Organisation dataset has been discontinued. “We have identified issues with the integrity of the data with the recent increase in volume of registrations. We apologise for any inconvenience,” said the notice, without revealing what the issue was.

QR codes have caused experts to discuss whether they present a genuine cyber security threat, including last weekend when a marketing stunt from Coinbase used QR codes to drive potential customers to its site. Some experts said that they shouldn’t be fully trusted due to the potential for hijacking by cyber criminals, while others said that the concern around the technology is overblown and the real-world threat is relatively low.

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Recommended

South Korean public sector organisations targeted by Gwisin ransomware
ransomware

South Korean public sector organisations targeted by Gwisin ransomware

8 Aug 2022
APAC region to lose 63 million jobs to automation by 2040
automation

APAC region to lose 63 million jobs to automation by 2040

8 Aug 2022
Cyber attacks rain on Taiwan during Pelosi visit
cyber warfare

Cyber attacks rain on Taiwan during Pelosi visit

5 Aug 2022
Microsoft becomes Australian space hub's first 'Constellation Partner'
Cloud

Microsoft becomes Australian space hub's first 'Constellation Partner'

4 Aug 2022

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
Samsung proposes 11 Texas semiconductor plants worth $191 billion
Hardware

Samsung proposes 11 Texas semiconductor plants worth $191 billion

21 Jul 2022
Should you take your password manager off the internet?
Sponsored

Should you take your password manager off the internet?

28 Jul 2022