Menu
Browse

Cyber Incident Victim: Transport for New South Wales

Date:

May 2016

Location:

Australia

Summary

A cyberattack compromised the NSW Trainlink online booking system, but subsequent analysis confirmed no theft of credit card details or personal customer information. The transport department clarified that sensitive data remained secure despite unauthorized access to the system, characterizing the incident as a breach without data exfiltration. This assessment followed an earlier disclosure of the security event, with officials reiterating that operational impacts were contained to system access without compromising passenger records or financial data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In late May 2016, the New South Wales transport department experienced a cybersecurity breach targeting the NSW Trainlink online booking system. The incident occurred approximately one week prior to the department's May 29 public statement, placing the attack around May 22, 2016. While initial reports indicated unauthorized access to the booking platform, subsequent investigation revealed no evidence of data exfiltration. The transport department confirmed that neither personal information nor credit card details had been compromised during the breach. The attack specifically impacted the digital reservation infrastructure but did not extend to other operational systems within the Transport for NSW network. No technical details regarding the attack vector or intrusion method were disclosed in official statements.

Cyber Incident Image

The department publicly addressed the incident through a formal announcement on May 29, 2016, emphasizing the containment of the breach and the integrity of customer data. Their response focused on verifying the absence of data theft through forensic analysis of system logs and transaction records. The statement served to update previous reports about the breach while reassuring customers about the safety of their financial and personal information. No service disruptions or operational impacts beyond the booking platform were reported following the incident. The investigation concluded that while unauthorized access occurred, the attackers failed to extract sensitive data from the compromised system. Transport for NSW maintained normal operations across all other services throughout the incident response period.

Sources
Sources available to members
1 source