Menu
Browse

Cyber Incident Victim: Deakin University

Date:

Jul 2022

Location:

Australia

Summary

A data breach at Deakin University occurred when attackers compromised a staff member's credentials to access a third-party SMS provider, exposing personal details of nearly 47,000 current and former students, including names, student IDs, mobile numbers, email addresses, and some academic results. The threat actors used this access to send fraudulent text messages to approximately 10,000 individuals, posing as the institution to solicit credit card information under false pretenses. Immediate action halted further SMS dissemination, and investigations were initiated with support from the Office of the Victorian Information Commissioner and external cybersecurity experts. Affected individuals were notified and offered identity protection services, while security protocols for the third-party system were being strengthened to prevent recurrence.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 10, 2022, Deakin University discovered a cyberattack originating from a compromised staff member's account, which provided unauthorized access to a third-party SMS messaging platform used by the institution. Threat actors exploited these credentials to exfiltrate personal data of 46,980 current and former students, including names, student ID numbers, mobile phone numbers, Deakin email addresses, and in some cases recent academic unit results. The attackers simultaneously deployed a smishing campaign, sending fraudulent text messages impersonating the university to 9,997 students. These messages contained a link directing recipients to a phishing form requesting credit card details under the false pretext of processing customs fees for a package. University officials terminated further SMS transmissions upon detection, though the duration of unauthorized access to the third-party system remained unclear.

Cyber Incident Image

Deakin University immediately initiated an investigation with assistance from the Office of the Victorian Information Commissioner and an external cybersecurity firm. The institution notified all affected individuals, directing them to IDCARE's identity support services using referral code DUVL, while advising financial institution contacts for those who submitted payment details. Security protocols at the third-party provider were enhanced to prevent recurrence, though the initial compromise method for the staff credentials was not disclosed. The breach coincided with Australian regulatory reforms targeting SMS scams, as telecommunications providers faced new mandates to block fraudulent texts following a 188% annual increase in SMS scam losses exceeding AU$6.5 million. Impacted students received guidance on recognizing phishing attempts through official university channels, with Deakin reaffirming that legitimate payment requests would only occur through standardized institutional processes.

Sources
Sources available to members
2 sources