Cyber Incident Victim: mySA Gov
Date:
Nov 2021
Location:
Australia
Summary
A cyber attack compromised mySA Gov accounts through credential stuffing, where attackers reused passwords obtained from an unrelated website to access the South Australian government's online service platform. The breach affected 2,601 accounts, exposing driver's licence and vehicle registration details in 2,008 instances. The Department for Infrastructure and Transport detected unauthorized access, blocked logins using compromised credentials, and notified impacted users, though no evidence of fraudulent transactions was found. Affected individuals were advised to change their licence numbers due to potential data exposure. The incident underscored risks associated with password reuse across multiple accounts.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On November 2, 2021, South Australia's Department for Infrastructure and Transport confirmed a cyber attack compromising mySA Gov accounts. The attackers accessed accounts by exploiting password reuse, utilizing credentials obtained from an unrelated external website to gain unauthorized entry. mySA Gov serves as the state's centralized online platform for services including venue check-ins and vehicle registration transactions. The department did not disclose the identity of the unrelated website or the timeframe of initial compromise but confirmed detection of the breach on November 2. According to reports, 2,601 accounts were accessed without authorization, with 2,008 containing sensitive driver's licence and vehicle registration details. No evidence indicated unauthorized financial transactions occurred within the compromised accounts.

The department implemented immediate containment measures, blocking logins attempted with known compromised passwords. Affected account holders received email notifications regarding potential unauthorized access to their information. Officials mandated password resets for impacted users, explicitly advising against reusing passwords across multiple accounts. As a precaution against potential identity misuse, the department urged affected individuals to visit Service SA Centres to change their driver's licence numbers. Public statements emphasized the necessity of complex, unique passwords for all accounts while refraining from attributing the attack to specific threat actors or detailing technical intrusion methods. The incident underscored risks associated with credential reuse across online services.
