Menu
Browse

Cyber Incident Victim: Transport for New South Wales

Date:

Apr 2022

Location:

Australia

Summary

Transport for NSW experienced a cyber incident affecting its Authorised Inspection Scheme online application, where an unauthorised party accessed a limited number of user accounts containing personal details such as names, addresses, contact information, dates of birth, and driver's licence numbers. The organisation acknowledged the breach's impact on data privacy, initiated direct notifications to affected examiners, and implemented additional security measures while continuing application monitoring. Officials warned customers about potential scam attempts leveraging the incident and advised vigilance against unsolicited communications. This event followed a prior cybersecurity breach involving a third-party file transfer system.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early April 2022, Transport for New South Wales experienced a cyber incident impacting its Authorised Inspection Scheme (AIS) online application platform. The AIS system facilitates the certification of vehicle examiners who assess compliance with safety standards, requiring applicants to submit sensitive personal information including full names, addresses, phone numbers, email addresses, dates of birth, and driver’s licence numbers. An unauthorised third party successfully compromised a limited number of user accounts within this system, though the exact method of intrusion was not disclosed by the agency. Transport for NSW confirmed the breach in early May 2022, characterizing the compromised accounts as a "small number" while acknowledging the seriousness of potential data exposure. The organization expressed regret over the privacy implications for affected customers and emphasized the sensitivity of the personal information involved in the application process.

Cyber Incident Image

Following the breach, Transport for NSW initiated direct notifications to impacted authorised examiners, offering unspecified support options to mitigate further consequences. The agency issued public warnings about potential scam attempts leveraging the incident, advising customers to disregard unsolicited communications purporting to address security matters related to Transport for NSW. Internal response measures included implementing additional security controls on the AIS application, though specific technical enhancements were not detailed in public statements. Continuous monitoring of the system was established to detect any anomalous activity. This incident occurred approximately one year after a separate cybersecurity event involving Transport for NSW, which stemmed from vulnerabilities in a third-party Accellion file transfer system unrelated to the AIS platform. The organization maintained operational continuity of its inspection services throughout both incidents.

Sources
Sources available to members
1 source