Cyber Incident Victim: Woollahra Council Libraries
Date:
Dec 2023
Location:
Australia
Summary
A cyberattack targeting a third-party software system used by Woollahra Council's libraries compromised personal information of library users, including names, addresses, email addresses, phone numbers, partial credit card details, and encrypted passwords for booking systems. The breach affected individuals who utilized library computers, room bookings, printing, scanning, or fine payment services. The council engaged the Australian Cyber Security Centre, Cyber Security NSW, and a forensic firm to investigate, while the software provider implemented a fix for the exploited vulnerability. Impacted users were notified, though the total number remains undetermined.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On December 15, 2023, Woollahra Council in Sydney's eastern suburbs discovered a cyberattack targeting library systems serving affluent areas including Double Bay, Watsons Bay, and Paddington. The breach occurred through a third-party software platform handling library operations such as public computer access, room reservations, printing/scanning services, and fine payments. Attackers potentially accessed personal data of library card holders who used these services, including names, residential addresses, email contacts, phone numbers, and partial credit card payment details. Encrypted passwords for the booking system were also stored within the compromised environment, though the council did not confirm whether decryption occurred. Council representatives stated they could not determine the exact number of affected individuals but confirmed the incident exclusively impacted users who had interacted with the specified library services.

Woollahra Council initiated incident response protocols upon detection, engaging the Australian Cyber Security Centre, Cyber Security NSW, and a specialized cyber forensic firm to investigate the breach. The third-party software provider developed and deployed a patch to address the exploited vulnerability in their system. Beginning December 15, the council directly notified potentially impacted library patrons about the data exposure and provided instructions through individual communications. Affected individuals were directed to contact ID Support NSW at a dedicated helpline (1800 001 040) for further assistance. The investigation confirmed no compromise of broader council infrastructure beyond the specified library management systems.
