Optus has confirmed that the identity numbers of 2.1 million customers were exposed in the recent data breach, which occurred after an attack on the telecommunications company.
In a press release, the Australian company announced new details regarding the breach of personal data of 9.8 million customers.

The ID numbers of 1.2 million customers (out of a total of 2.1 million) came from a valid identification document. 900,000 came from documents that had now expired.
See also: Telstra data breach: 30,000 employee details exposed
“The new update offers greater clarity to customers our,” says Optus’ press release regarding the data breach.
“Having worked with government agencies to meticulously analyse data for the company's 9.8 million customers, Optus can confirm that the exposed information did not contain valid or current document identification numbers for approximately 7.7 million customers“.
However, as Optus initially said, all of these individuals (9.8 million customers) were affected by the data breach, as other details such as addresses email, dates of birth and phone numbers were exposed.
The company has sent SMS messages to customers whose ID numbers were compromised in the cyberattack, providing information on their next steps.
See also: Retail chain DNS suffered data breach
Customers whose driver's license information was compromised can request a new driver's license number to help prevent identity theft or other fraudulent activities.

The attacker had initially tried to blackmail Optus by demanding a $1 million ransom to not publish or sell the stolen data. However, after not receiving the money, he leaked the data of 10,000 customers to a hacking forum , which included names, addresses, email, phone numbers and dates of birth.
A few days after the data breach, feeling pressure from law enforcement, the hacker apologized to Optus and its customers and claimed to have deleted all stolen data.
However, we cannot know whether the hacker actually deleted the data or if he is secretly selling it to other cybercriminals. Therefore, all Optus customers should take the necessary protective measures and be constantly vigilant for future fraud or phishing.
See also: Hackers stole data from US defense agency
Following the data breach, users should be wary of emails or messages they may receive that may claim to be from Optus.
If someone receives an email or SMS text from Optus, they should go directly to the company's website and check for any messages there. Under no circumstances should they click on a link within the email.
Source: www.bleepingcomputer.com
