A hacker gained access to databases of Australian travel insurance company Aussie Travel Cover and managed to retrieve information for over 750,000 customers.
The company suffered the breach on December 18 and notified its agents a few days later, but did not notify the customers whose private information was exposed.
A person with the Twitter handle Abdilo claimed responsibility and announced the attack in a message posted on Twitter , providing a link to a leaked database as proof of his actions.
The file includes log-in credentials of insurance advisors, as well as more than 770,000 policy records containing addresses, parts of payment card numbers, the country of residence (mainly Australia) and the identifier for the insurance type.
It appears that the reason Aussie Travel Cover did not contact customers was because the investigation was at an early stage, as reported by the ABC, citing an email the company sent to its advisors.
This tactic is often followed when the investigation is ongoing and more details are needed to determine the extent of the breach and identify the information that has been exposed.
According to the report, Abdilo may have more databases in his possession that have not been publicly exposed. These databases may contain information that can be exchanged for cash, which could lead to identity theft incidents.
In his Twitter feed, the hacker, who reportedly lives in Queensland, refers to attacks on other websites that have been carried out using the SQL injection.
In some cases, the hacker announces the discovery of the vulnerability and invites the interested party to provide him with a contact e-mail address to provide the necessary information.
This method is used to gain access to sensitive databases by executing malicious SQL statements entered into an available entry field. If the command is executed successfully, then private data will become accessible.
To resolve the issue, Aussie Travel Cover has taken its website offline for about a month.

