• long running

[WA] Free New WA Drivers Licence for Optus Data Breach Customers @ Transport WA

1530

WA has joined the free licence replacement party.

Relevant announcement from the Transport minister:

New drivers licences, with new licence and card numbers, will be available free of charge to Western Australians impacted by the Optus data breach.

Optus has just confirmed thay they will be contacting customers directly in upcoming days if their specific license has been compromised. This is in addition to the original email advising of the breach.

If you have received this secondary notification from Optus that your licence details have been compromised, please attend a Department of Transport Driver and Vehicle Service Centre with a copy of your Optus breach notice, as well as two forms of primary identification.

Further information, including frequently asked questions, will be available at http://transport.wa.gov.au later today.

ABC article with quotes from Mark McGowan

See Also: Driver License replacement schemes for other states.

QLD, SA, VIC, TAS, WA

Related Stores

Department of Transport, Government of Western Australia
Department of Transport, Government of Western Australia

Comments

  • No financial information or passwords have been accessed. The information which has been exposed is a combination of your name, date of birth, email, phone number and/or address associated with your former account. No ID document numbers or details have been affected.

    oh no. i dont get to have a new licence. :(

    • +8

      Same, though checking the API my drivers licence details are there. On what basis has Optus concluded they haven't been affected? Seems more likely their email is incorrect given the incompetence demonstrated thus far. Would rather get a new one to be on the safe side.

      • Opposite here, got a text from Optus saying my personal information including the number of the ID document provided was disclosed, although it's not in the API.

        • +12

          Strongly suggests they haven’t got a clue.

          • +3

            @B00PY: Checked my other account which is the one that actually has the active services attached and the DL details are there, sadly.

            All this because of the tablet deal that was posted here… hadn't been with Optus for several years prior.

            • @MiscOzB: Was that the iPad pro and data plan?
              I did the same, and pretty sure I used my driver's licence but haven received a secondary email with more detail yet.

            • @MiscOzB: I applied for same tablet deal. How did you check if your account was affected?

        • I used my passport as ID when I signed up with Optus in 2019,, as I hadn't renewed my license at the time. But the email I used I no longer use. Cancelled the service a year later, well ported to Boost.

          I haven't received any emails from Optus, or texts (still same number). Do I need to be worried about data breach? Or is this only affecting active customers?

          • @Tiggrrrrr: Not sure, but apparently it includes former customers dating back to 2017. But if they haven't contacted you, perhaps you've dodged a bullet.

          • @Tiggrrrrr: I haven't been with them since 2014 and i got a second email advising which of my details have been stolen so no, it affects previous customers too

            • @00broke00: Same, just waiting on second email now, got first one on Sunday. Hopefully second comes through asap. How many days between both your emails?

        • How you checking the API, are you saying it's still available? And isn't it illegal to even try accessing?

          • +1

            @foggsy: I mean this (halfway down the page), you can check yourself the details they have by following those instructions.

            • @MiscOzB: Thanks for this. Looks like I'll be getting a new driver's license as well. First email stated that the ID was exposed, this confirmed it.
              Waiting for second email.
              Also have had a Credit Simple account for a number of years, signed up to the alerts.

      • How/where exactly did you check what documents you have listed?

        EDIT: Scratch that, just saw MiscOzB's comment in the replies.

    • +1

      Even better. You're entitled to a free new house! XD

  • +5

    Good news, I didn't think we'd get it in WA tbh

    Hopefully Optus get that second email out quickly…

    • You just had to wait awhile longer than other states.

      • +1

        Yeah just not used to that, normally we're so far ahead of the game in WA /s :P

        • +9

          DoT have been told for years it's a massive risk that the numbers can't be changed. They even put out statements that basically said "nah".

          Then they manage to sort it in 48 hours. Ffs

          • @hotphil: They actually haven't sorted anything out yet. It's just that the Premier has made an announcement.
            If you go to DOT tomorrow you won't be able to get a new number.

  • +3

    i did not even get first email. WTF is going on! phone calls they are not picking. I am new customer and app is not working too.

    • same here I did online chat 3 hours ago still no reply

    • I got my initial email on the 23/09 but wife didn't get one at all.

      Their chat is probably getting slammed at the moment, so i'd expect a massive wait :(

  • Does anyone know if the Optus resellers are also contacting their customers? I assume Optus would not be contacting customers of, say, Moose Mobile?

    Any way to confirm if you are affected as a customer of an Optus reseller?

      • Not entirely:

        We're advising you that GOMO, powered by Optus has been a victim of a cyberattack resulting in the disclosure of your personal information, which is a combination of your name, date of birth, email, phone number and/or account address. No ID document numbers or details have been affected and no financial information or passwords have been accessed. Further information can be found on the Optus website or you can contact us via the GOMO app.

      • For Moose Mobile, it looks like you are correct:

        From their front page https://moosemobile.com.au/

        "NOTICE: Moose Mobile was not affected by the recent Optus cyberattack. We are an Optus wholesaler, but our systems are separate from theirs.
        Optus DO NOT have access to any of your personal or payment information if you are a Moose customer. Moose does not collect any of your personal identification like a driver's license or passport details."

  • Thanks for sharing op! Another state is joining the game. I know NSW said no to this but really hoping they change their mind xD

    • I'm sure Gladys had something to do with it which is why they're not budging

      • -1

        You mean Glad bags on the board of Optus Glad bags?

      • How on earth do you come to that conclusion or is it just some non relevant sarcasm?

  • +15

    I think its great the govt is doing this
    but they shouldnt be free
    should be full price, with the bill being sent to optus directly

    • +5

      with the bill being sent to optus directly

      The WA Government is supposedly seeking reimbursement from Optus for this exercise.

      • Yep Rita says she'll be billing Optus. Too right.

    • +1

      I saw somewhere that some states will be sending the bill to Optus to cover, think it was QLD.

      Edit: looks like both QLD & NSW are charging $29 replacement, but Optus will reimburse.

  • I didn't even receive the first email.

  • +2

    Must provide two forms of ID, i bet they don't take a drivers licence as one of them….lol

    • +3

      Hopefully the fraudsters can get your new licence before you do

  • Same as QLD

  • Phew… im an optus customer but in an unrelated coincidently accidently threw my wallet away that was in the bottom of my KFC bag in my own self disgust. Saved $30!

  • NSW Service is persist in begging the money from Optus victim.

  • "Importantly, no financial information or passwords have been accessed. The information which has been exposed is your name, date of birth, email, phone number, address associated with your former account, and the numbers of the ID documents you provided such as drivers licence number or passport number."

    Is this from first or second email?

    • First. I've only received one email and that's what was in mine.

  • FYI - ACT information is here: https://www.accesscanberra.act.gov.au/s/article/Information-…

    Short answer - you'll get a new license (with a new card number but not a new licence number) if both the licence number and card number have been compromised. Optus will reimburse the $42.60 cost. If only one field is compromised, no new card is required. You can still request a new card (with a new card number but not license number) and pay the $42.60 yourself. Either way - no new license number - it stays with you for life.

    • For WA is the card number the number on the back? And if we've gotten a new card since last using Optus does this mean we don't need to get a new card?

      • WA drivers licences have always kept the same number for you lifetime. This is the first time they're providing new numbers

        • Not if they're stolen, you get a new number. Pretty easy to sort out to be honest if you think it's been compromised.

      • +2

        Yes. They've realised thats not good enough and so will at long last be changing licence and card number for the affected customers, for free. Then sending an f-ing huge invoice to optus for the hassle.

  • -5

    So what's the worst that bad people can do with other people's ID numbers? Empty their bank accounts? And even if they do, surely it's all insurered and protected by their fraud policies.

    • imagine if thieves grab your home keys. even they don't have immediately steal your treasure.

      • -4

        Id numbers are very different to something physical like home keys that unlock physical locks. You can't steal anyone's treasures with just ID numbers, I think most people are just over-reacting over ID theft rather than potential loss of property or funds which is minimal.

    • Not so much stealing out of existing accounts, but they could open up credit cards with debt attributable to you.

      • -6

        That won't work since you need access to physical cards after signup and MFA. They'd have to camp outside your house and check your mailbox everyday lol even if they succeed, you have defence of not knowing thanks to Optus so becomes bank's problem.

        • They can easily set delivery address to a PO box or something. Also its quite difficult being the victim of identity theft.

        • It should be "the bank's problem" but it seems to end up being the individual's problem and many spend years trying to rectify it and recover from it.

        • +1

          Well, just post your name and license number here & a kind soul will show you how it's done.

          • @factor: Why would anyone intentionally reveal their ID because some random on the internet asked for it? lol point remains that no one can clean out someone's bank account with their name and license number, otherwise it would've been well documented and reported.

            Someone on breakfast TV this morning talked about how they kept hearing this 3rd person voices whenever she made calls to Optus in the past which made her suspicious that something was going on at Optus lol

    • lol, google it mate

  • +3

    Be on the look out for phishing scams asking you to provide your new DL number so they can use it alongside your leaked info to defraud.

    Guaranteed this will spike hard.

  • +2

    check this list to see if you are the unlucky one in WA.

    Not sure if it's legit though

    https://www.reddit.com/r/perth/comments/xp7fi5/optus_breach_…

  • +2

    The real question is whether going through this will extend the validity of your DL for free.

  • +2

    If only they'd listened when told dozens of times over the years that it's a massive risk to permanently assign a single number

    • +1

      I can't believe how any of those numpties in charge couldn't foresee this.. even if you were technologically illiterate (which isn't a good sign), it's a massive procedural flaw.

      • +3

        They even went so far as to publicly say they wouldn't be doing it because there was no need. All gasts were flabbered. But have now come back.

        • +2

          Can't facepalm any harder.. "Guys, guys.. that involves additional work.. we need to clock out by 4.29pm.."

  • People from WA couldn’t actually change their licence number. Has this suddenly changed?

    • +2

      It still isn't possible, but this Optus breach has essentially forced the WA Govt's hand to get their act together. They're now working on upgrading their systems to allow for a number change and billing Optus for the trouble.

      • I did read the functionality did exist in some form for DV victims/police and other specialist purposes. But who knows how manual that was.

    • +2

      Yep. They've managed to put something in place that people have been telling them to do for years. In a couple of days.

      Horse/bolt

  • Optus got all my details wrong..so i guess not to worry abt the data breach

    • I've tried to have contracts with them twice over the last few years. Both times they were so utterly incompetent I couldn't take it any more and gave up.

      • I justhad a prepaid service, but never bothered to take any contract with them. Optus coverage is very patchy at my place.
        I tried the links mentioned in the below page n found what details Optus holds about me.
        Login to optus account n then follow the instructions

        https://whirlpool.net.au/wiki/optus_sept_2022_breach

  • From "impossible" to a simple system improvement. Good on the WA gov to make a change happen. Thx

    • +2

      We don't have digital license yet

    • +1

      "simple", I guess you've never worked for/with government agencies.

  • NSW says this now:

    A $29 replacement fee will be charged by Service NSW at the time of application and reimbursement advice will be issued by Optus to customers in the coming days.

    NSW customers who need support regarding the replacement of identity documents and advice on preventative actions they can take, are encouraged to contact ID Support NSW on 1800 001 040.

    Also from ABC news.

  • +9

    This is crazy. License numbers are not secret and should never have been treated as ID. Same for passport numbers.
    It started out that you had to physically show your ID, as something hard to forge, for ID.

    But laziness and stupidity led people to use just the number as ID. How does that make the slightest sense??

    The first time you use your new number, it will no longer be a secret. That is security 101. Without a digital signature, any such code is single-use.
    What we need is a proper cryptographic ID system. Something like Google Authenticator would be a good start, as well as being able to take your physical ID to the local chemist or post office.

    • +2

      I think it was vodafone i used recently and i had to use my phone camera to scan my face so they could match not only the number but my mug too.

      • Interesting. Does this apply to both SIM swap (swapping to a new SIM card within the same provider) and SIM porting (port outs from Vodafone)?

        • That was porting in to post-paid Voda (from Optus)

  • I was with Optus 2010 and changed to Virgin Mobile 2010. I still received email from Optus saying my detail has been compromised. So basically they stored all my detail from 12 years ago. I think Optus has been hacked their entire system but they did not disclosed what their system has been compromised. Good luck everyone.

  • -5

    People panicking for nothing, pretty easy to get all information already from many sources , name addresses from electoral roll unless your silent voter, Facebook social media, any large organisation. Having a drivers license number really isnt going to be used in identity fraud. Your chances are less than 0.1% . Just the media hype. Plenty of large Australian companies have been hacked previously either media was interested or companies pay the scammers as fines are higher and dont want bad pr.

    • +3

      You're massively underplaying that. It was a one stop shop. Millions of records of >100 points of ID. It would only be worse if bank details were scraped too.

      • -2

        Rubbish, ooh on dark Web?.? You realise the dark Web is just website not listed on dns server right? That anyone can access by simply typing in ip address manually? With non typical browser, possible tunnel access it ain't hard to get there it's part of the deep Web with no advertising it's presence.

        Chances are the information you talk about is already available to any would be thief.

        • +1

          Who said anything about dark web?

          And yep, if someone was targeting me they could probably piece together some of that info from other sources. But to have everything, verified, for millions of people in one place is a gift to anyone wanting to do nasty things. Being served the best beef vindaloo you've ever had rather than just being given a basket of ingredients. It's the breath-taking scale of incompetence and data lost that makes it worrisome.

          • @hotphil: Follow the sheep n believe the media hype, im not worried a bit.

            • @Wayne7497: Not a sheep, and not following hype. And living life full of worry is indeed a bad thing. I'm just aware of things going on in my field of expertise.

    • +2

      There are plenty of ways to use the data they've gotten for either identity theft or other form of scam.

      How easy would it be for a scammer to ring you up and make any sorts of claims over the phone and recite your driver's license or passport numbers back to you and you'd absolutely think it was legit.
      Doesn't have to happen today or tomorrow, but it could happens months down the line when this Optus thing is out of the limelight.

      Out of the 9.2m or whatever that are at risk, I'm sure there is a huge number of those that are vulnerable/gullible when it comes to being scammed like this.

      • -2

        Many scams out there already, ppl will be hit usually the vulnerable are elderly non technical types, but this data is honestly available from heaps of places stay vigilant you'll have no problems, have worked in this area of expertise for nearly 40yrs, never seen such a panic hype by the media.

  • -1

    Why are taxpayers paying for this?

    • +5

      They are not. The state government will seeking reimbursement from optus

  • So when are the second emails due out. It's written very clearly in my first email that they got my DL number.

    • +1

      Knowing Optus is in charge of sending the emails out, it’s bound to be a shit show

      • +1

        Can't wait for the "Optus have been trying to contact my dead husband" headlines.

    • +1

      Same, and confirmed with live chat also but guess we’ll have to wait forever for this second email now.

Login or Join to leave a comment