Australian blood donor data breached

The Australian Red Cross Blood Service has apologised after the data of more than half a million donors was accidentally made publicly accessible.

A man gives blood

Source: AAP

Personal details of more than half a million Australians have been publicly available online for almost two months after an accidental leak.

The breach, labelled the country's biggest personal data leak, was revealed by the Australian Red Cross Blood Service on Friday.

The organisation's web developer unintentionally placed a back-up copy of an online inquiry form on an unsecured website in early September.

The data was accessed once this week by a member of the public before the Australian Cyber Emergency Response Team was notified and killed the site on Wednesday.

"It's not something you could Google but it's a website that, when someone is provided with the link, they might be able to access," Red Cross Blood Service spokesman Shaun Inguanzo told AAP on Friday.

The organisation's chief executive Shelly Park apologised unreservedly for the breach, which included names and addresses of donors dating back to 2010.

"I wish to stress that this file does not contain the deep, personal records of people's medical history or their test results," she told reporters in Melbourne.

Cyber security expert Troy Hunt was the person who contacted AusCERT after someone else gave him the data.

"In terms of the numbers of records we've seen from an Australian organisation (more than 1.2 million), there's no data breach I'm aware of that's larger than this," he said.

Mr Hunt and his wife are blood donors, and their names, address, dates of birth, phone numbers and email addresses were included in the leak.

Red Cross Blood Service said its systems were secure and, to their knowledge, all copies of the data had been deleted.

ID Care, Australia and New Zealand's National Identity Support Service, believed the data was at a low risk of future misuse.

Mr Hunt did not believe the person who found it was targeting the Red Cross

The Blood Service is notifying all affected donors, who can also call 13 95 96 or visit info.donateblood.com.au for more information.


Share
2 min read

Published

Source: AAP

Share this with family and friends


Follow SBS Korean

Download our apps
SBS Audio
SBS On Demand

Listen to our podcasts
Independent news and stories connecting you to life in Australia and Korean-speaking Australians.
Ease into the English language and Australian culture. We make learning English convenient, fun and practical.
Get the latest with our exclusive in-language podcasts on your favourite podcast apps.

Watch on SBS
Korean News

Korean News

Watch it onDemand