Login | Register
Profile | Log out
logo

  • Home
  • News
  • Opinion
  • Other
    • Market Updates
    • Explainers
    • Satire
  • About
  • Contact Us
    • Contact
    • Get Covered
    • Posting Guidelines
  • Subscribe
Submit An Article

Latest Articles

  • Stakk Secures T-Mobile Contract to Power Super App Expansion
    Stakk Secures T-Mobile Contract to Power Super App Expansion
    • News

  • Medibank Backs Emyria with Landmark Depression Care Deal
    Medibank Backs Emyria with Landmark Depression Care Deal
    • News

  • NoviqTech Launches Quantum Intelligence Products, Opening Path to Enterprise-Grade Quantum AI
    NoviqTech Launches Quantum Intelligence Products, Opening Path to Enterprise-Grade Quantum AI
    • News

  • BRE Wins Final Permit to Advance Rare Earth Pilot Plant in Brazil
    BRE Wins Final Permit to Advance Rare Earth Pilot Plant in Brazil
    • News

  • Harris Technology eyes profitability as refurbished tech sales surge
    Harris Technology eyes profitability as refurbished tech sales surge
    • News

  • QIC Fund Backs Ark Mines with $4.5m to Accelerate Sandy Mitchell Development
    • News

  • Swift Secures $2.4m Chevron Contract to Extend Entertainment and Support Services
    Swift Secures $2.4m Chevron Contract to Extend Entertainment and Support Services
    • News

  • FBR’s tech could help reduce housing construction-related cost pressures
    FBR’s tech could help reduce housing construction-related cost pressures
    • News

  • Atomo Locks in US$410K Pascal Order as FebriDx Demand Accelerates in the US
    Atomo Locks in US$410K Pascal Order as FebriDx Demand Accelerates in the US
    • News

  • June 2025 quarter CPI no roadblock to August RBA rate cut
    June 2025 quarter CPI no roadblock to August RBA rate cut
    • News

Latitude refuses to pay ransom demand, 14 million customers with stolen data in limbo

  • In News
  • April 11, 2023
  • Clara Venisha
Latitude refuses to pay ransom demand, 14 million customers with stolen data in limbo

A vicious cycle that no one can seem to break free of once they are looped in, we have seen how ransomware shattered Medibank last year. Refusing to pay, it ended up having to lifelessly see the hackers releasing private customer medical records to the dark web. Unfortunately, history has repeated itself, this time upon Latitude Financial’s (ASX: LFS) recent cyber attack. After the personal data of its 14 million current and past customers were stolen in March, the financial services provider announced that the criminals have demanded ransom.

In the same vein as its predecessor, Latitude insists that it will not pay a ransom as there’s no guarantee that paying a ransom will result in the return or destruction of the information that was stolen, as advised by cybercrime experts in line with the Australian Government. Instead, paying a ransom will be detrimental to the customers and cause harm to the broader community by encouraging further criminal attacks.

A consumer lender which offers personal loans and credit to customers shopping at retailers such as JB Hi-Fi, The Good Guys and Harvey Norman, Latitude first disclosed it was hacked on 16 March 2023. The breach was thought to only include around 328,000 customer records. However, the number has grown to hit 14 million after the Company provided an update on 27 March 2023, stating that 7.9 million Australian and New Zealand drivers licence numbers were stolen together with further 6.1 million records dating back to 2005. 

The stolen data the attackers have detailed as part of the threat is consistent with the number of affected customers disclosed by Latitude in the announcement dated 27 March 2023, which includes drivers licences, passport numbers, and financial statements. The ransom threat is currently under investigation by the Australian Federal Police.

Latitude did not disclose how much the ransom demand is, or whether it has been actively communicating with the hackers. It claimed to have not detected any hacker activity on its systems since 16 March which was the first day that the data breach had been discovered.

Latitude CEO Bob Belan commented, “Our priority remains on contacting every customer whose personal information was compromised and to support them through this process.”

“In parallel, our teams have been focused on safely restoring our IT systems, bringing staffing levels back to full capacity, enhancing security protections and returning to normal operations. I apologise personally and sincerely for the distress that this cyber-attack has caused and I hope that in time we are able to earn back the confidence of our customers.”

As damage control, Latitude claimed that it is currently offering support to affected individuals through a fully operating comprehensive customer care and remediation program. However, several customers have expressed disappointment in the lack of communication from the Company. Many are furious and frustrated as they haven’t heard anything other than a very generic initial email, while others are comparing the situation to how Optus and Medibank have previously managed to set up better systems and procedures to help affected customers. 

Customers also questioned Latitude’s data retention procedures, expressing concerns upon discovering that their private information was being held by the company for several years when the Company confirmed that the stolen personal information is dated back to 2005. Latitude Financial itself was established in 2015, when GE Capital sold its business in Australia and New Zealand to a consortium led by Deutsche Bank, KKR and Varde Partners. Customer data acquired prior to the business sale was then transferred to the current Latitude. 

Meanwhile, the Australian Securities & Investments Commission (ASIC) requires companies to keep records for seven years.

In communication with affected customers, Latitude has hinted the source of the attack may have started from a major vendor used by the company, which would probably be a back-end infrastructure provider. The Company took immediate action in response to unusual activity on its systems but the attacker was able to steal a Latitude employee login credentials which was then used to steal customer records from two of Latitude’s service providers.

Latitude has not clarified what it means by service providers.

As a consumer lender, Latitude offers a variety of credit options including personal loans, car loans, credit cards, and insurance, therefore requiring many identification documents as a credit-checking procedure for new customers. Documents used in credit checks often contain unique identifiers that can open a customer up to identity theft.

One of the largest-known data breaches on an Australian financial institution, the future is still bleak for Latitude as they have chosen not to pay the ransom. Comparatively, Medibank ended up losing $2 billion from its market valuation at the height of the crisis last year. It still faces lawsuits and an investigation by the Office of the Australian Information Commissioner over its handling of the incident.

Cybersecurity expert at the University of New South Wales, Professor Richard Buckland observed that the similarities between the Latitude and Medibank cyber hacks reflect the cracks in security procedures that need to be urgently corrected in the Australian cyber security sphere, especially since even big businesses are not immune from data breaches. 

Professor Buckland told the ABC, “I think what we’re seeing here is there is a pattern that companies aren’t properly securing their businesses no matter what their external assurances are, and we’re still seeing the same mistakes happening even after big public disclosures of the consequences of getting it wrong.”

  • About
  • Latest Posts
Clara Venisha
Clara is a Business Reporter for The Sentiment.
Latest posts by Clara Venisha (see all)
  • IPO Watch: The Australian Wealth Advisory Group set for ASX entrance - December 15, 2023
  • Harris Technology gears up for Christmas as consumer electronics and household tipped to be among most popular purchases - November 27, 2023
  • Linius Technologies sprints into the US college sports with automated game highlight technology - November 23, 2023
  •  
  •  
  •  
  •  
  • asx lfs
  • corporate hacking
  • cybersecutiry
  • data breach
  • hacking
  • Latitude Financial
  • richard buckland
  • News

Leave a Comment

You must be logged in to post a comment.

  • About
  • Latest Posts
Clara Venisha
Clara is a Business Reporter for The Sentiment.
Latest posts by Clara Venisha (see all)
  • IPO Watch: The Australian Wealth Advisory Group set for ASX entrance - December 15, 2023
  • Harris Technology gears up for Christmas as consumer electronics and household tipped to be among most popular purchases - November 27, 2023
  • Linius Technologies sprints into the US college sports with automated game highlight technology - November 23, 2023

Login or register for free to access unlimited reading

Register Now!
  • About
  • Latest Posts
Clara Venisha
Clara is a Business Reporter for The Sentiment.
Latest posts by Clara Venisha (see all)
  • IPO Watch: The Australian Wealth Advisory Group set for ASX entrance - December 15, 2023
  • Harris Technology gears up for Christmas as consumer electronics and household tipped to be among most popular purchases - November 27, 2023
  • Linius Technologies sprints into the US college sports with automated game highlight technology - November 23, 2023
  • News

  • Opinion

  • Satire

  • About

  • Contact Us

  • Subscribe

The content published on this website is solely for general information purposes and is not to be construed as financial advice. Should you seek financial advice you should consult with an appropriately qualified person. Opinions expressed on this site are subject to change without notice and The Sentiment who produced this content is under no obligation to keep the information current. The Sentiment, affiliated companies & associates may have a conflict of interest with companies discussed on the website due to commercial arrangements, for example they may be shareholders in the company, be engaged by them to assist in investor communications or receive commission/brokerage for funds raised.

Copyright © 2020 The Sentiment. All rights reserved.
Subscribe

Enter your email address below to subscribe to The Sentiment’s weekly newsletter, highlighting the top news, research, opinion and satire articles shaping ASX investor sentiment.

The Sentiment respects your privacy and will not spam you. View our privacy policy here.