The fallout from a data breach affecting a Brisbane-based telemarketing firm continues to widen as more charities confirm their exposure to the incident. Pareto Phone, the telemarketing firm serving the not-for-profit sector, suffered a breach in April. While not all of its 70-plus clients were initially impacted, the list of affected organizations has expanded.
Amnesty International Australia (AIA) is the latest large charity to confirm its exposure. AIA shared a timeline of the incident, noting that it was informed about unauthorized access to Pareto Phone’s systems in April. Initially, AIA was assured by Pareto that donor data had not been compromised. However, subsequent investigations revealed that some supporter data was indeed involved, although limited to basic details and contact information.
Data stolen included names, physical addresses, emails, mobile numbers, and dates of birth. Fortunately, financial information was not accessed. Other affected charities, like Médecins Sans Frontières and the Australian Conservation Foundation, also reported exposure to historical data, with some incidents dating back to 2012-2015.
The breach has led several charities to reevaluate their relationships with Pareto Phone, with some suspending their engagement with the company. The incident underscores the risks associated with third-party service providers and the importance of data security in maintaining donor trust.

