Latitude Financial has disclosed that a cyber attack and subsequent data breach have affected around 225,000 customers. The breach resulted in unauthorised access to almost 100,000 driver’s licences.
The Australian Securities Exchange placed the financial services company, which provides loans, insurance, and digital payment products, into a trading halt.
The company detected “unusual activity” on its systems, which it believes originated from a major vendor it engages.
According to a [pdf] statement released by the company, before the incident was isolated, the attacker obtained login credentials of Latitude employees, which enabled them to “steal personal information that was held by two other service providers.” Latitude did not disclose the identity of these service providers.
“As of today, Latitude understands that approximately 103,000 identification documents.The company stated that the first service provider had more than 97 percent of the stolen records, with the majority being copies of driver’s licenses.
Latitude also confirmed that the second service provider had approximately 225,000 customer records stolen. However, did not specify the nature of the information contained in those records.
The company assured its customers that it is taking all necessary measures. It will help to contain the incident and prevent further theft of customer data. This includes disabling certain customer-facing internal systems. Additionally, Latitude also revealed that it is collaborating with the Australian Cyber Security Centre. Furthermore, Notifying law enforcement agencies, and engaging the services of several cyber security experts.


