https://www.googletagmanager.com/ns.html?id=GTM-PT942DL

iiNet Cyberattack Exposes Customer Data

Australian internet provider iiNet, part of TPG Telecom, has confirmed a cyberattack that exposed personal details of thousands of its customers. The breach, revealed in August 2025, occurred when attackers gained access to the company’s systems using stolen employee credentials. 

The exposed data came from iiNet’s order management system and includes: 

  • Approximately 280,000 email addresses 
  • Around 20,000 landline phone numbers 
  • About 10,000 usernames, street addresses and mobile phone numbers 
  • Roughly 1,700 modem setup passwords 

Financial information, including credit cards and bank details, as well as identity documents such as driver’s licences and passports, were not affected. 

The attackers reportedly exploited employee login credentials to access sensitive customer data. iiNet has blocked the unauthorised access and launched an investigation with the help of external cybersecurity experts. Authorities involved include the Australian Cyber Security Centre, the National Office of Cyber Security, and the Office of the Australian Information Commissioner. 

Customers affected by the breach are being contacted and advised on steps to protect themselves. iiNet has also reassured unaffected customers that their data remains secure. 

Even when financial information is safe, exposure of contact details, addresses, and login credentials can leave customers vulnerable to phishing and identity impersonation. iiNet’s breach serves as a reminder of the risks posed by stolen credentials and inadequate access controls. 

At Qamba, we see this as a clear example of why digital security must extend beyond technology to include employee training, secure access management, and rapid incident response. Protecting personal data requires vigilance at every level, from businesses to end users.

More Articles