NSW AI Data Breach & Dodo Hack: What Every Business Should Learn

Show Links

In this episode we explore two recent and significant cyber incidents in Australia—one involving the misuse of an AI platform by a government-contractor and the other a telco hack leading to SIM swaps. Both highlight gaps that businesses of all sizes need to pay attention to as digital tools and identity vectors multiply.

  • NSW flood-recovery program data uploaded to ChatGPT. A government contractor uploaded thousands of records to an unauthorised AI tool.
  • Telco Dodo / Vocus hack and SIM-swap fraud. Email accounts compromised at a telco, leading to SIM swaps on mobile accounts.

These stories emphasise the rising risk from novel platforms (AI) and legacy systems (email/SMS) as part of business cybersecurity strategy.

Key Takeaways

    • Unauthorised use of AI tools can expose sensitive data; organisations must have governance and controls.

    • Telecom and identity vectors (like SIM swaps) remain a major threat channel even as attackers chase newer technologies.

    • Contractors and third-party providers are often the weakest link—include them in your security planning.

    • MFA and strong authentication technologies matter more than ever.

    • Regularly review data flows, platforms in use, and system dependencies in the context of new tool-set adoption.

Sources & Further Reading

What To Do Next

  • Book your free Empower Systems Assessmentnationalpc.com.au/empower

  • Listen to my audiobook: Sitting Duck – The Phone Call You Don’t Want to Receive → Available now on Spotify and leading audiobook platforms

  • Subscribe to the Don’t Be A Sitting Duck Podcast for daily insights

Episode Transcript

Imagine vulnerable flood-recovery applicants handing over mountains of deeply personal information… and that data being uploaded into an unsecured AI platform. Then imagine a telco where hackers gain access to email systems, swap SIMs and disrupt mobile service. Two very different incidents—but both ring the same alarm: your business data, your systems, your processes are only as secure as your weakest link.

Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford—let’s dive in.

The NSW Reconstruction Authority (RA) says that between 12 and 15 March 2025 a former contractor uploaded a Microsoft Excel spreadsheet containing more than 12,000 rows of data relating to applicants of the Northern Rivers Resilient Homes Program into the AI tool ChatGPT. Up to 3,000 individuals may have been impacted.

The risk here was not a classic cyber-hack, but misuse of a contractor’s access and a platform (ChatGPT) that was not authorised for handling sensitive personal data. The spreadsheet included names, addresses, email addresses, phone numbers, health-related details and financial commentary (though no banking or TFN numbers confirmed).

Because the data ended up in an AI environment, there is a risk (though currently unproven) that the information could be accessed indirectly, used in prompts, or leaked. The incident underscores how AI tools introduce new vectors of risk—especially when governance over who can upload what is weak.

Take Action:

  • Audit and enforce a policy on the use of AI tools: Who can upload data? What kind of data?
  • Ensure third-party contractors and temporary staff are included in training and contracts, especially about data use and AI.
  • Segment sensitive data, ensure that only authorised systems are used, block uploads to unauthorised platforms.
  • Monitor for abnormal data flows: Large spreadsheets, bulk uploads, external tools being used.
  • Educate staff about the risks of “just uploading” because it’s convenient—it may introduce compliance, legal and reputational risks.

Australian telco Dodo (and its parent Vocus) reported that roughly 1,600 email accounts were accessed via unauthorised access. This led to 34 SIM swaps on Dodo Mobile accounts. Services (email) were temporarily suspended to contain the situation.

Hackers were able to access email accounts, then exploit phone number assignments via SIM swaps. When you own someone’s phone number, you can intercept multi-factor authentication (MFA) texts or calls, reset passwords, access accounts. Telcos are high-risk because they are identity hubs for customers and hold control over key authentication factors. A breach here cascades. The incident also highlights that even “smaller” access (1,600 accounts) can result in high-impact outcomes (SIM swaps, identity compromise).

Take Action:

  • Ensure your staff and privileged users use robust MFA—not SMS-based alone but app-based or hardware tokens.
  • Ensure your vendor/partner telecom provider is meeting strong identity-verification standards.
  • Monitor for unusual SIM activity: Unexpected phone number changes, loss of service, repeated password resets.
  • Apply the “assume breach” mindset: If your staff email is compromised, what’s the impact on internal systems, finance, vendor portals?
  • Consider cyber-insurance or breach readiness for identity/telecom vector exposures.

That’s a wrap for today’s episode! Want more cybersecurity insights? Head over to sittingduck.com.au for show notes, resources, and the latest updates. Thinking about your business security? Here’s what to do next: Book your free Empower Systems Assessment to uncover vulnerabilities and learn how to strengthen your defences. Listen to my audiobook, Sitting Duck – The Phone Call You Don’t Want to Receive—a real-world look at Business Email Compromise. Available now on Spotify and leading audiobook platforms.

Until next time—stay safe, stay informed, and don’t be a sitting duck!

This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.