Sydney University & iiNet Cyber Breaches: What Businesses Must Learn

Show Links

In this episode of the Don’t Be A Sitting Duck Podcast, we explore two recent and impactful Australian cyber incidents — the University of Sydney data breach and the iiNet customer data exposure. We explain how attackers gained access, what kinds of data were compromised, and most importantly, share actionable advice for businesses to reduce their risk of similar breaches.

Major Stories Covered

  • University of Sydney cyberattack: Personal data of current and former staff, students and alumni accessed via a code library.
  • iiNet cyber breach: Contact details and account information from ~280,000 customers exposed through stolen employee credentials.

Key Takeaways

  • Legacy systems and forgotten data repositories can be prime targets — don’t ignore them.
  • Stolen credentials are often all a cybercriminal needs to begin a breach.
  • Multi-factor authentication and strong access controls are essential.
  • Staff training on credential security and phishing awareness is critical.

Sources & Further Reading

Episode Transcript

Hackers have struck at well-known Australian organisations again, reminding us all that no one is immune. In recent weeks, cyber attackers infiltrated the University of Sydney’s IT systems, exposing tens of thousands of personal records from staff, alumni and students. Around the same time last year, major internet provider iiNet confirmed a breach that put hundreds of thousands of customer contact details into the hands of unauthorised third parties. Today’s episode will break down exactly what happened in each case, how these attacks unfolded, what they mean for organisations of every size, and most importantly, what you can do to protect your business from going down the same path. Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford—let’s dive in.

University of Sydney has disclosed a cyberattack that exposed personal information stored in an internal online code library. Hackers accessed historical data files that contained names, dates of birth, phone numbers, addresses and other employment details for staff, former employees and alumni going back over a decade.

Here’s how it happened and why it matters. The attackers found their way into a system used for code storage and development — a place many organisations assume is less attractive to criminals. Unfortunately, it also contained a trove of personal data. Once inside, the hackers were able to download those files before the breach was detected. University leaders have reported the incident to the relevant privacy and cybersecurity authorities and are monitoring for any misuse, but this serves as a stark reminder that even legacy systems or development environments can be a weak link if not properly segmented and secured.

Take action:

For businesses of any size:

  • make sure you inventory all your systems — including development repositories, archived databases, and forgotten data stores.
  • Apply strong access controls with multi-factor authentication everywhere, and ensure sensitive data isn’t stored in locations not protected to the highest standard.
  • Regularly audit who has access and why, and monitor for unusual behaviour around any systems containing personal information.

Next, let’s talk about iiNet — a major Australian internet service provider that confirmed a cyberincident in August that exposed the contact details of around 280,000 customers. This included active and inactive email addresses, landline phone numbers, street addresses, usernames and even some modem set-up passwords. No financial or government ID numbers were involved, but the data is still valuable for targeted scams and phishing.

In this case, attackers gained entry using stolen employee credentials to access an order management system. Credential theft remains one of the most common entry points for breaches because once a bad actor has a legitimate login, they can often move through systems unnoticed. That’s why this breach is so instructive — it shows that cyberattacks often begin not with sophisticated zero-day vulnerabilities, but with simple credential misuse.

Take action:

  • Make sure your business has robust password policies, implements multi-factor authentication across all services, and trains staff on recognising phishing attempts that could harvest credentials.
  • Regularly rotate access keys, disable accounts immediately when an employee leaves, and use tools that can alert you to credential compromise before an attacker has a chance to leverage it.

That’s a wrap for today’s episode! Want more cybersecurity insights? Head over to sittingduck.com.au for show notes, resources, and the latest updates. Thinking about your business security? Here’s what to do next: Book your free Empower Systems Assessment to uncover vulnerabilities and learn how to strengthen your defences. Listen to my audiobook, Sitting Duck – The Phone Call You Don’t Want to Receive—a real-world look at Business Email Compromise. Available now on Spotify and leading audiobook platforms.

Until next time—stay safe, stay informed, and don’t be a sitting duck!

This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.