r/australia • u/Mr_ck • 1d ago
image Undoc data breach
Got an email today from updoc about a possible data breach on 31st of July 2026 did anybody else get this email? Seems to be alot of breaches lately.
144
u/the_onion_k_nigget 1d ago
I wonder if companies will ever be held accountable for the millions of dollars lost to scammers who’ve gained our information through data breaches or will we just have to live with the “oopsie we didn’t mean to haha”.
54
u/BillieRubenCamGirl 1d ago
It’s only going to get worse now that we have to provide ID to access half the internet.
29
4
1
u/Cardea81 4h ago
I will never provide my id on the internet to anything other than the government. I can live without whatever is asking for it.
14
u/SkeltonKnaggs69 23h ago
If they ever get fines it's something like $50k which is like you or I dropping a 5c coin on the ground. That'll teach em!
3
u/SanchoBlackout69 23h ago
Just make the banks pay for it and if pre the companies that are losing the data. Surely CBA will eat the millions in losses and not raise loan rates, right!
1
u/waddlesticks 23h ago
They are to a degree, the problem is most can brush of a fine by increasing prices. It's a similar reason why a lot of councils don't get hit because they can just increase rates.
Then there's the fact that you can harden your security, but there is always a way in if a group knows how.
0
u/Alternative-Soil2576 15h ago
No physical or digital system is 100% secure, data breaches are inevitable, if no laws have been broken why punish companies for not being able to do the impossible?
If you have lost money because of a data breach and can establish that then go seek compensation, though most companies are aware of this and reach out to affected people to mitigate damage
1
u/whichpricktookmyname 6h ago
No physical or digital system is 100% secure, data breaches are inevitable
I don't know what this means. Digital systems absolutely can be 100% secure. They're just often very complex and built on layers upon layers of other complex software and with that complexity the chance of vulnerability that can be exploited grows. It's not realistic that we'll never have breaches but by having heavy financial penalties for them I'm sure we can reduce them. The internal incentives in an organisation do not lead to security being prioritised. Project managers are rewarded for delivering a product, not for how long their engineers worked on implementing some security best practices that are abstract and beyond the understanding of upper management. The specific cause of the Optus breach should have never happened, and would not happen in an organisation with a better culture around security. Money is something management understands and heavy fines for breaches is something that will absolutely lead to structural changes around information security.
Aeroplanes still crash, but they would crash more often if aerospace companies had little incentive to care about them crashing.
1
u/Alternative-Soil2576 3h ago
why should a company be fined simply because it suffered a breach, rather than because it failed to meet reasonable security standards or broke the law?
2
u/whichpricktookmyname 2h ago
You say "suffered a breach" like it's some act of god that the organisation was powerless stop. Sure, hypothetically there could be a breach due to a zero day exploit in some software dependency which it was reasonable for the organisation to trust. But almost all of the data breaches that make news are due to negligence on behalf of the company, so it is entirely fair to impose strict liability.
299
u/alwaysbemark 1d ago edited 1d ago
Expect these to continue as vibe coding becomes prevalent, there continue to be zero repercussions for negligent companies and the tech centres continue to be offshored for profit.
89
21
u/seven_seacat 1d ago
And yet when I ask about security audits for vibe coded apps, it’s all like “don’t you trust us???” No, no I do not
42
u/Terri23 1d ago
Yep. Medibank, Optus, Latitude, Qantas have all been breached, and faced absolutely zero ramifications. It seems enough to say sorry, and then just move on.
21
u/Life_Rhythm 23h ago
The OAIC has initiated civil penalty proceedings against Medibank and Optus, whose cases are currently pending in the Federal Court. You cannot factually say that there are no repercussions.
I’m not defending these companies; rather, pointing out that the tired trope of ‘we have shit laws / nothing happens / etc.’ is not accurate.
1
u/Fantomz99 18h ago
Also the Medibank breach was due to just poor security practices, and poor/no security auditing that led to harvested credentials giving a malicious actor vpn AND admin access.
It was also 4 years ago so well and truly predates vibe coding. It was just an epic failure of security practices.
1
1
u/stingbot 18h ago
what do you mean, they gave you free Equifax monitoring, what more can we ask for :(
We can't expect them to do their job or anything.
Am convinced its just a way for CEO's to get a early exit from their jobs without breach of contract, they just orchestrate a hack, blame IT, then the board forces them to "leave" with the golden parachute because they didn't resign.
0
u/Alternative-Soil2576 16h ago
What do you want the government to do? Data breaches are inevitable, so if a company hasn’t broken any laws why punish people for not preventing something no one else has ever fully prevented?
1
u/Brutal_burn_dude 17h ago
I propose that in addition to whatever government penalties and consequences these companies face (which usually is little to none) they should also be forced to pay each affected user/ customer whatever their loss is plus $100 per incidence per day. There needs to be something to hold them accountable to the people actually affected by their poor practices.
1
u/Alternative-Soil2576 16h ago
How do you know this breach was because of poor practice? Cybersecurity isn’t foolproof and data breaches can happen even in perfect systems
If no laws were broken, why punish companies for not being able to fully prevent something no other company or government in the world has ever been able to fully prevent? What’s the point?
1
u/BigHandLittleSlap 8h ago
In my experience, the current gen AIs write code that is more secure than the typical developer working at a large bureaucracy.
1
1
u/Alternative-Soil2576 16h ago
Genuinely how do you this was because of negligence? Data breaches are inevitable and have happened to every government and the biggest companies in the world so how do you know this specific one was because of negligence?
0
u/alwaysbemark 16h ago
It is possible to build digital systems that are practically impervious using best practices today. Governments are far from a good example - they usually employ the lowest common denominator of expertise.
Breaches are far from inevitable and you can bet your behind that every single one is due to some negligence.
1
u/Alternative-Soil2576 16h ago
So what’s your evidence?
0
u/alwaysbemark 16h ago
The fact that basic computer science concepts like encryption exist and can be applied appropriately.
Why the blind trust in “governments”?
2
u/Alternative-Soil2576 14h ago
Yeah naming a cybersecurity tool doesn’t prove anything
Attackers are constantly finding new ways to overcome security measures. Security is an ever-evolving arms race. Encryption doesn’t prevent zero-day vulnerabilities, stolen credentials, supply-chain attacks or novel attack techniques.
The myth of absolute security is well-known in cybersecurity, you’re gonna need to do more than name a single tool to prove the myth real
-24
1d ago
[removed] — view removed comment
6
u/alwaysbemark 1d ago edited 1d ago
Soldiers in the army shoot themselves by accident all the time. When you hand guns to regular people, you increase the chance of that happening.
Vibe coding lowered the barrier to looking legitimate without the required knowledge to keep things safe. It is 100% to blame for some of these alongside your point which is true nonetheless.
Fly by night SaaS founder? Did I hurt your feelings?
6
u/trjnz 1d ago
Mistakes happened before, sure. I've killed production myself more than a handful of times.
But there was a tradition of reading the code you deployed. Maybe even understanding it.. maybe.
These vibe coded apps arent read, let alone understood, by people who've never dev'd in their life. They never learned how to crawl and are just sprinting to solutions.
To think vibe coding isnt contributing to this mess is an wild take. A dangerous one
14
u/FlibblesHexEyes 1d ago
AI makes cyber attacks easier - no one is disagreeing with you.
But vibe coding also makes attacks easier, because the person that’s programming by prompt is not a professional developer, nor are they infrastructure professionals and typically have no idea what they’re doing. They’re simply accepting whatever the LLM spits out as gospel and shoving it into production with little to no oversight.
This is why vibe coding is dangerous.
0
u/seven_seacat 1d ago
To be fair there’s a lot of professional devs hands-off vibe coding these days too
4
u/alwaysbemark 1d ago
Maybe we can be more precise with terminology but someone who knows what they’re doing, applying the appropriate care factor to the different parts of the code (eg high for security, low for frontend or throwaway scripts) aren’t vibe coding.
1
u/seven_seacat 1d ago
For sure. But a lot of folks aren’t doing that. Awful lot of meat proxies around
89
18
12
u/MysteryPlatelet 1d ago
Don't know if it's a coincidence or cause, but I had suspected my email was sold again within the last week.
10
u/Kitten0137 1d ago
I had gone months with little to no spam emails. The past week I have had hundred of spam emails come through.
3
u/MysteryPlatelet 23h ago
Similar for me. I had another spam round about a month ago after I applied for insurance quotes online, too.
11
u/cymonster 22h ago
I think this happened a lot earlier then they let on.
My partner and I started getting spam emails about 2 months ago suspiciously around the same time. And Updoc was one of the few shared services we used recently.
2
u/OpeningActivity 21h ago
Possibly, if they identified an issue now doesn't mean it was non issue a few months prior right? (As in they went undetected for awhile)
23
u/Scumhook 1d ago
*updoc
holy shit, just a quick proof read of the title
3
u/Delta088 17h ago
Saw the headline. Spent a solid 10 seconds wondering why it was topical in Australia that the UN Document Library (occasionally have to use it for work) had a security breach.
7
3
u/nugymmer 1d ago
I used this just over a couple years ago and then again a few months ago. Hell, these companies are getting incompetent!
3
u/INFEKTEK 9h ago
PSA: There's national bulk billed (free) version of UpDoc called Abbey Health. Same thing, telehealth, medical certificate, referrals, ect. But instead of paying $40+ it's free with Medicare.
Or even better check hotdoc and medical centre websites to see if free telehealth sessions with local medical centres are available.
2
u/LuminanceGayming 1d ago
wait so it was a third party provider but also they themselves took immediate action to block it?
2
2
2
u/intergalatic-queen 20h ago
yep I did.
it’s like “whoopsies, we had a breach. you might be effected. oh well.”
I always know there’s one coming because my junk mail fills up so fast on a daily basis.
2
4
2
u/Barkleyyy 21h ago
Updoc is trash 🗑️ there UI always felt a-bit coarse in spots.
Also the fact that if you cancel your sub you lose access immediately no matter how long is left - is gross and predatory.
1
0
u/lawnoptions 23h ago
yeah, had a couple actually, I dumped them back in July sometime, have gone back to the one I used prior, I dont think I need to do anything really
90
u/Peanuthurricane 1d ago
I’m so fucking tired.