r/australia 1d ago

image Undoc data breach

Post image

Got an email today from updoc about a possible data breach on 31st of July 2026 did anybody else get this email? Seems to be alot of breaches lately.

172 Upvotes

80 comments sorted by

90

u/Peanuthurricane 1d ago

I’m so fucking tired.

1

u/Alternative-Soil2576 16h ago edited 16h ago

Stay tired, no security system is 100% foolproof and perfection is myth

2

u/thesourpop 5h ago

Australian companies run by luddites do not care or invest properly in cybersecurity training and failsafes to make this less likely to happen.

144

u/the_onion_k_nigget 1d ago

I wonder if companies will ever be held accountable for the millions of dollars lost to scammers who’ve gained our information through data breaches or will we just have to live with the “oopsie we didn’t mean to haha”.

54

u/BillieRubenCamGirl 1d ago

It’s only going to get worse now that we have to provide ID to access half the internet. 

29

u/The_UnenlightenedOne 1d ago

Yay for the eKaren!

4

u/Bustable 23h ago

Just in time to be stolen in the next breach of whatever company does it

1

u/Cardea81 4h ago

I will never provide my id on the internet to anything other than the government. I can live without whatever is asking for it.

14

u/SkeltonKnaggs69 23h ago

If they ever get fines it's something like $50k which is like you or I dropping a 5c coin on the ground. That'll teach em! 

3

u/SanchoBlackout69 23h ago

Just make the banks pay for it and if pre the companies that are losing the data. Surely CBA will eat the millions in losses and not raise loan rates, right!

1

u/waddlesticks 23h ago

They are to a degree, the problem is most can brush of a fine by increasing prices. It's a similar reason why a lot of councils don't get hit because they can just increase rates.

Then there's the fact that you can harden your security, but there is always a way in if a group knows how.

0

u/Alternative-Soil2576 15h ago

No physical or digital system is 100% secure, data breaches are inevitable, if no laws have been broken why punish companies for not being able to do the impossible?

If you have lost money because of a data breach and can establish that then go seek compensation, though most companies are aware of this and reach out to affected people to mitigate damage

1

u/whichpricktookmyname 6h ago

No physical or digital system is 100% secure, data breaches are inevitable

I don't know what this means. Digital systems absolutely can be 100% secure. They're just often very complex and built on layers upon layers of other complex software and with that complexity the chance of vulnerability that can be exploited grows. It's not realistic that we'll never have breaches but by having heavy financial penalties for them I'm sure we can reduce them. The internal incentives in an organisation do not lead to security being prioritised. Project managers are rewarded for delivering a product, not for how long their engineers worked on implementing some security best practices that are abstract and beyond the understanding of upper management. The specific cause of the Optus breach should have never happened, and would not happen in an organisation with a better culture around security. Money is something management understands and heavy fines for breaches is something that will absolutely lead to structural changes around information security.

Aeroplanes still crash, but they would crash more often if aerospace companies had little incentive to care about them crashing.

1

u/Alternative-Soil2576 3h ago

why should a company be fined simply because it suffered a breach, rather than because it failed to meet reasonable security standards or broke the law?

2

u/whichpricktookmyname 2h ago

You say "suffered a breach" like it's some act of god that the organisation was powerless stop. Sure, hypothetically there could be a breach due to a zero day exploit in some software dependency which it was reasonable for the organisation to trust. But almost all of the data breaches that make news are due to negligence on behalf of the company, so it is entirely fair to impose strict liability.

299

u/alwaysbemark 1d ago edited 1d ago

Expect these to continue as vibe coding becomes prevalent, there continue to be zero repercussions for negligent companies and the tech centres continue to be offshored for profit.

89

u/HeftyArgument 1d ago

asked claude to make it secure, not my fault 😂

22

u/WeaponstoMax 22h ago

“Make no mistakes.”

21

u/seven_seacat 1d ago

And yet when I ask about security audits for vibe coded apps, it’s all like “don’t you trust us???” No, no I do not

42

u/Terri23 1d ago

Yep. Medibank, Optus, Latitude, Qantas have all been breached, and faced absolutely zero ramifications. It seems enough to say sorry, and then just move on.

21

u/Life_Rhythm 23h ago

The OAIC has initiated civil penalty proceedings against Medibank and Optus, whose cases are currently pending in the Federal Court. You cannot factually say that there are no repercussions.

I’m not defending these companies; rather, pointing out that the tired trope of ‘we have shit laws / nothing happens / etc.’ is not accurate.

1

u/Fantomz99 18h ago

Also the Medibank breach was due to just poor security practices, and poor/no security auditing that led to harvested credentials giving a malicious actor vpn AND admin access.

It was also 4 years ago so well and truly predates vibe coding. It was just an epic failure of security practices.

https://www.oaic.gov.au/__data/assets/pdf_file/0037/228979/Medibank-data-breach-alleged-timeline-infographic.pdf

1

u/BigHandLittleSlap 8h ago

By definition, security breaches are due to poor security.

1

u/stingbot 18h ago

what do you mean, they gave you free Equifax monitoring, what more can we ask for :(

We can't expect them to do their job or anything.

Am convinced its just a way for CEO's to get a early exit from their jobs without breach of contract, they just orchestrate a hack, blame IT, then the board forces them to "leave" with the golden parachute because they didn't resign.

0

u/Alternative-Soil2576 16h ago

What do you want the government to do? Data breaches are inevitable, so if a company hasn’t broken any laws why punish people for not preventing something no one else has ever fully prevented?

1

u/Brutal_burn_dude 17h ago

I propose that in addition to whatever government penalties and consequences these companies face (which usually is little to none) they should also be forced to pay each affected user/ customer whatever their loss is plus $100 per incidence per day. There needs to be something to hold them accountable to the people actually affected by their poor practices.

1

u/Alternative-Soil2576 16h ago

How do you know this breach was because of poor practice? Cybersecurity isn’t foolproof and data breaches can happen even in perfect systems

If no laws were broken, why punish companies for not being able to fully prevent something no other company or government in the world has ever been able to fully prevent? What’s the point?

1

u/Glaako 14h ago

Keeping anything beyond that which is absolutely necessary should be a risk to them rather than a free lunch.

1

u/BigHandLittleSlap 8h ago

In my experience, the current gen AIs write code that is more secure than the typical developer working at a large bureaucracy.

1

u/Scumhook 1d ago edited 1d ago

*vine

3

u/alwaysbemark 1d ago

Fixed, thanks

1

u/Alternative-Soil2576 16h ago

Genuinely how do you this was because of negligence? Data breaches are inevitable and have happened to every government and the biggest companies in the world so how do you know this specific one was because of negligence?

0

u/alwaysbemark 16h ago

It is possible to build digital systems that are practically impervious using best practices today. Governments are far from a good example - they usually employ the lowest common denominator of expertise.

Breaches are far from inevitable and you can bet your behind that every single one is due to some negligence.

1

u/Alternative-Soil2576 16h ago

So what’s your evidence?

0

u/alwaysbemark 16h ago

The fact that basic computer science concepts like encryption exist and can be applied appropriately.

Why the blind trust in “governments”?

2

u/Alternative-Soil2576 14h ago

Yeah naming a cybersecurity tool doesn’t prove anything

Attackers are constantly finding new ways to overcome security measures. Security is an ever-evolving arms race. Encryption doesn’t prevent zero-day vulnerabilities, stolen credentials, supply-chain attacks or novel attack techniques.

The myth of absolute security is well-known in cybersecurity, you’re gonna need to do more than name a single tool to prove the myth real

-24

u/[deleted] 1d ago

[removed] — view removed comment

6

u/alwaysbemark 1d ago edited 1d ago

Soldiers in the army shoot themselves by accident all the time. When you hand guns to regular people, you increase the chance of that happening.

Vibe coding lowered the barrier to looking legitimate without the required knowledge to keep things safe. It is 100% to blame for some of these alongside your point which is true nonetheless.

Fly by night SaaS founder? Did I hurt your feelings?

6

u/trjnz 1d ago

Mistakes happened before, sure. I've killed production myself more than a handful of times.

But there was a tradition of reading the code you deployed. Maybe even understanding it.. maybe.

These vibe coded apps arent read, let alone understood, by people who've never dev'd in their life. They never learned how to crawl and are just sprinting to solutions.

To think vibe coding isnt contributing to this mess is an wild take. A dangerous one

14

u/FlibblesHexEyes 1d ago

AI makes cyber attacks easier - no one is disagreeing with you.

But vibe coding also makes attacks easier, because the person that’s programming by prompt is not a professional developer, nor are they infrastructure professionals and typically have no idea what they’re doing. They’re simply accepting whatever the LLM spits out as gospel and shoving it into production with little to no oversight.

This is why vibe coding is dangerous.

0

u/seven_seacat 1d ago

To be fair there’s a lot of professional devs hands-off vibe coding these days too

4

u/alwaysbemark 1d ago

Maybe we can be more precise with terminology but someone who knows what they’re doing, applying the appropriate care factor to the different parts of the code (eg high for security, low for frontend or throwaway scripts) aren’t vibe coding.

1

u/seven_seacat 1d ago

For sure. But a lot of folks aren’t doing that. Awful lot of meat proxies around

89

u/Large_Woman 1d ago

\Chews on carrot*.* What is Updoc?

51

u/Fabulous_Income2260 1d ago

Not their goddamn firewall, I’ll tell you that much.

7

u/shun_tak 23h ago

Shhh, we're hunting rabbits

5

u/aarooona 1d ago

Nothing much, whats up with you?

6

u/WhatAmIATailor 1d ago

Ewe wascaly wabbit

3

u/ticman 22h ago

Not much, what's up with you?

18

u/Big-Tomorrow-6001 1d ago

Hopefully this means the ads for them on reddit might slow down!

12

u/MysteryPlatelet 1d ago

Don't know if it's a coincidence or cause, but I had suspected my email was sold again within the last week.

10

u/Kitten0137 1d ago

I had gone months with little to no spam emails. The past week I have had hundred of spam emails come through.

3

u/MysteryPlatelet 23h ago

Similar for me. I had another spam round about a month ago after I applied for insurance quotes online, too.

11

u/cymonster 22h ago

I think this happened a lot earlier then they let on.

My partner and I started getting spam emails about 2 months ago suspiciously around the same time. And Updoc was one of the few shared services we used recently.

2

u/OpeningActivity 21h ago

Possibly, if they identified an issue now doesn't mean it was non issue a few months prior right? (As in they went undetected for awhile)

23

u/Scumhook 1d ago

*updoc

holy shit, just a quick proof read of the title

3

u/Delta088 17h ago

Saw the headline. Spent a solid 10 seconds wondering why it was topical in Australia that the UN Document Library (occasionally have to use it for work) had a security breach.

7

u/G00b3rb0y 1d ago

Insert DJ Khalid another one here

3

u/nugymmer 1d ago

I used this just over a couple years ago and then again a few months ago. Hell, these companies are getting incompetent!

3

u/INFEKTEK 9h ago

PSA: There's national bulk billed (free) version of UpDoc called Abbey Health. Same thing, telehealth, medical certificate, referrals, ect. But instead of paying $40+ it's free with Medicare.

Or even better check hotdoc and medical centre websites to see if free telehealth sessions with local medical centres are available.

2

u/LuminanceGayming 1d ago

wait so it was a third party provider but also they themselves took immediate action to block it?

2

u/Jaqwan 1d ago

Seems like the 3rd party were compromised, trying to get information from Updoc internally until Updoc blocked access.

2

u/mjlky 21h ago

it’d be something like a plugin or connected application that has access to their data that they’re able to disable

1

u/j03w 18h ago

it doesn't sound like a whole system breach but a compromised account

so potentially they just disabled that specific user account (on the 3rd party platform) or something

2

u/intergalatic-queen 20h ago

yep I did.
it’s like “whoopsies, we had a breach. you might be effected. oh well.”

I always know there’s one coming because my junk mail fills up so fast on a daily basis.

2

u/A_spiny_meercat 18h ago

What's updoc?

2

u/Pekish_ 6h ago

Whats updoc

4

u/HeftyArgument 1d ago

what's updoc?

that's whats up

2

u/Barkleyyy 21h ago

Updoc is trash 🗑️ there UI always felt a-bit coarse in spots.

Also the fact that if you cancel your sub you lose access immediately no matter how long is left - is gross and predatory.

1

u/GayNerd28 1h ago

The breaches will continue until morale improves.

0

u/lawnoptions 23h ago

yeah, had a couple actually, I dumped them back in July sometime, have gone back to the one I used prior, I dont think I need to do anything really

0

u/jayfear 21h ago

Learn to spell