RingCentral Data Breach 2026: What Businesses Should Do

In late July 2026 the extortion group ShinyHunters announced that it had taken 623GB of data from RingCentral and demanded payment. RingCentral disclosed the incident the next day, said it had been caused by a sophisticated social engineering campaign, said the core platform was not affected, and declined to pay. The group then published a 280GB archive, and on 13 August the breach notification service Have I Been Pwned loaded 1.6 million unique email addresses from it, along with names, phone numbers and physical addresses. That is the whole of the confirmed story, and on its face it sounds contained: no passwords reported, no payment cards reported, no call recordings, no outage. The problem is what that kind of list is for. A breach at a communications provider does not mainly hurt the provider. It hands attackers an accurate map of who uses which phone platform, who to call, and what to say when they do, and the group responsible has spent the last eighteen months proving that a convincing phone call is the most reliable way into a company. For Australian businesses the incident matters in two ways. Some are RingCentral customers directly or through the Optus Loop migration, and should assume they will be targeted. Everyone else should treat it as the clearest recent demonstration that the phone line has become the front door for serious intrusions, and check whether their own door is locked.

Security · Incident Analysis 2026

Your Phone Provider Was Breached. Here Is What Actually Changes.

In July 2026 RingCentral, one of the largest cloud phone providers in the world, confirmed that an extortion group had taken customer contact data after a social engineering attack. About 1.6 million records ended up on a leak site. No calls were intercepted and the platform kept running, which is why a lot of coverage treated it as a minor event. It is not minor for the people on that list, because a name, a work number, an email address and a street address attached to "this business uses RingCentral" is exactly the raw material for the next attack. This is what is known, what is only claimed, and what to do about it whether or not you were affected.

📅 ⏱ 18 min read 🇦🇺 Australian owned, Australian hosted, Australian supported
TL;DR

What is confirmed: RingCentral disclosed on 28 July 2026 that a social engineering attack in July exposed customer data. Have I Been Pwned verified 1.6 million unique email addresses with names, phone numbers and physical addresses. RingCentral says the core platform was not affected and it did not pay the ransom. What is claimed: ShinyHunters says it took 623GB and published 280GB. What is not known: the exact technique used to get in. Why it matters: contact data from a phone provider is the ideal kit for targeted vishing, provider impersonation, invoice fraud and number porting attacks. What to do: verify through a number you already hold, never through the one that called you; move admin accounts to phishing-resistant MFA; lock number porting; audit call forwarding and admin access; and brief staff this week. If personal information you hold was involved, the Notifiable Data Breaches scheme may apply to you, not just to the provider.

What Is Actually Known

The sequence is short and well documented, and it is worth getting exactly right because a lot of secondhand coverage has blurred it.

DateEventSource
July 2026Attackers gain access to RingCentral systems through what the company calls a sophisticated social engineering campaign.RingCentral notice
27 JulyShinyHunters claims the breach on its leak site, says it holds 623GB of data, and demands payment.Attacker claim, reported by security press
28 JulyRingCentral publicly discloses the incident, says it stopped the unauthorised activity, has engaged a third party forensic firm, and that the core platform and services were not affected.RingCentral notice
Early AugustRingCentral does not pay. ShinyHunters publishes a 280GB compressed archive.Attacker leak site, reported by security press
13 AugustHave I Been Pwned adds the breach: 1.6 million unique email addresses, with names, phone numbers and physical addresses.Independent verification

RingCentral's own description is that the incident affected "a limited portion" of its customers and that it has been contacting the people involved directly. It has also said it has seen no further unauthorised activity since containing the incident. Those statements are consistent with what has been independently verified: a large volume of customer contact records, not a compromise of the phone service itself.

That distinction matters, and it cuts both ways. Nobody's calls were being listened to and no business lost its phones. But "only contact data" is also the phrase that tends to make people stop paying attention, and that is exactly the wrong reaction to this particular kind of list.

Confirmed, Claimed and Unknown

Extortion groups exaggerate, because a bigger number puts more pressure on the victim. Companies minimise, because they have lawyers. The honest way to read any breach is to sort every statement into one of three columns and act on the first one while planning for the second.

ConfirmedClaimed by the attackersNot disclosed
A social engineering attack in July 2026.623GB taken in total.The specific technique: phone call, help desk impersonation, a malicious app authorisation, or something else.
About 1.6 million unique email addresses, with names, phone numbers and physical addresses, verified by Have I Been Pwned.A 280GB archive published, and that it represents part of a larger haul.Which internal system held the data, and whether it was a RingCentral system or a third party platform RingCentral uses.
RingCentral says the core platform was not affected and services ran without disruption.Anything the group says about what else is in the unpublished portion.How many of the records relate to Australian businesses or individuals. Nothing published so far says.
RingCentral did not pay and engaged a forensic firm.The final findings of that forensic investigation.
Why we are careful about the entry method

A lot of commentary has assumed RingCentral was breached the same way as other ShinyHunters victims, through a voice phishing call that tricked an employee into approving access to a customer relationship management system. That is plausible given the group's history, and it may turn out to be right. It has not been confirmed, and we are not going to state it as fact. What matters for your defences is the same either way: the attack targeted people, not software, and the defences that work are the ones that do not rely on a person spotting a lie in real time.

The Campaign Behind It

RingCentral was not a one-off. The group operating under the ShinyHunters name has been responsible for one of the most sustained data theft campaigns of the last two years, and its method is consistent enough that it is worth understanding in some detail.

2025: the CRM wave. From mid 2025 the group phoned employees at large organisations, posed as internal IT support, and talked them through authorising what looked like a legitimate data export tool for their Salesforce environment. It was an attacker controlled application. Once approved, it had broad access to customer records and did not need a password or a second factor again, because the employee had granted it a standing token. Salesforce itself was not breached; its customers' staff were persuaded to open the door. Qantas was among the victims in July 2025, with data on around 5.7 million customers taken from a third party platform used by one of its contact centres. Google, Allianz Life and several luxury brands were hit the same way.

Late 2025 into 2026: the single sign-on wave. The method moved up a level. Callers posed as help desk staff, told employees their multi-factor authentication needed updating, and walked them onto convincing copies of their company's single sign-on page while the attacker relayed the login and the one-time code to the real site in real time. Security firms counted more than a hundred organisations targeted by January 2026. Okta published warnings about custom phishing kits built for exactly this. ADT confirmed a breach in April 2026 after an extortion demand from the group, and McKesson disclosed an incident involving voice phishing and stolen single sign-on credentials.

The common thread is that none of this required a software vulnerability. It required a phone, a plausible script, some research on the target, and a second factor that could be relayed. Every successful step depended on an employee believing a caller.

The most effective intrusion technique of 2025 and 2026 was a phone call. That is an uncomfortable fact for anyone who runs a phone system, and it is why a breach at a phone provider is worth more attention than its data classes suggest. The list that was stolen is the list of people this group, or anyone who buys the archive, will call next.

Why Contact Details Are Not Nothing

Here is what a single record in a leak like this typically gives an attacker, and what each field is used for.

FieldWhat it lets an attacker do
NameOpen a call or email with the person's name, which immediately lifts trust. Search LinkedIn for their role and manager.
Work emailTarget a phishing email precisely, and confirm the company's email format for everyone else there.
Phone numberCall or text directly. For a mobile, it is also the key to a SIM swap or port-out attempt.
Physical addressAnswer "can you confirm your address" style security questions, and add credibility to an invoice or delivery pretext.
The fact they are a customer of this providerThe field nobody lists and the most valuable one. It tells the attacker exactly which company to impersonate.

That last row is the point. A generic scam call claiming to be "your phone company" fails most of the time because most people know it is a guess. A call that says "this is RingCentral account security, we are contacting affected customers about the July incident, I can see your account is registered to Sarah at 14 Smith Street" is a completely different proposition. It is accurate, it refers to a real event the person may have read about, and it arrives with an apparently legitimate reason to ask for verification. Breach follow-up calls work precisely because the breach was real.

There is also a second-order effect. Once one leak is public, it gets combined with others. The Qantas data, the Optus and Medibank breaches from 2022, and years of smaller leaks already mean many Australians have their details circulating. Each new list adds a field or confirms a current one. The RingCentral data adds something few other leaks have: a verified link between a person and the platform that carries their business calls.

Five Attacks a Leaked List Enables

These are the five we would expect to see against anyone on the list, roughly in order of likelihood.

1. The provider impersonation call. "We are calling about the security incident. To protect your account we need to verify you and reset your admin access." The goal is either the admin login for your phone portal or a one-time code that lets the caller reset it. With admin access to a business phone system an attacker can forward your main number, read voicemail, pull call recordings, add users and run up call charges.

2. The help desk pretext against your staff. The attacker calls one of your employees posing as your IT provider or your phone provider, citing the breach as the reason, and walks them through "re-enrolling" their authenticator on a fake login page. This is the single sign-on technique described above, pointed at your business instead of at RingCentral.

3. The invoice or bank detail change. An email arrives from what appears to be your phone provider's billing team: following the incident, payment details have changed, please update. The address matches, the account name matches, the amount matches your usual bill. Payment redirection fraud is one of the most costly scams reported to Australian authorities for businesses, and a list of real customers with real addresses is exactly what makes it convincing.

4. The port-out or SIM swap. With a name, a mobile number and an address, an attacker can attempt to move a mobile number to a SIM they control. Australian mobile carriers have been required since 2020 to perform additional identity verification before a mobile number is ported, usually a one-time code sent to the existing service, which has cut this sharply. It has not eliminated it, because the verification step itself can be socially engineered: the victim is called and asked to read out the code "to confirm their identity". If the stolen number is the one that receives your banking or admin codes, a successful port gives the attacker all of them.

5. The data enrichment step nobody sees. Not every use is immediate. Many buyers of leaked data simply add it to larger datasets and use it months later. Expect the effect of this list to show up well into 2027, which is why a one-off reminder to staff is not enough.

If this sounds familiar, it is the same playbook we described in our guide to voice cloning and vishing, with one addition: the caller now has genuine data to anchor the lie. Synthetic voices make the call sound right. A breach list makes the details right.

If You Use RingCentral or Optus Loop

RingCentral has said it is contacting affected customers directly. That is the right thing to do, and it also creates a problem: the genuine notification and the fake follow-up will look similar. Some practical points.

Check exposure without clicking anything. Go directly to haveibeenpwned.com in a browser you trust and enter the email addresses your business uses with the provider, especially the admin and billing contacts. Do not use a link from any email about the breach, including ones that look genuine. If you manage a domain, Have I Been Pwned also offers domain level searches after you verify ownership.

Treat inbound contact about the incident as untrusted by default. If RingCentral or anyone claiming to be RingCentral calls, hang up and ring back through the number in your account portal or on your last invoice. A genuine provider will never object to this. A scammer always will, usually with urgency.

Optus Loop customers. Optus announced in March 2024 that RingCentral would power its cloud communications for Australian businesses, and many Optus Loop customers have been moved, or are being moved, to the RingCentral-built platform. Nothing published about this incident says Optus customers were among the affected records, and we are not suggesting they were. But if your business is mid-migration, you are already expecting calls and emails about account changes, logins and new portals from both companies, which is exactly the environment in which a fake one is hardest to spot. Be especially strict about verifying any request that arrives during the migration window. Our Optus Loop migration guide covers the change itself.

A fake breach notification is a known follow-up attack

After large breaches it is common to see waves of emails and texts pretending to be the breach notification, offering "identity protection" or "account verification" behind a link. If you receive any message about the RingCentral incident that asks you to click, log in, call a number in the message, or confirm details, treat it as hostile until you have verified it through a channel you already had before the message arrived.

Ten Things to Do This Week

These apply whether or not you are a RingCentral customer. Most take minutes. The first five are the ones that stop real losses.

#ActionWhy
1Write down a callback rule and tell everyone. Any request to change access, payment details or phone configuration is verified by calling back on a number you already hold.This single rule defeats most of the five attacks above, because the attacker controls the inbound call and not your outbound one.
2Move phone system admin accounts to phishing-resistant MFA: a passkey or a hardware security key.Codes by SMS or authenticator app can be relayed by a live caller. Passkeys cannot, because they only work on the real site.
3Ask your mobile carrier to add a port-out and SIM change lock to business mobiles, especially any that receive admin or banking codes.It adds a step an attacker holding only a name, number and address cannot complete.
4Confirm supplier bank details by phone before paying any invoice where the details changed.Payment redirection is the most direct way a leaked customer list becomes cash.
5Brief staff with the actual script they are likely to hear, not a generic warning.People recognise a script they have heard before. They do not recognise "be alert to phishing".
6Review who has admin rights on your phone system and remove anyone who no longer needs them.Fewer admin accounts is fewer targets.
7Check call forwarding rules on main numbers and key users for anything unexpected.Silent forwarding to an attacker's number is a quiet way to intercept verification calls.
8Turn on login alerts and audit logs in your phone portal if they are not already on.You want to know about a new admin login the same day, not at the end of the month.
9Check international calling and premium number barring are set the way you want.Toll fraud is still how compromised phone accounts are most often monetised.
10Check whether any personal information your business holds was in the exposed data, and if so, start a breach assessment.The notification obligations may be yours as well as your provider's. See below.

Controls That Actually Stop Vishing

Security awareness training is worth doing, but it is not a control. A person having a busy afternoon, speaking to a polite caller who knows their name and refers to a real news story, will get it wrong sometimes. The controls that work are the ones that still hold when somebody does.

🔑

Phishing-resistant MFA

Passkeys and FIDO2 hardware keys are tied to the genuine website address. If an employee is talked onto a fake login page, the key simply does not respond. This is the control that broke the relay technique used throughout the ShinyHunters single sign-on campaign.

📞

Callback verification

Every sensitive request is confirmed on a number you already hold. It costs a minute and it moves control of the conversation from the attacker to you. Write it into policy so staff are never in the position of having to be rude.

🧾

App consent controls

Stop ordinary users from authorising new third party applications against your CRM, email or file storage without an administrator approving them. This is the exact step the 2025 Salesforce wave relied on.

🔒

Help desk identity rules

Whoever resets passwords or MFA, internal IT or an outsourced provider, needs a verification procedure that does not rely on information a breach could supply. Name, address and phone number all fail that test now.

The Australian Signals Directorate's Essential Eight has moved in the same direction, with phishing-resistant MFA expected at the higher maturity levels. For a small business the practical version is simple: every account that can change your phone system, your email, your banking or your domain should use a passkey or a hardware key, and nobody should be able to approve access for a new app on their own.

On the phone system itself, look for per-user and admin audit logs, alerts on new admin logins and forwarding changes, the ability to restrict admin access, and barring of international and premium destinations by default. Our older but still relevant guide to VoIP security and phone system fraud covers the toll fraud side in detail, and how AI improves business security covers what automated call screening can and cannot catch.

Questions to Ask Any Phone Provider

No provider can promise it will never be breached, and you should be wary of one that does. What you can assess is how they reduce the chance, limit the damage, and tell you when something goes wrong.

QuestionWhat a good answer sounds like
Where is my account and contact data held, and by whom?A clear list of systems and countries, including third party platforms like CRM and support desks. Customer data leaks from support tools as often as from the core platform.
How do your support staff verify me before making changes?Something beyond name, address and phone number, such as a PIN, a portal-initiated request, or a callback to a registered contact.
How would you contact me about an incident, and how do I verify it is you?A defined channel, and a clear statement that they will never ask for passwords, codes or payment changes in a breach notice.
Does the admin portal support passkeys or hardware keys?Yes, and the option to require them for all admins.
What audit logs and alerts can I see?Logins, admin changes, forwarding changes and new devices, exportable, with alerts you can route to email.
How do you handle number port-out requests?Authorisation checks against the account holder, notification to the registered contact, and a way to add a port lock.
Who can your staff reach, and from where?Access to customer data restricted by role, logged, and ideally held and supported in Australia.
What happened last time?A provider willing to talk plainly about past incidents and what changed is more trustworthy than one that says it has never had one.

If you are comparing platforms at the moment, our comparison of RingCentral, 8x8 and Aircall alternatives looks at the commercial and support differences. We would add one thing to any comparison after this year: ask where the support tools and customer records live, not just where the calls are processed. The 2025 and 2026 campaigns went after customer records and the people who could reach them.

Your Own Privacy Act Obligations

Most businesses read a supplier's breach as the supplier's problem. Under Australian privacy law that is not always true.

The Notifiable Data Breaches scheme applies to organisations covered by the Privacy Act, which includes businesses with annual turnover above $3 million and some smaller ones, such as health service providers. If personal information you hold is involved in a breach that is likely to cause serious harm, and you cannot prevent that harm through remedial action, you must notify the affected individuals and the Office of the Australian Information Commissioner. If you only suspect a breach, you must take reasonable steps to assess it within 30 days.

For a provider incident like this one, the question to ask is whether any of the exposed data was personal information your business was responsible for, for example the details of your own staff or of customers held in an account with the provider. If it was, the provider's notification does not automatically discharge your obligation. In most supplier incidents the organisations involved coordinate so that a single notification goes out, but you need to confirm that is happening rather than assume it.

The small business exemption still exists, for now

As at writing, most businesses under the $3 million threshold are still exempt from the Privacy Act, although removal of the exemption has been agreed in principle by the government and remains on the reform agenda. Even exempt businesses carry reputational and contractual exposure if customer data they hold leaks, and many have contracts with larger clients that require breach notification regardless. From 10 December 2026, covered businesses also have new disclosure obligations about substantially automated decisions, covered in our automated decisions guide.

Two practical steps regardless of size. Keep a short record of what you checked and when, so that if a customer asks, or a regulator does, you can show you assessed it. And look at what personal information you actually keep in your phone system: call recordings, voicemail, transcripts, contact directories and SMS threads are personal information, and the less of it you hold beyond what you need, the less there is to lose. Our coverage of the Origin Energy breach earlier this year goes through the same obligations from a different angle.

Is Cloud Still the Safer Choice?

Some businesses will read this and wonder whether an office phone system in a cupboard would have been safer. For almost everyone the answer is no, and it is worth being precise about why.

The RingCentral incident did not involve the phone platform being compromised. It involved customer records, taken by persuading a person. An on-premises system does not remove that risk, because you still have a supplier with your account records and a support desk that can be phoned. What it does add is the set of risks that cloud providers largely remove: unpatched firmware exposed to the internet, default passwords, no audit logs, and toll fraud that runs all weekend because nobody is watching. Older on-premises systems are consistently among the most common sources of phone fraud losses for small businesses.

The better lesson is narrower. Security of a phone service now depends as much on the provider's people and support processes as on its network. Ask about both.

RiskOld on-premises PBXWell run cloud platform
Social engineering of support staffPresent, through the installer or maintainerPresent, through the provider
Unpatched software exposed to the internetCommonPatched centrally
Toll fraud through weak passwordsCommon, often unnoticed for daysMonitored and barred by default on good platforms
Audit logs and login alertsRareStandard
Phishing-resistant MFA on admin accessUsually impossibleAvailable on good platforms

How We Approach This

We are a phone provider, so everything above applies to us too, and we would rather say that than pretend otherwise. What we can tell you is how we are set up.

Uniden Voice over Cloud is Australian owned, and your calls, recordings and account data are hosted in Australia and supported by an Australian team. Support staff verify account holders before making configuration changes, and requests to change admin access, forwarding or numbers are confirmed through registered contacts rather than on the strength of an inbound call. The admin portal keeps audit logs of logins and changes, and international and premium destinations can be barred by default. We will never ask you for a password, a one-time code or a change of bank details in a phone call or an incident notice, and if anyone claiming to be us does, hang up and ring 1300 881 662.

If you would like a second pair of eyes on your current setup, whoever it is with, we are happy to go through the checklist above with you: admin access, MFA, forwarding, barring, porting locks and what your provider holds about you. It usually takes half an hour and it is the most useful half hour most businesses will spend on phone security this year.

Check your phone system's front door

Talk to an Australian team about admin access, MFA, call forwarding, number porting and what your provider holds about you. No obligation, and it applies whichever provider you use today.

Get Started Or call 1300 881 662

Frequently Asked Questions

What happened in the RingCentral data breach?
In July 2026 attackers gained access to RingCentral systems through what the company described as a sophisticated social engineering campaign. The extortion group ShinyHunters claimed the breach on 27 July, said it had taken 623GB of data and demanded payment. RingCentral disclosed the incident publicly on 28 July, said it had stopped the unauthorised activity, engaged a third party forensic firm, and that its core platform and services were not affected. It did not pay, and the group then published a 280GB compressed archive. On 13 August the breach notification service Have I Been Pwned added the breach after verifying about 1.6 million unique email addresses, accompanied by names, phone numbers and physical addresses. RingCentral has described the incident as affecting a limited portion of its customers and has said it is contacting affected people directly. The exact social engineering technique used to gain access has not been disclosed. Commentary linking it to the voice phishing methods ShinyHunters used against other organisations in 2025 and 2026 is plausible but unconfirmed, so it should be treated as speculation until RingCentral or its investigators say otherwise.
Were RingCentral phone calls or recordings exposed?
Nothing confirmed so far indicates that. RingCentral has said the incident did not affect its core platform and that services continued without disruption, and the data classes verified by Have I Been Pwned are email addresses, names, phone numbers and physical addresses. Passwords, payment card details, call recordings and message content have not been reported as part of the verified data. The attackers have claimed a larger total haul of 623GB than the 280GB they published, and extortion groups routinely exaggerate, so the honest position is that the published and verified data is contact information and anything beyond that is unproven. That does not make the breach harmless. Contact data from a communications provider is especially useful to attackers, because it tells them exactly which company to impersonate when they call you, and gives them accurate personal details to make that call convincing. The practical risk from this breach is the follow-up phone calls, emails and texts, not interception of past calls.
How do I know if my business was affected by the RingCentral breach?
RingCentral has said it is contacting affected customers directly. You can also check independently by going to haveibeenpwned.com in a browser you trust, typing the address yourself rather than following any link, and entering the email addresses your business uses with the provider, particularly admin and billing contacts. If you control your own email domain, Have I Been Pwned offers a domain search once you verify ownership, which shows every address on that domain found in known breaches. Be careful with any email, text or call that claims to be a breach notification. Fake notifications are a common follow-up attack after large incidents, and they usually ask you to click a link, log in, call a number in the message or confirm details. A genuine provider will be happy for you to hang up and ring back on the number in your account portal or on your last invoice. If anyone claiming to be RingCentral objects to that, treat the contact as hostile. Nothing published so far says how many affected records relate to Australian businesses.
Are Optus Loop customers affected by the RingCentral breach?
Nothing published about the incident says Optus Loop customers were among the affected records, and there is no basis to assume they were. The connection is that Optus announced in March 2024 that RingCentral would power its cloud communications for Australian businesses, and many Optus Loop customers have been or are being moved onto the RingCentral-built platform. The practical concern is timing rather than exposure. A business in the middle of that migration is already expecting emails and calls about new portals, logins and account changes from both Optus and RingCentral, and that is exactly the environment in which a fake message is hardest to spot. If you are mid-migration, apply a strict rule: verify every request involving logins, codes, payment details or phone configuration by calling back on a number you already hold, such as one on an existing invoice or in your current portal, and never on a number supplied in the message itself. If you are reviewing whether to stay through the migration at all, that is a commercial decision worth making on its own merits.
What is ShinyHunters?
ShinyHunters is the name used by an extortion group, or a loose collection of actors, responsible for a long run of large data thefts. In its recent campaigns it has relied on social engineering rather than software vulnerabilities. From mid 2025 it phoned employees at large organisations while posing as IT support and persuaded them to authorise an attacker controlled data export application against their Salesforce environments, which gave standing access to customer records without needing a password again. Qantas was among the victims in July 2025, with data on about 5.7 million customers taken from a third party platform used by one of its contact centres, alongside organisations such as Google and Allianz Life. From late 2025 the group moved to voice phishing against single sign-on accounts, calling staff as help desk workers and walking them through fake login pages while relaying their credentials and one-time codes to the real site. Security firms counted more than a hundred organisations targeted by January 2026, and ADT and McKesson disclosed incidents in 2026. The group typically demands payment and publishes data when victims refuse, as happened with RingCentral.
What should a business do after its phone provider has a data breach?
Start with the controls that stop real losses, most of which take minutes. Adopt a written callback rule: any request to change access, payment details or phone configuration is verified by ringing back on a number you already hold, never on the number that called you. Move every admin account for your phone system, email, banking and domain to phishing-resistant multi-factor authentication, meaning a passkey or hardware security key, because codes sent by SMS or shown in an authenticator app can be relayed by a live caller. Ask your mobile carrier to add port-out and SIM change protection to business mobiles, especially any that receive admin or banking codes. Confirm supplier bank details by phone before paying any invoice whose details changed. Brief staff with the specific script they are likely to hear. Then tidy up: remove unneeded admin accounts on the phone system, check call forwarding for anything unexpected, turn on login alerts and audit logs, confirm international and premium number barring, and check whether personal information you are responsible for was involved, in which case you may have your own obligations under the Notifiable Data Breaches scheme.
Does a supplier's data breach create Privacy Act obligations for my business?
It can. The Notifiable Data Breaches scheme applies to organisations covered by the Privacy Act, which includes businesses with annual turnover above $3 million and some smaller ones such as health service providers. If personal information your business holds is involved in a breach likely to cause serious harm, and remedial action cannot prevent that harm, you must notify affected individuals and the Office of the Australian Information Commissioner, and where you only suspect a breach you must take reasonable steps to assess it within 30 days. When the breach happens at a supplier, the question is whether any exposed data was personal information you were responsible for, such as details of your staff or customers held in your account with that supplier. The supplier notifying people does not automatically discharge your obligation, although in practice the organisations involved usually coordinate a single notification. Confirm that is happening rather than assume it, and keep a brief record of what you checked and when. Most businesses under the $3 million threshold are still exempt as at writing, though removal of that exemption remains on the reform agenda.

What to Read Next

Your next reads

Australia’s smartest AI-powered cloud phone system. Australian owned, Australian hosted, Australian supported. unidenvoice.com | 1300 881 662