NewsBite

Aussie real estate agency Harcourts reveals names, addresses possibly compromised in cyber attack

An Australian real estate agency has revealed the simple mistake that led to hackers exposing the names and addresses of tenants.

A tenth of Optus customers leave after the data breach

A leading Australian real estate agency has revealed the simple mistake that led to tenants’ names and addresses being exposed in a cyber attack.

Harcourts Real Estate confirmed its Melbourne City franchisee had fallen victim to hackers after the rental property database was accessed by a third party last month.

In an internal email sent to customers, the franchisee confirmed the confidential information of tenants, landlords, and businesses may have been exposed.

Harcourts Real Estate said they were confident no other personal information had been affected.
Harcourts Real Estate said they were confident no other personal information had been affected.

A Harcourts spokesman said the property database was used by the franchisee’s service provider, Stafflink, to provide administrative support.

“In this particular instance the rental property database was used by a representative of Stafflink and accessed by an unknown third party,” the spokesman said.

“We understand the unauthorised access occurred because the representative of Stafflink was using their own device for work purposes rather than a company-issued (and more secure) device.

Harcourts is currently undertaking a comprehensive external investigation with cyber security experts.”

It is not known how many people were impacted by the breach.

An email from Harcourts management said the company had suffered a cyber attack in October, potentially exposing the names, addresses and phone numbers of tenants.
An email from Harcourts management said the company had suffered a cyber attack in October, potentially exposing the names, addresses and phone numbers of tenants.

Harcourts Australia CEO Adrian Knowles issued a statement apologising for the incident.

“Dealing with this incident is our top priority, we are working together with the franchisee to ensure that all impacted individuals are advised of the incident,” he said.

“In addition, we are in the process of establishing complimentary credit monitoring and access to the IDCARE support service for impacted individuals.”

Mr Knowles said the Privacy Commissioner had been notified of the breach and a review of the company’s systems and processes was also underway.

In an internal email, seen by NCA NewsWire, Harcourts’ Melbourne City branch explained they became aware on October 24 that an “unknown third party” had accessed their rental property database without permission.

Snippets of the email Harcourts sent explaining details of the cyber attack in October, with an explanation of what might have been exposed.
Snippets of the email Harcourts sent explaining details of the cyber attack in October, with an explanation of what might have been exposed.

The email explained the full legal names, email addresses, addresses, phone numbers, and signatures of tenants were potentially visible.

The bank details of rental providers, landlords, and trades may also have been detectable.

“We are confident that no other personal information was affected,” the email read.

Harcourts explained they had suspended the compromised account and had added new layers of protection to its outgoing EFP payments, data and security settings.

Strict access controls and password policies were also put in place.

Harcourts reassured the email recipients that the network accounts and information were now secure.
Harcourts reassured the email recipients that the network accounts and information were now secure.

The company urged recipients to be aware of any suspicious activity in their online accounts and beware of potential phishing scams.

In September, hackers made off with the information of 10 million current and former customers of telco giant Optus, before dumping the information of 10,0000 customers and bizarrely apologising for the theft.

Health care giant Medibank said criminals had allegedly stolen up to 200GB of data in late October.

Originally published as Aussie real estate agency Harcourts reveals names, addresses possibly compromised in cyber attack

Original URL: https://www.couriermail.com.au/technology/online/real-estate-agency-harcourts-reveals-names-addresses-possibly-compromised-in-cyber-attack/news-story/339e9bff70acf16ea12b734a4b024499