Optus A.I CyberSecurity Scoring
Optus
Company Information
Website:http://www.optus.com.au
Employees number:11,105
Number of followers:173,339
NAICS:517
Industry Type:Telecommunications
Homepage:optus.com.au
Optus Risk Score (AI oriented)
Between 550 and 599
OptusTelecommunications
Updated:
10/08/2026
10/08/2026
573/1000
Very Poor
Ca
Optus Global Score (TPRM)
xxxx
OptusTelecommunications
Score locked

OptusVery Poor
Current Score
573Ca (VERY POOR)
01000
5 incidents
-82.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
678
Ransomware
10 Aug 2026 • Optus
Medibank and Optus: Cyber extortion 101: To pay (a ransom), or not to pay (a ransom) – that is the question
Ransomware Surge in Australia: Legal Risks and Regulatory Pitfalls
573
CRITICAL-105
MEDOPT1786343034
Ransomware Surge in Australia: Legal Risks, Regulatory Pitfalls, and Why Paying Isn’t the Answer
Nearly 100 Australian organizations have fallen victim to ransomware attacks this year, with many more likely unreported. The dilemma of whether to pay ransoms often demanded to prevent data leaks has become a critical issue for businesses, compounded by strict legal and regulatory consequences.
Under Australian law, paying a ransom to sanctioned entities, including groups like LockBit or those linked to the Iranian Revolutionary Guard Corps (IRGC), is illegal. Businesses face severe penalties, including federal money-laundering charges, even if they claim ignorance. Phoebe Chester, Practice Leader at LegalVision, emphasizes that paying ransoms not only funds criminal activity but also fails to guarantee data security, marking organizations as repeat targets.
The Australian Signals Directorate (ASD) advises against payment, urging instead a focus on prevention robust cybersecurity measures and tested backups to avoid negotiation with attackers. In the event of an attack, the first 24 hours are critical. Organizations must isolate affected systems without destroying forensic evidence, avoid unauthorized contact with threat actors, and consult legal and IT experts. Cyber insurers should be notified, and incidents reported to the Australian Cyber Security Hotline. Premature public statements or customer notifications risk regulatory backlash while facts remain unclear.
Refusing to pay does not exempt businesses from legal obligations. Under the Privacy Act, organizations must assess breaches, notify the Office of the Australian Information Commissioner (OAIC), and inform affected individuals within 30 days, regardless of ransom decisions. Failure to comply can result in penalties up to $50 million, three times the value of any benefit obtained, or 30% of adjusted turnover. Reputational damage is also a concern, with public sentiment increasingly critical of mishandled responses, as seen in high-profile breaches like Optus and Medibank.
The biggest misstep, according to Chester, is treating ransomware as an IT issue rather than a legal and regulatory crisis. Downplaying breaches before facts are verified or failing to document board-level decisions can attract scrutiny over director duties. Early legal involvement and transparent, well-documented responses are essential to mitigating risks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
737
Breach
23 Jul 2026 • Optus
Qantas, Medibank and Optus: Hack React: What the Origin Energy hack means for Australian consumers and businesses
Rising Threats to Australia’s Energy Sector and Critical Infrastructure
677
CRITICAL-60
OPTMEDQAN1784773430
Cybersecurity Alert: Rising Threats to Australia’s Energy Sector and Critical Infrastructure
Australia’s energy and utilities sector is facing escalating cyber threats, with attackers increasingly targeting these industries for both data theft and operational disruption. Experts warn that breaches in IT systems can quickly spread to operational technology (OT) environments where attacks could destabilize power grids and critical services relied upon by millions.
The potential consequences extend beyond financial or reputational damage. While a data breach erodes customer trust, an OT compromise risks widespread societal disruption, making robust defenses essential. Australian energy providers and critical infrastructure operators must proactively prepare for both scenarios to safeguard essential services.
As investigations into recent incidents continue, cybersecurity leaders emphasize that preparation cannot wait until an attack occurs. Organizations need documented incident-response plans, regularly tested and updated, with clearly defined roles for containment, evidence preservation, and communication. Rapid, transparent responses distinguishing confirmed facts from ongoing investigations are critical to minimizing harm.
This latest incident follows a string of high-profile Australian breaches, including those at Optus, Medibank, and Qantas, where attackers exploited personal data for phishing and identity fraud. Even non-financial details like names, addresses, and dates of birth can be weaponized, underscoring the value of all customer data to cybercriminals. Recent data from WatchGuard Threat Lab recorded over 96,000 network attacks blocked against Australian organizations in a single quarter last year, highlighting the sustained pressure from malicious actors.
Healthcare and critical infrastructure remain prime targets due to the sensitive nature of the data they hold. The challenge for organizations lies in balancing swift action with accurate verification, as both underestimating and overstating an incident can have severe consequences. With Australia remaining a high-value target, early detection and strong network visibility are key to preventing data compromise.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
736
MAY 2026
734
APRIL 2026
734
MARCH 2026
733
FEBRUARY 2026
732
JANUARY 2026
731
DECEMBER 2025
729
NOVEMBER 2025
729
OCTOBER 2025
728
SEPTEMBER 2025
727
SEPTEMBER 2022
694
Cyber Attack
01 Sep 2022 • Optus
Optus
Data Breach at Optus
667
CRITICAL-27
OPT2353111122
Hackers have breached Optus’ systems.
They accessed names, dates of birth, phone numbers, email addresses, physical addresses and driver’s licence numbers of millions of the telecommunications giant’s customers.
Up to 9 million customers had been affected.
Many had their contact details exposed to the hackers, who also pilfered even more sensitive details, such as passport and drivers’ licence numbers, for a smaller portion of Optus customers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2022
775
Breach
16 Jun 2022 • Optus
Optus
Optus Data Breach (2022) and Rising Cyber Threats in Financial Services (2025)
690
CRITICAL-85
OPT1862118091225
In August 2025, Australia’s privacy regulator filed a landmark lawsuit against Optus over a 2022 data breach that exposed the personal information of 9.5 million customers. The breach, one of the largest in Australian history, involved unauthorized access to sensitive customer data, including names, dates of birth, phone numbers, email addresses, and in some cases, government-issued identification numbers (e.g., driver’s license or passport details). The potential regulatory fines could reach A$2.2 million per affected individual, totaling a catastrophic financial penalty exceeding A$20 billion if applied at maximum scale.The incident underscored systemic vulnerabilities in third-party data handling, particularly in highly regulated sectors like financial services and telecommunications. The breach not only triggered massive reputational damage but also led to a surge in fraudulent activities targeting affected customers, including identity theft and phishing scams. Optus faced intense scrutiny from regulators, lawmakers, and the public, with the case setting a precedent for stricter enforcement of data protection laws in Australia. The fallout also accelerated industry-wide shifts toward localized, no-retention software solutions to mitigate similar risks in the future.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2000
776
Breach
16 Jun 2000 • Optus
Optus
Extortion Attempt by Unemployed Individual
718
CRITICAL-58
OPT2318111122
Dennis Su, 19, texted 93 of the telco's customers, demanding they transfer $2000 to a CBA bank account
He threatened them for exposing personal information being used for financial crimes.
He was having a difficult time being unemployed and wanted to make some quick money.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Optus ??
What was Optus's A.I Rankiteo Cyber Score in July 2026 ??
What was Optus's A.I Rankiteo Cyber Score in June 2026 ??
What was Optus's A.I Rankiteo Cyber Score in May 2026 ??
What was Optus's A.I Rankiteo Cyber Score in April 2026 ??
What was Optus's A.I Rankiteo Cyber Score in March 2026 ??
What was Optus's A.I Rankiteo Cyber Score in February 2026 ??
What was Optus's A.I Rankiteo Cyber Score in January 2026 ??
What was Optus's A.I Rankiteo Cyber Score in December 2025 ??
What was Optus's A.I Rankiteo Cyber Score in November 2025 ??
What was Optus's A.I Rankiteo Cyber Score in October 2025 ??
What was Optus's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Optus's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Optus ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Optus's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?