Cyber Incident at Insurer Prosura: Customer Data Compromised
Summary
Australian and New Zealand insurer Prosura (also trading as Hiccup) has suffered a cyber breach, resulting in unauthorized access to customer personal data. A threat actor is directly contacting affected customers, threatening to leak the data. The company has suspended new policy sales and its online portal while investigating.
Key Points
- Breach Details: Unauthorized access was identified on Saturday. Compromised data may include names, email addresses, phone numbers, residency, travel details, invoices, policy dates, and claim data (including driver’s licenses).
- Threat Actor Communication: A self-described threat actor is emailing customers, claiming responsibility for the New Year’s Day breach and demanding the company contact them to “sort” the issue, or they will leak all data.
- Company Response: Prosura states credit card details were not accessed or stored. Policies remain unaffected. An urgent system review and additional security measures are underway. Authorities have been notified.
- Customer Impact: Customers linked to the rental comparison site VroomVroomVroom are affected. Some have received fraudulent emails referencing old policies. The exact number of impacted customers is undisclosed.
- Broader Context: This incident follows several major cyber attacks in Australia over the past three years, including breaches at Optus, HWL Ebsworth, and Qantas.
保险公司Prosura遭遇网络攻击:客户数据泄露
摘要
澳大利亚和新西兰保险公司Prosura(亦以Hiccup名称运营)遭遇网络攻击,导致客户个人数据因系统未授权访问而泄露。一名威胁行为者正在直接联系受影响的客户,威胁要公开数据。公司已暂停新保单销售和在线门户网站,并展开调查。
关键点
- 泄露细节:上周六发现未授权访问。泄露数据可能包括姓名、电子邮件地址、电话号码、居住国、旅行目的地、发票、保单起止日期以及索赔数据(含驾照信息)。
- 威胁行为者联系:一名自称威胁行为者的人正在向客户发送电子邮件,声称对元旦发生的入侵负责,并要求公司与其联系以”解决”问题,否则将泄露所有数据。
- 公司回应:Prosura表示信用卡详细信息未被访问或存储。现有保单不受影响。正在进行紧急系统审查并实施额外安全措施。已通知相关部门。
- 客户影响:通过租车比价网站VroomVroomVroom购买保险的客户受到影响。部分客户收到了涉及旧保单的欺诈性邮件。受影响客户的具体数量未披露。
- 背景信息:此次事件是过去三年来澳大利亚发生的多起重大网络攻击中的最新一起,此前Optus、HWL Ebsworth律师事务所和澳航均发生过数据泄露。
Original Article Link: https://www.abc.net.au/news/2026-01-07/car-excess-insurer-prosura-hit-by-cyber-breach-customer-data/106204198