🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇦🇺 AU › Telco
Telco sector · leaderboard
Own the Telco leaderboard
The top banner across the Telco overview and every Telco record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

iiNet (TPG Telecom)

🇦🇺 Australia · iiNet — TPG Telecom · Record AU-2025-0288
○ Reported — awaiting official confirmation
Reported — awaiting official confirmation. The facts below are drawn from the organisation's own disclosure and credible reporting. Figures are as reported; unknowns are labelled, not estimated by us.
People affected
280,000 (approx)
Breach date
2025-08
Regulator
OAIC (notified)
Trust tier
B · Reported

Data exposed

Email addresses, usernames, phone numbers; some modem setup passwords Media-reported

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

In August 2025 TPG Telecom disclosed that its iiNet subsidiary’s order-management system had been accessed using stolen credentials, affecting an estimated 280,000 customers — with email addresses, usernames and phone numbers, and for a subset modem setup passwords, exposed [register-iinet].

Timeline

  • 2025-08 — Unauthorised access to the iiNet order-management system disclosed [register-iinet].

Current status

Disclosed; customers notified and credentials reset. Figures are as reported. [register-iinet]

Why it matters

Another reminder that a single compromised business system — not the core network — is often all an attacker needs to reach hundreds of thousands of customers.

GGOVERN Tabletop Exercises · Govern house Strengthen your cyber resilience — rehearse the decisions that matter. Book a Discovery Call →