Latitude Financial Data Breach: Lessons for Small Businesses

The 2023 Latitude Financial breach exposed approximately 14 million records, including information dating back to 2005. Here is what Australian businesses can learn about data retention, third-party access, stolen credentials and breach response.

In March 2023, Latitude Financial suffered what remains one of the largest data breaches in Australian history.

Latitude Financial is the ASX-listed lender behind Gem, GO Mastercard and 28° Global. It provides personal loans, credit cards and point-of-sale interest-free finance to around 2.8 million customer accounts across Australia and New Zealand.

An attacker, who compromised one of Latitude's vendors, obtained Latitude employee login credentials and used them to extract customer data from two other service providers. The stolen data included:

  • ~7.9 million Australian and NZ driver licence numbers
  • ~103,000 copies of driver licences or passports
  • ~53,000 passport numbers
  • ~6.1 million additional records, some dating back to at least 2005
  • income and expense information used in ~900,000 loan applications, including - ~308,000 bank account numbers and ~143,000 credit card or credit card account numbers;
  • less than 100 customers with monthly financial statements.

Many affected people were former customers and applicants, and some information dated back nearly two decades.

Due to its impact, this breach is among the biggest Australian data breaches along with Optus and Medibank, intensifying the debate about privacy reform, data retention and cyber security.

The weaknesses that contributed to the impact of this breach - third-party access, one compromised account reaching multiple sources of sensitive information, and retention of large volumes of historical data - can exist in businesses of every size. And as for small businesses, there are usually fewer designated defences available for IT and security.

What happened

On 16 March 2023, Latitude Financial entered a trading halt at ASX and disclosed a cyberattack, describing it as "sophisticated and malicious". It was initially disclosed that approximately 103,000 identification documents and 225,000 customer records were stolen.

By 27 March, Latitude confirmed the theft of records relating to approximately 14 million customer and applicant records. The stolen information included:

  • Driver licence numbers: ~7.9 million Australian and New Zealand
  • Passport numbers: ~53,000 records
  • Records containing names, addresses, dates of birth and phone numbers: ~6.1 million, with some dating back to at least 2005
  • Images of driver licences or passports: 103,000 records
  • Income and expense information: ~900,000 loan applications
  • Bank account numbers: ~308,000 records
  • Credit card or credit account numbers: ~143,000 records
  • Monthly financial statements: less than 100 customers.

Latitude said bank-account passwords, card expiry dates and three-digit security codes were not compromised.

Latitude received the ransom demand but refused to pay it, explicitly aligning with the Australian Government's position.

As of July 2026, no attacker has been publicly identified or charged in connection with this breach.

The timeline

DateEvent
Prior to 16 March 2023An attacker obtains a compromised employee credential through one of Latitude’s vendors. Latitude detects unusual activity and begins its response.
16 March 2023Latitude enters an ASX trading halt and publicly discloses the breach. Early findings: ~330,000 customers and applicants affected.
27 March 2023The full scale of the breach disclosed: ~14 million records.
11 April 2023Latitude confirms a ransom demand and refuses to pay.
April - May 2023~6 weeks of severe business disruption: new lending paused, collections interruptions.
May 2023The OAIC and NZ Privacy Commissioner open a joint investigation into Latitude's information handling.
Aug 2023Latitude reports $76M of pre-tax cyber-related costs and provisions related to the incident and $98.2M statutory loss after tax.
2023 - 2024Gordon Legal and Hayden Stephens and Associates lodged a representative complaint with the OAIC on behalf of affected individuals.

How the attacker gained access

Based on Latitude’s public disclosures, the incident began with a third-party credential compromise, rather than a technical exploit. Here’s how the cybercriminals got in:

  1. Third-party compromise. The attack originated from one of Latitude’s major vendors.
  2. Theft of a valid login credential. From the vendor environment, the attacker obtained active credentials belonging to a Latitude employee.
  3. Large-scale data theft. The attacker used that credential to gain unauthorised access to personal information of current and historical customers and applicants, resulting in approximately 14 million records stolen.

Public disclosures have not identified malware, a zero-day vulnerability, or phishing against Latitude employees as the initial access method. The confirmed starting point was a compromised credential obtained through a third party that unlocked almost two decades of identity data.

5 reasons the breach had such a large impact

  1. A third-party compromise reached Latitude. Based on reports, the attacker obtained a valid employee credential through a compromised third party. This shows how a supplier’s security weakness can become a customer’s security incident. Businesses should know which vendors can access their systems and data, limit that access to what is necessary and remove it when it is no longer needed.
  2. Stolen credentials worked, at scale. The compromised credential provided sufficient access for the attacker to retrieve large volumes of data. Public information does not establish whether MFA was absent, bypassed or otherwise ineffective. The suspicious activity was not detected or interrupted early enough to prevent large-scale data theft.
  3. Historical data increased the consequences. Some stolen records dated back to at least 2005 and related to former customers and unsuccessful applicants. Australian Privacy Principle 11.2 generally requires an organisation to take reasonable steps to destroy or de-identify personal information no longer needed, unless it must be retained under other legal requirements. In May 2023, the OAIC and New Zealand Privacy Commissioner started a joint investigation into whether Latitude met that obligation.
  4. Valuable identity information was concentrated. The attackers were able to reach Latitude’s customer and applicant records in the service-provider systems with one set of employee credentials. The stolen information included driver licence and passport details, document images, Medicare information and financial information provided during credit applications. Where retention is legally or operationally necessary, the information should be isolated, encrypted, tightly access-controlled and deleted when the retention requirement ends.
  5. Detection did not prevent large-scale theft. Latitude detected unusual activity and moved to contain the incident, but substantial information had already been compromised. Businesses should have alerts on unusual behaviour such as mass searches, bulk downloads, large exports, access from new locations and one account rapidly accessing several sensitive systems.

What it cost

  • In August 2023, Latitude reported $76 million in pre-tax March-incident-related costs and provisions, contributing to a $98.2 million after tax loss from continuing operations for the half-year.
  • Business operation disruption: For around 6 weeks, Latitude paused new lending, and loan collections were disrupted.
  • Cost for reimbursing identity document replacement for millions of people
  • Legal and regulatory exposure: Serious privacy contraventions can expose a company to substantial civil penalties, although a data breach does not automatically mean that the maximum penalty will apply.
  • Reputational damage.

What Latitude did well

Although the breach exposed serious weaknesses, several aspects of Latitude’s incident response are worth recognising:

  • Early disclosure: Latitude disclosed the cyberattack and entered a trading halt on 16 March 2023 while the investigation was still underway.
  • Containment and operational action: Latitude isolated affected systems, paused parts of its onboarding process for new customers and worked with cyber security specialists, the ACSC, AFP and other government agencies.
  • Refusal to pay the ransom: Latitude publicly stated that it would not pay the attacker, aligning its position with Australian Government advice.
  • Support for affected people: Latitude offered to reimburse reasonable costs for replacing compromised identity documents and provided information about protective steps customers could take.

9 lessons for your business

  1. Do not keep data longer than necessary. Review what personal information your business holds, why it’s needed, and how long it must be retained. Australian Privacy Principle 11.2 generally requires an organisation to take reasonable steps to destroy or de-identify personal information it no longer needs, unless it must retain the information under another legal obligation. Historical information increased the scale of the Latitude breach. Cybercriminals cannot steal data your business no longer holds.
  2. Minimise stored identity documents. Verify identity without retaining a full document image where the law and business process allow. If retention is required, store only the minimum information, encrypt it, isolate it, restrict access and delete it as soon as the applicable retention period ends.
  3. Your vendors' security affects your business. Know which third parties hold your data or can access your systems. This may include IT providers, bookkeepers and software platforms. Require MFA, prompt breach notification and clear security obligations.
  4. Review third-party access regularly. Keep a record of every vendor account, what it can access and who approved it. Remove access immediately when it is no longer required.
  5. Make stolen credentials insufficient. Require MFA (multi-factor authentication) for remote, administrator and third-party access. Give every account only each account only the access it needs. Set alerts on unusual behaviour, such as new login locations, bulk downloads or access outside expected hours.
  6. Control large data exports. Restrict who can download or export sensitive information. Set alerts on unusually large downloads, repeated searches or one account accessing several sensitive systems in a short period.
  7. Test your incident response plan. A written plan is useful only if people know how to use it. Run a simple exercise covering containment, notifications, customer communication and contact with your IT provider.
  8. Decide your ransom position before an incident. Document who has authority to make the decision and obtain legal, law-enforcement, insurance and incident-response advice. Paying a ransom does not guarantee that stolen data will be deleted, returned or kept private.
  9. Explain that early breach figures may change. Clearly label early figures as preliminary. Then may change as forensic investigation progresses.

How cyber security frameworks apply

While the publicly available information is limited and does not provide enough technical detail to map every stage of the Latitude attack, the incident can still be examined using established cyber security frameworks.

MITRE ATT&CK helps understand the attacker’s behaviour

  • Valid Accounts (T1078): This technique is consistent with the publicly known facts because the attacker obtained a valid employee credential to gain unauthorised access to sensitive information.
  • Data from Information Repositories (T1213): The data theft from customer and applicant systems may be consistent with this technique.

NIST Cybersecurity Framework 2.0 helps organise the lessons

  • Govern: Assign responsibility for cyber security, privacy, data retention and third-party risk. Set security requirements for vendors and check that they are followed.
  • Identify: Know what personal information the business holds, where it is stored, why it is needed, who can access it and when it should be deleted.
  • Protect: Use least privilege, strong MFA, encryption, access segmentation and controls that limit large downloads or exports.
  • Detect: Monitor successful and failed logins. Alert on unusual locations, new devices, mass downloads and access across sensitive systems.
  • Respond: Maintain and test an incident-response plan covering containment, legal and privacy assessment, communication and customer support.
  • Recover: Restore services safely, support affected people and update systems, contracts and retention practices after the incident.

ACSC’s Essential Eight

Although the Essential Eight does not cover every issue raised by this data breach, it is a useful Australian technical baseline. The most relevant strategies include:

  • Multi-factor authentication: Require MFA for employees, administrators, vendors and access to sensitive systems.
  • Restrict administrative privileges: Give your employees and service providers only the access required for their work. Review privileged access regularly and remove it when it is no longer needed.
  • Regular backups: Maintain protected and tested backups to support operational recovery.

Final takeaway

The Latitude breach was not only a story about a compromised credential. It also showed how much sensitive information one account could reach, how third-party access can connect multiple systems, and how historical data can increase the harm caused by an incident.

Small businesses may hold fewer records, but the same risks still apply. Know what personal information you hold, remove information you no longer need, limit each account to the minimum access required and monitor unusual activity after login.

Use our DIY cyber security health check to review your current controls and identify practical steps for improvement.

Sources used

  • Latitude Financial, Cybercrime Update, 20 March 2023
  • Latitude Financial, Cybercrime Update, 27 March 2023
  • Latitude Financial, Cybercrime Update 11 April 2023
  • Latitude Financial, Latitude Cyber Response
  • OAIC, Joint Australia-New Zealand investigation into Latitude group
  • OAIC, Statement on Latitude Financial data breach
  • New Zealand Office of the Privacy Commissioner, New Zealand - Australia investigation into Latitude breach begins
  • Latitude Group Holdings, 1H23 Results
  • MITRE ATT&CK, Valid Accounts - T1078
  • MITRE ATT&CK, Data from Information Repositories - T1213
  • NIST, Cybersecurity Framework 2.0
  • ASD, ACSC’s Essential Eight Maturity Model
  • Australian Government, Australian Privacy Principles Guidelines, Chapter 11
  • Gordon Legal, Latitude Financial privacy breach representative complaint
Share
Share

More To Explore

What The Medibank Breach Teaches Small Businesses

What The Medibank Breach Teaches Small Businesses

The 2022 Medibank data breach made headlines, but the weaknesses that contributed to it are not unique to large companies. Here are the practical lessons small businesses can take from the incident.
The DIY Cyber Security Health Check for Small Business

The DIY Cyber Security Health Check for Small Business

A practical, jargon-free cyber security checklist you can complete this afternoon to see where your business is exposed - no IT department required.
Why Hackers Target Accounting Firms and How to Reduce the Risk

Why Hackers Target Accounting Firms and How to Reduce the Risk

Accounting firms hold the keys to their clients' finances - which is exactly why they're such an attractive target for cybercriminals. Here's what makes them vulnerable, and how to close the cyber security gaps.