Meriton cyber attack exposes nearly 2000 guests and staff
Meriton, one of Australia's largest serviced apartment operators, has become the latest major company to suffer a significant cyberattack, with the breach potentially compromising the personal information of nearly 2000 guests and employees.
The attack took place in mid-January when cybercriminals infiltrated Meriton's computer networks and accessed approximately 35.6 gigabytes of data. The company said the stolen information consisted primarily of internal "incident reports"—documentation of injuries and other events that occurred at its properties—rather than sensitive financial or booking data. Still, the breach laid bare gaps in the hospitality giant's cybersecurity defenses.
Over the following weeks, Meriton engaged specialized cybersecurity and forensic IT firms to investigate the full scope of the attack and understand exactly what had been taken. It was a painstaking process: determining who had been affected, what information had been accessed, and whether the data might have been sold or shared on the dark web. This week, Meriton formally disclosed the incident publicly and revealed it had already notified all 1889 potentially affected individuals.
The company stressed several mitigating factors. No credit card details or guest payment information were stolen, a critical point for a business handling reservations and accommodation payments. Meriton also said there is no evidence that the stolen information has been misused or released into the public domain. The company reported the breach to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner, as required by law. Since the incident, Meriton has implemented enhanced security measures and deployed real-time network monitoring aimed at detecting threats faster.
The disclosure comes as Australian businesses and regulators grapple with a widening crisis of data breaches. Just days ago, consumer finance company Latitude Group announced that a cyberattack had exposed the personal details of 14 million Australian and New Zealand customers, including nearly 8 million driver's license numbers and over 53,000 passport records. The breach also compromised millions of other sensitive documents containing names, addresses, phone numbers and dates of birth.
Throughout 2022 and into this year, other major corporations—Medibank, Optus, and others—have suffered comparable breaches affecting millions of Australians. The Australian Consumer Watchdog has warned that the surge in data breaches is fueling a spike in identity theft and financial scams. In 2022 alone, Australians reported more than $569 million in scam losses, though authorities believe the actual figure is significantly higher.
The spate of breaches has prompted calls for stronger data protection regulation and corporate accountability. Business leaders face mounting pressure to implement robust security practices and respond transparently when incidents occur.
Meriton operates serviced apartment properties across Australia's major metropolitan areas, including Sydney, Brisbane, the Gold Coast, Melbourne, and Canberra.
Frequently Asked Questions
The attack took place in mid-January 2023. Meriton worked with cybersecurity specialists to investigate for several weeks before publicly disclosing the breach in late March.
Nearly 1,900 individuals potentially had their information compromised, including both guests who have stayed at Meriton properties and current and former employees.
Hackers accessed internal incident reports that documented injuries and other events occurring at Meriton properties. Critically, no credit card details, financial information, or standard guest booking data were stolen.
More news
- Nine Shots Fired Into Altona North Home in Drive-By Terror Attack
- High-Speed Police Chase Ends at Scarborough Beach
- Knife-Wielding Man Shot by Police After Random Attacks in Adelaide Suburb
- Thousands of Migrants Overwhelm Spanish Border Post
- Hardgrave Calls for COVID Honours Review After Fauci Admissions