Meriton cyber attack exposes guest and staff data
Meriton, one of Australia's largest apartment and serviced accommodation operators, has revealed it suffered a significant cyber attack that potentially exposed details of nearly 2000 guests and staff members across its national network of properties.
The incident occurred in January but only came to light this week as the company notified affected individuals. While the breach involved access to "incident reports" — such as records of injuries sustained at Meriton-run facilities — the company stressed that more sensitive information, including credit card details, remained secure throughout the breach.
For guests and employees with connections to Meriton properties in Sydney, Brisbane, the Gold Coast, Melbourne and Canberra, the breach raises urgent questions about data security at a time when cyber attacks on major Australian businesses have accelerated sharply.
Meriton said it has already contacted the 1889 people potentially affected and insisted there is "no evidence" their information has been misused or released publicly. The company also reported the incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner, meeting its legal obligations to notify regulators and affected parties.
"Meriton has been working closely alongside leading cybersecurity and forensic IT professionals and taking all available steps to protect against future risk to data and prevent recurrence," the company said in a statement released over the past day.
The measures include enhanced network security systems and expanded monitoring capabilities designed to detect and respond rapidly to any future threats. However, the 35.6 gigabytes of data that hackers initially accessed — and the five months it took to fully investigate and contain the breach — underscore the scale of the intrusion.
The Meriton incident arrives amid a broader wave of cyber attacks targeting Australian businesses and consumers. Earlier this month, finance company Latitude Group revealed that hackers had stolen personal information from more than 14 million Australian and New Zealand customers, including millions of driver's licence numbers and passport details. That incident has prompted the consumer watchdog and business leaders to call for stronger data protection across the private sector.
For travellers using Meriton suites or employees on its payroll, the incident carries particular significance: while damage appears contained, the breach demonstrates that even large, established operators cannot entirely shield customer and staff data from sophisticated cyber criminals. Scams and identity theft facilitated by stolen personal data have cost Australians more than $569 million in documented losses in recent years, though authorities suggest actual losses are far higher.
The company's disclosure that primarily "incident reports" were compromised may provide some reassurance to its customer base. Equally important, Meriton has stated that none of the stolen data has been released publicly — a critical distinction, given that once personal information circulates on criminal forums or the dark web, the risk to individuals multiplies significantly.
Still, the incident reflects a mounting trend: Australian organisations, regardless of size or resources, are increasingly finding themselves targeted by cyber criminals who view major hospitality and service companies as valuable repositories of guest and employee data. Individuals with ties to Meriton properties should remain vigilant about monitoring their accounts and remain alert to any unusual activity that might suggest their identity or personal information is being misused.
Frequently Asked Questions
Approximately 1889 people, including guests who have stayed at Meriton properties and past and present employees, were potentially affected by the January breach.
Hackers accessed "incident reports" such as records of injuries sustained at Meriton properties. No credit card details, billing information, or other sensitive personal identification data was taken.
Meriton says there is no evidence of data misuse or public release of information. The company has notified affected individuals, reported the incident to regulators, and implemented enhanced security measures to prevent future breaches.
More news
- Nine Shots Fired Into Altona North Home in Drive-By Terror Attack
- High-Speed Police Chase Ends at Scarborough Beach
- Knife-Wielding Man Shot by Police After Random Attacks in Adelaide Suburb
- Thousands of Migrants Overwhelm Spanish Border Post
- Hardgrave Calls for COVID Honours Review After Fauci Admissions