Meriton reveals cyberattack affecting nearly 2000 guests and staff
Nearly 2000 guests and staff at hotel and apartment giant Meriton have been exposed to a cyberattack that struck the company's systems in January, according to a disclosure made this week.
The breach potentially affected 1889 individuals, including current and former employees and guests across Meriton's properties in Sydney, Brisbane, the Gold Coast, Melbourne and Canberra. The company said it has already notified those impacted.
While 35.6 gigabytes of data was accessed during the January attack, Meriton's analysis suggests the sensitive information exposed was limited in scope. The hackers obtained internal "incident reports" that document injuries and other incidents at Meriton properties, rather than the payment details, identification numbers or personal information typically targeted in such breaches.
The company emphasised that no credit card details or guest data was compromised. "Very little was sensitive information," Meriton said. "There is no evidence that affected individuals have had their information misused, nor that any information has been released into the public realm."
Meriton's disclosure comes as Australia confronts a rising tide of high-profile data breaches. In recent weeks, consumer finance company Latitude Group revealed that a cyberattack had exposed the personal records of 14 million Australian and New Zealand customers. That incident exposed nearly 8 million driver's licences, more than 53,000 passport numbers and millions of other personal details including names, addresses and dates of birth.
The broader scale of data theft in Australia has become a pressing concern for regulators and consumers alike. According to authorities, more than $569 million was reported lost to scams in 2022 alone—a figure that represents just 13 per cent of the actual total. Identity theft cases have surged in tandem with major breaches at companies including Optus and Medibank over the past year, prompting the consumer watchdog to urge business leaders to strengthen their data protection and reporting practices.
Meriton said it has reported the January incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. The company has implemented enhanced cybersecurity measures and new network monitoring systems designed to detect and respond to future incidents more quickly.
"Meriton has been working closely alongside leading cybersecurity and forensic IT professionals, and taking all available steps to protect against future risk to data and prevent recurrence," the company said in a statement.
The company operates serviced apartment suites across major Australian cities and has built its reputation on hospitality services. This breach marks a significant challenge to customer confidence, though the company's assertion that minimal sensitive data was compromised may limit the broader impact.
Frequently Asked Questions
The attack occurred in January. Meriton disclosed it this week after notifying the affected parties.
Approximately 1889 guests and staff were potentially affected, including current and former employees and guests who stayed at Meriton properties across Australia.
No. Meriton says no credit card details or payment information was compromised. Hackers accessed internal incident reports documenting injuries at properties. The company states there is no evidence the data has been misused or publicly released.
More news
- Nine Shots Fired Into Altona North Home in Drive-By Terror Attack
- High-Speed Police Chase Ends at Scarborough Beach
- Knife-Wielding Man Shot by Police After Random Attacks in Adelaide Suburb
- Thousands of Migrants Overwhelm Spanish Border Post
- Hardgrave Calls for COVID Honours Review After Fauci Admissions