Data breach: More than one million Aussies who visited ClubsNSW venues at risk of identity theft

More than one million Aussies who have visited pubs and clubs have had their personal details including their addresses and phone numbers exposed in a major data breach.  

The private information may have been shared to an overseas developer by tech company OutABox, a firm located in Sydney, that designs IT products and solutions for gaming and hospitality venues across NSW.

Prominent politicians are reported to be among the Aussies who have had sensitive information compromised as a result of the bungle which has impacted dozens of venues that fall under the ClubsNSW banner, prompting a NSW Police investigation.

The list includes many pubs and RSL clubs across the state, including City of Sydney RSL. 

Information compromised includes addresses, signatures, dates of birth, phone numbers and driver's licence photographs.

City of Sydney RSL is among dozens of pubs and clubs caught up in a major data breach

City of Sydney RSL is among dozens of pubs and clubs caught up in a major data breach

READ MORE: Horror stories emerge after mass Optus outage that left with doctors and nurses unable to make calls to emergency services

Millions of customers were impacted, with doctors and carers unable to use the phone in emergency situations after Optus was hit with a mass outage (pictured Optus store)

Millions of customers were impacted, with doctors and carers unable to use the phone in emergency situations after Optus was hit with a mass outage (pictured Optus store)

Advertisement

It's understood OutABox contracted an offshore developer to build a series of software systems for licensed premises.

Th tech firm then provided the developer with full access to back-end systems at venues, which houses data from customers, The Daily Telegraph reported. 

The data is stored on computers and serves capable of storing large quantities of digitised information. 

The developers are understood to have had access to the personal details from names, phone, numbers and addresses to facial recognition displays and drivers license scans.

The full list of affected venues has been put up on the haveibeenoutaboxed.com website. 

'Anyone who has visited any of these venues since 2020 likely has their visit logged and personal data leaked,' it states. 

NSW detectives have launched an investigation into the data breach.

2GB breakfast host Ben Fordham said that the situation is 'causing a lot of worry in the NSW parliament'.

OutABox said that it was aware and responding to a cyber incident potentially involving some personal information'.

Fairfield RSL has also been caught up in the data breach

Fairfield RSL has also been caught up in the data breach

'We have been in communication with a group of our clients to inform them and outline our strategy to respond,' a statement read.

'Due to the ongoing police investigation, we ae not able to provide further information at this time.'   

OutABox added it was aware of a 'malicious website', containing false statements which they say has been set up to harm their business. 

'We believe this is linked and urge people not to repeat false and reputationally damaging misinformation,' the firm added

Daily Mail Australia contacted OutABox for further comment. 

Clubs NSW held an emergency meeting with affected venues on Wednesday. 

The peak body is 'deeply concerned' by the data breach and is now working with the affected venues and authorities. 

'The clubs concerned are working towards notifying all impacted patrons. We can advise that the appropriate authorities have been notified by the third-party IT provider and the NSW Government has also been advised,' a spokesperson said.  

More than one million Aussies have had their personal details exposed in the latest major data breach (stock image)

More than one million Aussies have had their personal details exposed in the latest major data breach (stock image)

The spokesperson indicated that OutABox is a a third party IT service provider used by dozens of hospitality venues across NSW. 

Club and pub patrons are advised to take extra caution when reviewing or opening links contained in emails or texts.

A spokesman from NSW Police told Daily Mail that officers from the State Crime Command's Cybercrime Squad are investigating the data breach. 

'As the investigation is ongoing, no further information is available at this time,' the spokesman said.  

Clubs NSW was contacted for further comment.

List of venues affected by OutABox data leak

Breakers Country Club, in Wamberal

Buladelah Bowling Club

Central Coast Leagues Club, in Gosford

Mex Club, in Mayfield

City of Sydney RSL

East Maitland Bowling Club

East Cessnock Bowling Club

Fairfield RSL

Gwandalan Bowling Club

Halekulani Bowling Club, in Budgewoi

Ingleburn RSL Club

Club Old Bar

Club Terrigal

West Tradies, in Dharruk

Vikings Erindale Vikings

Source: haveibeenoutboxed.com