Special Features

Cybersecurity Month

Australian e-tailer digiDirect customers' info allegedly stolen and dumped online

Full names, contact details, and company info – all the fixings for a phishing holiday


Data allegedly belonging to more than 304,000 customers of Australian camera and tech e-tailer digiDirect has been leaked to an online cyber crime forum.

digiDirect, a prominent Australian consumer electronics retailers, did not immediately respond to The Register's inquiries. We will update this story if and when we hear back.

According to a BreachForums post, a crook who goes by “Tanaka” allegedly swiped a database containing customers' full names, email addresses, phone numbers, billing and shipping addresses, and company names.

The criminal also posted a sample of the stolen data – which has not been verified by The Register - and issued an apparent shoutout to another cyber crook – "very thanks to Chucky" – who may or may not have also been involved in the digital break-in, if it indeed happened.

There has been no word yet from digiDirect, nor from the Office of the Australian Information Commissioner or the Oz Federal Police as to whether they have received a breach report from the electronics shop, or if they are investigating. The Register has asked both government agencies for comment.

Still, anyone who has recently purchased electronics from the shop would be wise to keep an eye on their digital identity and bank accounts to ensure that fraudsters aren't using personal and financial information for shopping sprees or other nefarious purposes.

In 2021, digiDirect was fined AU$39,240 ($27,100) by the Australian Competition and Consumer Commission for allegedly misleading consumers about "storewide" sales, which the consumer protection watchdog claimed weren't really storewide at all.

The breach, if the report turns out to be true, follows a rough several months for Australians. Their sensitive info has been stolen – and then posted online – from Ticketmaster, prescriptions provider MediSecure, and Nissan Oceania, among others.

Crikey. ®

Send us news
1 Comment

Brazen crims selling stolen credit cards on Meta's Threads

The platform 'continues to take action' against illegal posts, we're told

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers

Attacks on unprotected servers reach 'critical level'

Gang gobbles 15K credentials from cloud and email providers' garbage Git configs

Emeraldwhale looked sharp – until it made a common S3 bucket mistake

Uncle Sam outs a Russian accused of developing Redline infostealing malware

Or: why using the same iCloud account for malware development and gaming is a bad idea

Feds investigate China's Salt Typhoon amid campaign phone hacks

'They're taunting us,' investigator says and it looks like it's working

JPMorgan Chase sues scammers following viral 'infinite money glitch'

ATMs paid customers thousands ... and now the bank wants its money back

Ransomware's ripple effect felt across ERs as patient care suffers

389 US healthcare orgs infected this year alone

Would banning ransomware insurance stop the scourge?

White House official makes case for ending extortion reimbursements

Biz hired, and fired, a fake North Korean IT worker – then the ransom demands began

'My webcam isn't working today' is the new 'The dog ate my network'

Critical hardcoded SolarWinds credential now exploited in the wild

Another blow for IT software house and its customers

Cisco confirms 'ongoing investigation' after crims brag about selling tons of data

Networking giant says 'no evidence' of impact on its systems but will tell customers if their info has been stolen

Wanted. Top infosec pros willing to defend Britain on shabby salaries

GCHQ job ads seek top talent with bottom-end pay packets