Cyberdaily.Au Senate Orders OAIC to Release Full Amex Privacy Investigation Details
Article Content
- •The Australian Senate has ordered the OAIC to release full details of the Amex investigation.
- •The OAIC's previous report was abridged due to concerns over individual harm and cybersecurity risks.
- •Amex must implement stronger access controls within six months following identified insider breaches.
The Australian Senate has mandated the Office of the Australian Information Commissioner (OAIC) to disclose the complete findings of its investigation into American Express (Amex) regarding security weaknesses. The investigation revealed significant access control issues following two insider breaches. The OAIC had previously only published an abridged report citing potential harm to individuals and cybersecurity risks as reasons for withholding full details. The Senate's motion, passed with a vote of 33-21, requires the OAIC to provide the full determination and related correspondence by July 28, 2026. This move aims to enhance transparency and accountability regarding the handling of privacy breaches by Amex. The OAIC had ordered Amex to implement stronger access controls within six months after the breaches were identified.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track American Express in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and…