← Case Files · The Breach Files

2023 · Consumer finance

Latitude Financial, 2023: a licence number from 2005, stolen in 2023

Case file · 5 min read · Published 15 September 2026

People affected
About 14 million customer records across Australia and New Zealand
When it happened
Detected 16 March 2023
Made public
16 March 2023
How they got in
Employee login credentials stolen and used to access two service providers holding customer data
Attributed to
Not publicly identified; a ransom was demanded and refused
What it cost
A ransom refused, remediation and identity document replacement across two countries, and a regulatory investigation

What was exposed: Driver's licence numbers · Passport numbers · Names · Physical addresses · Phone numbers · Dates of birth

Most of the people in this breach had not thought about Latitude Financial in years. They had taken an interest-free store finance deal for a fridge, or a card that came with a retail promotion, handed over a driver's licence to prove who they were, and moved on. In March 2023 that licence number was stolen, sometimes eighteen years later.

What happened

Latitude Financial provides consumer credit across Australia and New Zealand, personal loans, credit cards, and the point-of-sale finance offered in retail stores. On 16 March 2023 it disclosed that it had detected unusual activity on its systems.

The intrusion route was stolen employee login credentials, used to reach two service providers holding Latitude customer data. Over the following weeks the disclosed scale grew substantially, in the pattern that almost every large breach follows: an initial figure in the hundreds of thousands, then millions, and finally around 14 million customer records across both countries.

The composition is what makes this case distinctive. Roughly 7.9 million driver's licence numbers were taken, of which a minority had been supplied in the previous decade, the rest were older. A further 6.1 million records, containing names, addresses, phone numbers and dates of birth, dated back to at least 2005. Around 53,000 passport numbers were also included.

Retained data is stored liability. A record that no longer serves a business purpose cannot earn anything, cannot be sold, and cannot improve a service. It can only be stolen. Every identity document number held past the end of its regulatory retention period is a small permanent risk carried for no return, and the aggregate of those small risks is the difference between a breach of recent customers and a breach of everyone who ever applied. Deletion is a security control, and it is the only one that reduces the size of the eventual incident.

Why the age of the data is the story

Identity documents behave differently from other breached data, and time makes them worse rather than better. A password stolen in 2005 has almost certainly been changed. A card number has expired. A driver's licence number issued in 2005 is quite possibly still the number on the licence in the wallet today, because licences are renewed by reissuing the same number.

That matters because of how identity verification actually works in Australia. Banks, telecommunications providers and government services confirm identity by checking a document number against a name and a date of birth. Someone holding all three can open accounts, port a phone number, or apply for credit. The document does not need to be forged, the number alone is often sufficient to satisfy an automated check.

So a breach of eighteen-year-old records is not a breach of stale data. For the portion of it that consists of identity document numbers, it is nearly as dangerous as a breach of records collected last week, and the affected population is far larger: everyone who ever applied, whether or not they were approved, whether or not they ever borrowed a cent.

The refusal

Latitude received a ransom demand and announced publicly that it would not pay, giving reasons that were specific rather than rhetorical: payment would not guarantee the return or destruction of the data, and it would incentivise further attacks on Australian businesses.

That position was not obvious a year earlier. It became the Australian norm after the Optus and Medibank incidents of 2022, where Medibank's refusal, followed by the publication of deeply sensitive health records, established both that refusal was survivable as a company and that it was genuinely costly for customers. The reasoning behind refusal is sound, and the honest version has to acknowledge what it means for the people in the file: the data goes out anyway, and the organisation that lost it absorbs the cost of the aftermath.

The timeline

  1. Before March 2023: Employee login credentials are stolen and used to reach two service providers holding customer data.
  2. 16 March 2023: Latitude detects unusual activity and discloses the incident.
  3. 20–27 March 2023: The disclosed scale grows repeatedly as the investigation progresses.
  4. 27 March 2023: The company confirms around 14 million records, including 7.9 million driver's licence numbers and 6.1 million older records dating back to at least 2005.
  5. April 2023: A ransom demand is received; Latitude announces publicly that it will not pay.
  6. 2023 onwards: Identity document reissue programmes run in both countries; privacy regulators open inquiries.

What it changed

Coming after Optus and Medibank, this breach completed an argument Australian policymakers had been making about data minimisation. Three of the country's largest breaches in seven months had a common feature: a substantial share of the harm came from data that no longer needed to exist. That pushed retention from a compliance footnote into the centre of privacy reform discussions, and it gave regulators a concrete question to ask boards, not "was this data secured" but "why was this data still here".

It also forced the practical machinery of document reissue into the open. Replacing a compromised driver's licence number is a state-level process, and the volume of people needing it across three breaches exposed how poorly that process scales and how much of the cost lands on individuals. Fee waivers and streamlined reissue after a declared breach are now a standard expectation rather than a concession.

If you were a Latitude customer: or applied once

Start by recognising that you might be in this and not remember the relationship at all. The exposure runs through store-branded finance and cards issued under retail partnerships, so the name on the paperwork you signed may not have been Latitude.

If your driver's licence number was taken, have the licence reissued with a new number. That single action removes most of the ongoing risk, because the number is what identity checks rely on, and it is the one exposed element you can actually change. Where a breach has been declared, reissue fees are commonly waived, ask.

Then place a credit ban with each Australian credit reporting body, or the equivalent in New Zealand. It is free, it lasts a defined period, it is renewable, and it blocks new credit being opened in your name rather than telling you afterwards that it was. Monitoring reports; a ban prevents. For data this durable, prevention is the only control that keeps working.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored, it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

How did the attackers get in?

Through stolen employee login credentials, used to reach two service providers that held Latitude customer data. No exotic exploit was involved. It is the most common intrusion route there is, and it is the reason credentials that unlock access to customer databases need a phishing-resistant second factor rather than a password and a code.

Why were records from 2005 still there?

That is the central question of this case and it was never satisfactorily answered. Consumer finance businesses collect identity documents to meet know-your-customer obligations, and those obligations come with retention periods. What they do not require is indefinite retention of identity document numbers for customers whose accounts closed many years ago. Data kept past its purpose is pure liability: it cannot generate revenue and it can be stolen.

Did Latitude pay the ransom?

No. The company publicly announced it had received a ransom demand and would not pay, on the stated grounds that paying would not guarantee the return or deletion of data and would encourage further attacks. Both points are correct. Australian corporate practice had shifted sharply in that direction after the Optus and Medibank breaches the previous year.

What can someone do if their driver's licence number was taken?

In Australia, state and territory authorities allow licences to be reissued with a new number where they have been compromised, and in some jurisdictions the cost is waived after a declared breach. That is worth doing, because unlike a password the number is used as a proof of identity by banks and telcos. Credit bans, free, and renewable, stop new accounts being opened in your name while you sort it out.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported, where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →