Cybersecurity giant Symantec plays down unreported breach of test data

The American cybersecurity giant Symantec has downplayed a data breach that allowed a hacker to access passwords and a purported list of its clients, including large Australian companies and government agencies.

The list extracted in the February incident, seen by Guardian Australia, suggests that all major federal government departments were among the targets of a hacker who also claimed to be responsible for Medicare data being available for sale on the dark web.

But Symantec said the “minor incident” involved “an isolated, self-enclosed demo lab in Australia – not connected to Symantec’s corporate network – used to [demonstrate] various Symantec security solutions and how they work together”.

The incident was not reported because Symantec concluded that “no sensitive personal data was hosted in or extracted from this demo lab, nor were Symantec’s corporate network, email accounts, products or solutions compromised”.

The US cybersecurity company Symantec says a data breach that allowed a hacker to access passwords and a purported list of its clients was a ‘minor incident’. Photograph: SOPA Images/LightRocket via Getty Images
The US cybersecurity company Symantec says a data breach that allowed a hacker to access passwords and a purported list of its clients was a ‘minor incident’. Photograph: SOPA Images/LightRocket via Getty Images

The hacker extracted a list of purported clients of Symantec’s CloudSOC services, account managers and account numbers – but Symantec insists data contained in the system were “dummy e-mails and a small number of low-level and non-sensitive files for demonstration purposes” in a demo lab “not used for production purposes”.

The list of purported clients includes the Australian federal police, the big four banks, insurers, universities, retailers and departments in the New South Wales and federal public service.

“This is an old list of some of the largest public and private entities in Australia – it was in the environment for testing purposes,” a Symantec spokeswoman said. “These entities are not necessarily Symantec customers, nor do we necessarily host services for them.”

Several federal departments, including infrastructure, industry, human services and finance, confirmed that they do not use Symantec’s CloudSOC services and do not store information with Symantec. But Guardian Australia understands that others queried the “minor” breach with Symantec because they are customers.

The Department of Social Services said it “uses Symantec products including CloudSOC, in line with Australian Cyber Security Centre best practice”.

“The product in question is not used by the department to store customer, or sensitive information.”

In a statement the Department of Infrastructure, Transport, Cities and Regional Development noted the department name referenced in the list was “discontinued in 2013”.

“We have received no notice from Symantec regarding this matter, but we will make contact in relation to their continued use, if any, of our department name.”

In a statement the Department of Home Affairs said it “does not use the Symantec CloudSOC services, however does use a number of other Symantec products on the department’s internal network, that are managed by departmental staff”.

“The department does not have any sensitive information that is held by Symantec.

“Information held by Symantec would relate to Symantec’s commercial relationship with the department, which is publicly available information.”

The departments of agriculture, education, employment, communication and arts said they used other Symantec products, but not cloud services, and did not store information with Symantec. Education also said it would “make contact in relation to their use of our department name”.

The Australian Privacy Act creates a scheme for compulsory notification when a data breach is likely to result in serious harm to individuals whose personal information is involved in the breach.

The Symantec spokeswoman said it treated “any cyber-security incident – regardless of its scope or severity – with the utmost priority and take great caution in complying with the laws of the countries in which we do business around the world”.

“Consistent with our internal policies and guidance, which align with national and international data protection laws, no sensitive personal data or information has been disclosed that would trigger any regulatory obligations, but Symantec will continue to take appropriate remediation efforts if the situation changes.”

The Guardian

Other News

SK Group partners to build AI ecosystem in Vietnam

SK Group partners to build AI ecosystem in Vietnam

SK Innovation and SK Telecom signed MoUs with Nghe An province and the National Innovation Centre of Vietnam to advance AI ecosystem development and support the country’s long-term growth strategy.

Vietnam Research Excellence Fellowship for 2026-2030 approved

Vietnam Research Excellence Fellowship for 2026-2030 approved

Under the Vietnam Research Excellence Fellowship (VREF) for the 2026–2030 period, PhD students are identified as a core research force directly contributing to breakthroughs in sci-tech and innovation. Investing in top-tier doctoral candidates is more than workforce development, but a high-stakes strategic bet to forge a cohort of world-class scientists and technologists who can power Vietnam’s long-term economic ambitions.

Strategic tech must address practical challenges: PM

Strategic tech must address practical challenges: PM

Prime Minister Pham Minh Chinh on March 28 said strategic technologies must tackle Vietnam’s practical challenges, while chairing a meeting of the Government’s Steering Committee for science and technology, innovation, digital transformation, and Project 06.

Ho Chi Minh City sets sights on becoming semiconductor hub

Ho Chi Minh City sets sights on becoming semiconductor hub

Ho Chi Minh City is stepping up efforts to attract investment from global leading groups and companies in the fields of electronic components, semiconductors and chip manufacturing as it seeks to position itself as a leading semiconductor industry hub in both the region and the world. 

Ho Chi Minh City launches upgraded technology exchange platform

Ho Chi Minh City launches upgraded technology exchange platform

The upgraded platform represents a comprehensive shift from a simple information-sharing model to a managed online technology trading system, enabling monitoring and measurement of real transaction outcomes. It is built on three pillars, namely new tradable technology products, a modern digital platform, and an improved operational model.

AI – unmissable opportunity for Vietnam: Experts

AI – unmissable opportunity for Vietnam: Experts

AI also emerges as a key enabler for Vietnam's ambition to build financial and technology hubs. Applications can boost efficiency, automate workflows, cut costs, and sharpen data analytics, which are essential pillars of a modern financial system.

PM calls for accelerated space technology development in Vietnam

PM calls for accelerated space technology development in Vietnam

Vietnam aims by 2030 to achieve a mid-level position in space science and technology development within Southeast Asia, and after 2030 to build national capabilities to independently develop satellite technologies and apply space data to address global challenges and national security needs.

High-level forum advances Vietnam–US technological cooperation

High-level forum advances Vietnam–US technological cooperation

A high-level executive leadership forum focusing on strengthening Vietnam - US relations through technology cooperation was jointly held in Washington D.C. on March 11 by the Embassy of Vietnam in the US, the Weatherhead East Asian Institute of Columbia University, and the US -ASEAN Business Council (USABC). 

AI Law takes effect, anchors national governance framework

AI Law takes effect, anchors national governance framework

While many countries are still drafting policy blueprints or issuing non-binding guidance, Vietnam has moved ahead with a standalone Law on Artificial Intelligence (AI), effective from March 1, placing it among a select group of nations to adopt dedicated AI legislation at the parliamentary level. 

Vietnam International Defence Expo 2026 preparations move into high gear

Vietnam International Defence Expo 2026 preparations move into high gear

Vietnam International Defence Expo 2026, themed “Peace, Friendship, Cooperation and Development,” will be organised on a larger scale, featuring a wide array of weapons and technical equipment alongside product exhibitions, seminars and panel discussions, drills, live field demonstrations, and business networking activities.

Ministry requests urgent measures to counter UAVs threatening aviation safety

Ministry requests urgent measures to counter UAVs threatening aviation safety

Ministry of Construction requested the Ministry of National Defence, the Ministry of Public Security and provincial and municipal steering committees for counter-terrorism to strengthen the management, inspection and supervision of UAVs and other aerial devices, ensuring strict compliance with Decree No. 288/2025/ND-CP and relevant legal regulations.