What iiNet has confirmed
- A stolen staff login was used to reach an internal order management system.
- About 280,000 email addresses were viewed.
- A smaller set included landline numbers plus name, address and phone.
- Roughly 1,700 modem setup passwords were exposed for a defined group.
- Payments and ID documents sit outside scope based on current statements.
How entry happened
The intruder signed in with a valid username and password. iiNet has not said how those credentials were taken.
In events like this the common paths are usually phishing or password reuse. Once inside the tool, linked records can be viewed and exported.
What’s now at risk
Email and phone data make targeted scams and cyber-attacks believable. Expect messages that reference your plan, address or a recent order.
The modem setup password is the administrator login for a home or office router. With that and network reach, an attacker can change your settings or add a hidden rule that survives a reboot.
iiNet is contacting the smaller affected group with reset steps.
If you are an iiNet customer
- Change your iiNet account password and the email password tied to the service
- Turn on multi factor where offered
- Treat calls and emails about credits or plan changes with care and only call iiNet on a published number before you act
- If iiNet tells you your modem setup password was exposed, factory reset the modem, set a new admin password, update Wi-Fi, check for firmware, and turn off remote administration if you do not use it
If you run a help desk or a small IT team
Add a call back step to a number on file before any change. Use challenge questions that are not public. Log all support changes and review them for the next month. Brief staff on voice phishing patterns hitting telecom customers this month.
What we’re watching next
Gridware has been closely following Salt Typhoon’s activity in telecoms. They generally favour stolen logins, service platform access, and quiet persistence in core systems. iiNet’s description of this breach shows a similar pattern. That overlap is why we’re watching it closely alongside other telco incidents in Australia and abroad.



