[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f256q2wa623u1e":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":37,"seoTitle":38,"seoTitleEn":39,"seoDescription":38,"seoDescriptionEn":40,"logoUrl":41,"isVerified":4,"isSensitive":4,"isSpamList":42,"isMalware":42,"company":43},"68e3266eda11adda48825171","ctars","CTARS Data Breach","ctars.com.au","2022-05-21T00:00:00.000Z","2022-05-31T22:58:15.000Z","2026-07-09T20:20:39.108Z","2026-07-18T23:49:15.096Z","Third party breach","https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Fctars-data-breach",[15,17,18,19,20],"https:\u002F\u002Fia.acs.org.au\u002Farticle\u002F2022\u002Fdata-leaked-as-ndis-software-provider-hacked.html","https:\u002F\u002Fwww.familyspirit.org\u002Fctars-data-security-alert\u002F","https:\u002F\u002Flifechoicewbb.org\u002Fwp-content\u002Fuploads\u002F2023\u002F01\u002FCTARS-Data-Breach-May-2022.pdf","https:\u002F\u002Fwww.crikey.com.au\u002F2022\u002F09\u002F27\u002Fndis-ctars-data-breach-optus\u002F",12314,"known",null,"unknown","Medium",[27,28,29,30,31,32,33,34,35,36],"Dates of birth","Email addresses","Genders","Names","Passwords","Personal health data","Phone numbers","Physical addresses","Salutations","Usernames","\u003Cp>The CTARS data breach is related to the unauthorized access in May 2022 of the cloud-based customer management system used in Australia for NDIS, disability services, out-of-home care, child services, and aged care processes. Since CTARS is a platform where care providers keep records about participants, caregivers, and service processes, this incident is not an ordinary account breach. The verified scope includes 12,314 unique email addresses; however, the types of data are not limited to email. The record contains sensitive fields such as dates of birth, genders, names, passwords, health-related personal information, phone numbers, physical addresses, salutation information, and usernames. Therefore, the record should be treated as a sensitive breach, and guidance should be provided to users regarding both account security and identity risk.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The types of data recorded in CTARS are multilayered: email addresses and usernames are linked to account access, passwords to identity risk, phone numbers and physical addresses to direct communication and location context, birth dates and gender information to authentication processes, and names and title information to a person's real-world identity. One of the most critical areas is personal health data. In the context of care services, information about health status, support needs, treatment process, or care plan can directly impact a person's privacy. When such data is exposed, the risk is not limited to account takeover; risks of discrimination, targeted fraud, blackmail, and social engineering may also arise.\u003C\u002Fp>\n\u003Cp>The presence of password and username fields increases the risk that the accounts of affected individuals or care provider staff will be tried on other services. Phone and address information can be used for more convincing contacts, such as fake support calls, delivery notifications, care service appointments, or impersonation of official institutions. Date of birth and name information is linked to identity verification questions in some customer service processes, so it can help an attacker bypass security checks on other accounts. Health-related data is the most sensitive layer; therefore, this record should not be seen as an incident that can be resolved merely by changing the password.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number 12,314 used in this record represents the scope of verified unique email addresses. The incident is linked to a broader CTARS event affecting care service providers in Australia; some notifications have indicated that a large number of institutions and different customer groups could be affected. Nevertheless, the number on this page represents the scope of accounts that could be checked and does not necessarily represent the exact total number of affected individuals. It should not be assumed that the same fields exist for each individual; for some people, only contact information may be present, while for others, more sensitive information related to care or health may have been included.\u003C\u002Fp>\n\u003Cp>The record regarding the date has been corrected to May 2022. It has been reported that unauthorized access was detected in mid-May 2022, and it was later understood that some data had been shared with unauthorized recipients. The previous incorrect year information was corrected because it did not align with the verified timeline of this incident. This correction is important because showing the wrong date of the breach could confuse the user about which accounting period and which service relationship they need to check. Since the record is sensitive, the results should only be shown to the relevant email owner or a person authorized over the domain.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The people at the highest risk are NDIS participants served by care providers using CTARS, people receiving disability services, individuals associated with child and family services, aged care residents, caregivers, relatives, and staff working in these services. These groups may already be more vulnerable to fraud and coercion attempts due to their need for support or sensitive living conditions. Attackers can create seemingly trustworthy calls, messages, or emails by combining real names, contact information, and care context. Particular attention should be paid to contacts impersonating official institutions, care providers, support coordinators, or identity verification units.\u003C\u002Fp>\n\u003Cp>The risk is also high for institution employees and service providers. If employee usernames and passwords are reused on other systems, attackers may target the institution's email, case management system, cloud storage, or remote access accounts. Maintenance providers' old CTARS records may also be affected, even if services are no longer being used; therefore, not only current customers but also individuals who previously had records in the system should be considered. Family members and legal representatives are also at risk, as the information kept as contact persons can be used in fraud attempts.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The first step for users matching the CTARS record is to update all accounts that use the same or similar password. Email accounts, healthcare service portals, public service accounts, banking, cloud storage, and maintenance provider systems should be prioritized for review. Passwords should be unique, and multi-factor authentication should be enabled on important accounts. In the email account, forwarding rules, recovery options, and recent login activities should be checked. If suspicious login, unknown devices, or unexpected password reset messages are observed, the relevant service provider should be contacted directly.\u003C\u002Fp>\n\u003Cp>The second step is to reduce the risk of identity theft and fraud. Health, care, payment, identity document, or account information should not be shared with callers or text messengers whose identity has not been verified. When receiving communication that appears to be from an official institution or care provider, one should respond through the institution's known contact channel without using the link in the message. If the affected person is an NDIS participant, a care service recipient, or a legal representative, the support coordinator or service provider should be informed. If necessary, free identity support services should be used, and suspicious contacts should be recorded.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident demonstrates the high sensitivity of the data recorded in care and health services. Users should develop a stricter verification habit for requests coming via email and phone in the long term. Using a password manager prevents password reuse across different services. Multi-factor authentication, session history checks, and keeping recovery information up to date on important accounts provide lasting security. For individuals receiving health and care services, it is also useful to create a shared communication verification plan with family members, legal representatives, or support staff.\u003C\u002Fp>\n\u003Cp>The long-term strategy is broader in terms of care providers and software suppliers. Sensitive health and care data should be kept with the principle of least privilege, old records should not be retained unnecessarily, access logs should be regularly reviewed, and strong authentication should be mandatory for high-risk accounts. In incident response, technical shutdown alone is not sufficient; affected individuals should be clearly informed about which areas are at risk, which support channels to use, and which fraud scenarios to watch out for. Institutions that use suppliers should also regularly update their own data inventories and third-party risks.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If the control result on this page matches the CTARS record, the user should consider the result sensitive and not share the information with unnecessary people. First, the email account and any other accounts that may have used the same password should be protected. Then, contact should be made through a verified communication channel with the maintenance provider, support coordinator, or relevant institution to ask which data may have been affected. If a suspicious call, message, or email is received, it should not be responded to directly; the communication should be separately verified through a reliable channel.\u003C\u002Fp>\n\u003Cp>A CTARS violation requires long-term attention due to the context of health and care. The affected person or their representative should monitor signs of identity misuse, unexpected service requests, account recovery notifications, and suspicious official correspondence. When password security, authentication, and fraud awareness are not addressed together, the impact of such sensitive data breaches can last for years. Therefore, the record should be considered as a broader personal security and privacy action rather than a one-time password alert.\u003C\u002Fp>","","CTARS Data Breach (12.3 Thousand Reported Records)","CTARS Data Breach. 12.3 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fctars_com_au.webp",false,{"name":44,"sector":45,"country":46,"website":9,"websiteArchiveUrl":38,"websiteStatus":38,"websiteCheckedAt":23},"CTARS","Client management software for disability and care services","Australia"]