‘Shocking’ data breach at major smoke alarm provider leaves homeowners at risk

In an age where our personal information is as valuable as currency, the security of our data is paramount.

Unfortunately, a recent incident is a wake-up call for all homeowners, especially those of us who have grown to rely on the convenience and safety that modern technology provides.



A major Australian smoke alarm provider, Smoke Alarm Solutions, has been at the centre of a data breach that left an alarming amount of customer information exposed online for nearly three months.

This oversight has potentially put hundreds of thousands of individuals at risk of being targeted by unscrupulous criminals.


shutterstock_745714324.jpg
A smoke alarm provider has been at the centre of a data breach for exposing customer information online for almost three months. Credit: Shutterstock


Cybersecurity Researcher Jeremiah Fowler discovered that the company, which operates across New South Wales, Victoria, Queensland, and South Australia, failed to protect 762,856 documents, amounting to 107GB of data.

Fowler reported they included over 355,000 detailed invoices, records of inspections, compliance reports, electrical safety inspections, service quotes, and service reports, all dated from 2021 to 2024.

It comes on the heels of a warning from the Australian Competition and Consumer Commission (ACCC) about a surge in fake invoice scams, which have already cost Australians over $16 million in the past year.

‘It’s very likely [the information was accessed by hackers] actually, because the bad guys are looking for the same data that I’m looking for, except when I find it I verify, validate and report it, but the bad guys are using it as a tool for scams, phishing attempts, anything they can get,’ Fowler said.

‘In this case you had templates of thousands of invoices. This company offers subscription services, you can see when the subscription is going to expire.’

‘So, for example, you wait until about one month before it expires and say, “Hey, we’re going to give you a 50 per cent discount,”’ Fowler added.



Fowler said the documents from Smoke Alarm Solutions contained ‘details only the company and the homeowner would know’, such as the locations of smoke alarms, types installed, and the dates of last work orders.

The breach was not addressed for months, even after Fowler's initial disclosure to the company.

‘I literally emailed them a follow-up email [after the initial disclosure] and was like, “Guys, it’s still available,”’ he said.

‘A month-and-a-half in, I actually sent them links to the cloud hosting providers on how to secure data, and it still stayed open for another month.’

‘Based on the circumstances of the alleged incident as instructed by our client, the alleged incident does not, in our view, constitute a notifiable data breach under the Act, and therefore our client is not required to notify either the authorities or any individual about such alleged incident,’ Smoke Alarm Solutions’ legal representative said to Fowler in a statement.

It is understood that Smoke Alarm Solutions had been contacted for comment.



In Australia, smoke alarms are mandatory in every home. According to IBISWorld, the fire and security alarm installation service industry is worth around $4 billion annually.

‘In Australia, it’s an interesting dynamic because you’re required to have a smoke alarm, you’ve got the penalty of law, and you’ve got a company that’s going to take care of that for you,’ Fowler said.

This comes after ACCC advised people to thoroughly check their invoices.

Victims usually only figure out they've been scammed when the real business contacts them about the unpaid invoice.

Large industries like real estate and construction are often targeted because they involve large amounts of money. Recently, scammers have also targeted travel companies and car dealerships.



However, scammers also operated on a smaller scale, sometimes pretending to be road services and asking people to pay overdue tolls.

‘Scammers are sophisticated criminals and are becoming more targeted in how they exploit Australian consumers and businesses,’ ACCC Deputy Chair Catriona Lowe said.

‘These criminals are posing as genuine businesses that a consumer has recently dealt with, sending fake invoices with altered payment details so that the money ends up with the scammer.’
Key Takeaways
  • A major Australian smoke alarm company experienced a significant data breach, leaving sensitive customer information exposed online for almost three months.
  • Cybersecurity Researcher Jeremiah Fowler discovered the unsecured database, which included detailed invoices and personal client information, highly likely accessed by hackers.
  • The data breach comes as the ACCC has reported a surge in fake invoice scams targeting Australians, with losses exceeding $16 million over the past year.
  • Although notified of the breach, Smoke Alarm Solutions delayed securing the database, and a legal representative claimed the incident did not constitute a notifiable data breach under the law.
Have you ever encountered a similar scam? What measures do you take to ensure your personal information remains secure? Let us know in the comments below.
 
Sponsored
As storage of our personal information is done more conveniently by computer rather than by card-index, and said computers are commonly linked to the internet, then I am surprised that hackers and scammers haven't sent all of us bankrupt already.

Since we have decided to live a in a world of digital "convenience" perhaps our private information gathered by any company should be stored on equipment that is not attached to the internet, if that is indeed possible given that every electro-magnetic gadget gives out some form of radio signal when active.
 
As storage of our personal information is done more conveniently by computer rather than by card-index, and said computers are commonly linked to the internet, then I am surprised that hackers and scammers haven't sent all of us bankrupt already.

Since we have decided to live a in a world of digital "convenience" perhaps our private information gathered by any company should be stored on equipment that is not attached to the internet, if that is indeed possible given that every electro-magnetic gadget gives out some form of radio signal when active.
An interesting thought about the storage of private information.
 
Yes, I have received multiple attempted scams from various sources but I have learned to easily recognise them. Many of them are supposedly from companies that I haven't dealt with. Those from companies that I HAVE dealt with are easily verifiable.

My advice to anyone is if you don't recognise the company concerned, ignore it. If in the case the company is one that you have dealt with, is to check with the supposed service provider to verify the invoice.

Under NO circumstances whatsoever, EVER click on ANY link provided by the message or email making the claim. If it's in the form of a phone call from any unverifiable caller, simply hang up and block the caller's number immediately, doing the same for any further unsolicited calls for the same matter.

Again, DO NOT respond by following any web link or calling any phone number the caller asks you to call.
 
  • Like
Reactions: Abby2
Indeed yes. So we have to take the trouble to try to contact the company and that entails maybe working through the automatic answering machine service that at the end will tell us that due to the unexpected large number of telephone calls we have to wait.... for how long? And how many companies? Just put the bill in the post and wait till it gets to me and then I will pop down to the Post Office and use a cheque to do a BillPay. That fixes the problem. All bills arriving at my internet address get deleted as a matter of security.. Finish.
 
  • Like
Reactions: Abby2
Indeed yes. So we have to take the trouble to try to contact the company and that entails maybe working through the automatic answering machine service that at the end will tell us that due to the unexpected large number of telephone calls we have to wait.... for how long? And how many companies? Just put the bill in the post and wait till it gets to me and then I will pop down to the Post Office and use a cheque to do a BillPay. That fixes the problem. All bills arriving at my internet address get deleted as a matter of security.. Finish.
That is all good but a lot of banking companies are cancelling cheque accounts.
And these automatic answering service that at the end will tell us that due to the unexpected large number of telephone calls we have to wait.... for how long? Such a time waster that is.
 
Cash and cheques need to be made an election, issue; as does cybersecurity against Big Brother government snooping via use of whatever systems we use to pay bills etc.
 
  • Like
Reactions: Abby2

Join the conversation

News, deals, games, and bargains for Aussies over 60. From everyday expenses like groceries and eating out, to electronics, fashion and travel, the club is all about helping you make your money go further.

Seniors Discount Club

The SDC searches for the best deals, discounts, and bargains for Aussies over 60. From everyday expenses like groceries and eating out, to electronics, fashion and travel, the club is all about helping you make your money go further.
  1. New members
  2. Jokes & fun
  3. Photography
  4. Nostalgia / Yesterday's Australia
  5. Food and Lifestyle
  6. Money Saving Hacks
  7. Offtopic / Everything else

Latest Articles

  • We believe that retirement should be a time to relax and enjoy life, not worry about money. That's why we're here to help our members make the most of their retirement years. If you're over 60 and looking for ways to save money, connect with others, and have a laugh, we’d love to have you aboard.
  • Advertise with us

User Menu

Enjoyed Reading our Story?

  • Share this forum to your loved ones.
Change Weather Postcode×
Change Petrol Postcode×