Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →TPG Telecom disclosed on 14 December 2022 that a Hosted Exchange service used by iiNet and Westnet business customers had been accessed without authorization. Accounts for up to 15,000 business customers were hosted on the affected service; TPG did not say that every account was individually accessed or that information was stolen.
What happened to iiNet and Westnet business email?
TPG said its external cyber security advisers, Mandiant, informed it on 13 December 2022 that they had found evidence of unauthorized access to a Hosted Exchange service hosting email accounts for iiNet and Westnet business customers. Mandiant found the access during a forensic historical review conducted as part of its ongoing work to help protect TPG from cyber threats. TPG’s announcement was authorized for lodgement by its board and filed with the Australian Securities Exchange on 14 December 2022. Read TPG’s ASX announcement.
Hosted Exchange was described at the time as a Microsoft product operated by iiNet and Westnet to provide email service. The incident account identifies unauthorized access to that service; it does not establish that Microsoft itself was breached. The Guardian’s contemporaneous coverage provides this service context.
Was financial information stolen?
TPG said preliminary analysis suggested the threat actor’s primary aim was to search for customers’ cryptocurrency and financial information. That was the company’s early assessment of the actor’s apparent objective, not confirmation that financial information—or any other information—was viewed, copied, or taken. TPG said the investigation into the incident and its potential impact was continuing. Contemporaneous reporting also said the company had not specified what, if anything, might have been obtained. The Guardian reported on the unresolved scope.
#1 Best Overall
The available public account does not establish the final forensic findings, whether information was exfiltrated, or which customers’ information may have been viewed. Treat claims that customers’ financial details were stolen as unconfirmed.
Were residential iiNet or Westnet customers affected?
TPG said the incident did not affect home or personal iiNet and Westnet products, including broadband and mobile. Its disclosure concerned business customers’ email accounts on the Hosted Exchange service, not a reported breach of residential internet or mobile services.
Rank #2
- Pass the Securing Email with Email Security Appliance 300-720 SESA with updated flashcards packed with detailed content aligned to the latest exam blueprint. Cover all core topics without the overload found in lengthy study guides. Get 300+ Securing Email with Email Security Appliance 300-720 SESA flashcards on 8-1/2″ x 11″ perforated card stock.
What did TPG do after discovering the access?
TPG said it had stopped the unauthorized access, implemented additional security measures, begun contacting affected Hosted Exchange customers, and notified relevant government authorities. It said it would communicate directly with affected customers as further information became available.
Incident timeline
| Date | What TPG reported |
|---|---|
| 13 December 2022 | Mandiant advised TPG it had found evidence of unauthorized access during a forensic historical review. TPG ASX announcement. |
| 14 December 2022 | TPG announced the incident to the ASX, describing the affected Hosted Exchange service, its preliminary assessment of the actor’s aim, and its response. TPG ASX announcement. |
| 14–15 December 2022 | Contemporaneous coverage noted that the incident’s scope and data impact remained under investigation. The Guardian’s report. |
What should TPG customers do about suspicious messages?
For general protection against impersonation, TPG’s current support guidance warns customers not to provide passcodes, passwords, dates of birth, addresses, or payment details through links in emails claiming to be from TPG. The page also explains how to report suspicious calls, texts, and emails. This is general current advice, not a specific instruction tied to the 2022 Hosted Exchange incident. See TPG’s scam guidance.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Best Value
- XGS 88W with 1 Year Xstream Protection - Next-generation firewall appliance with Xstream Protection subscription providing zero-day defense, cloud sandboxing, email filtering, intrusion prevention, and advanced reporting, managed through Sophos Central for unified policies and reporting.
- Built in Wi Fi 6 with 4 x 2.5 GE copper ports, delivering up to 9.9 Gbps firewall performance for secure wired and wireless networks.
- Zero day protection with cloud sandboxing, email filtering, and advanced reporting for full enterprise coverage.
- TLS inspection and next generation intrusion prevention block hidden threats in encrypted traffic and stop sophisticated attacks.
- Includes Xstream Protection – Advanced security bundle with zero-day protection, cloud sandboxing, email filtering, and automated threat response, providing full coverage against the most sophisticated cyberattacks.
Rank #4
- XGS 108 with 1 Year Xstream Protection - Next-generation firewall appliance with Xstream Protection subscription providing zero-day defense, cloud sandboxing, email filtering, intrusion prevention, and advanced reporting, managed through Sophos Central for unified policies and reporting.
- 6 x 2.5 GE copper ports and 1 SFP fiber port, supporting up to 12.5 Gbps firewall performance for growing business networks.
- Zero day protection with cloud sandboxing, email filtering, and advanced reporting for full enterprise coverage.
- TLS inspection and next generation intrusion prevention block hidden threats in encrypted traffic and stop sophisticated attacks.
- Includes Xstream Protection – Advanced security bundle with zero-day protection, cloud sandboxing, email filtering, and automated threat response, providing full coverage against the most sophisticated cyberattacks.
Rank #3
- Pass the Securing Email with Email Security Appliance with updated flashcards packed with detailed content aligned to the latest exam blueprint. Cover all core topics without the overload found in lengthy study guides. Get 300+ Securing Email with Email Security Appliance flashcards on 8-1/2″ x 11″ perforated card stock.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

