Disclosures · Department of Home Affairs

Two Pages of the Government's Optus Response: Notified the Night Before, Drafting Statutory Directions by Day Three

A single chronology, compiled for a Senate Estimates hearing and released under FOI, records what Home Affairs did in the eleven days after the Optus data breach. It was told the evening before Optus went public, spent the following Saturday drafting correspondence under two separate Acts, and received a second mandatory incident report about a different issue a week in.

Not every FOI release is a document set. This one is two pages, and one of them is a signature block. What survives is a single table: a chronology of the Australian Government’s response to the Optus data breach, compiled inside the Department of Home Affairs for the October 2022 Budget Estimates hearing and emailed to the department’s estimates team at 2.10pm on Friday 28 October 2022, hours before officials sat down in front of the Legal and Constitutional Affairs Committee.

A chronology is a modest thing. This one is still worth reading, because it fixes times against actions during a fortnight when the public account was necessarily vague.

What was released#

One email, two pages, released in part, published on the Home Affairs disclosure log on 9 December 2022. It is from the department’s Group Manager and Head of the Cyber and Infrastructure Security Centre, Hamish Hansford, to “Senate Estimates”, subject line marked OFFICIAL.

The body is a list of forty-odd entries running from Wednesday 21 September to Saturday 1 October 2022, each giving a date, a time and a line of description. The redactions are minimal: the original email header is removed under s. 22(1)(a)(ii) as irrelevant material, and direct contact details in the signature block under s. 47E(d).

Everything below is from page 1.

The evening before#

The first entry:

Wednesday 21 September, 19.59 – Department informed of cyber incident through a Cyber Incident Report.

Optus made its public statement on 22 September. The chronology puts the department’s formal notification at just before 8pm the evening before, through the mandatory reporting channel rather than through a phone call or a media enquiry.

The second entry, the next morning:

Thursday 22 September, 09.21 – Email from GM CISC to MO notifying of regulatory actions underway post the mandatory cyber incident report.

Regulatory action was under way, and the Minister’s office was told about it, before the day on which the breach became a national story had properly begun.

The Saturday#

The chronology’s centre of gravity is Saturday 24 September, which carries nine separate entries between 10.00 and 21.45. The day begins with a call between the Minister for Home Affairs, her chief of staff, the Secretary, the head of the Cyber and Infrastructure Security Centre, the First Assistant Secretary Legal, and the Director-General and Deputy Director-General of the Australian Signals Directorate.

Ninety minutes later, the department was drafting under statute:

Saturday 24 September, 1133 – Departmental email to MHA/MO with draft inputs required for the proposed correspondence to Optus under s313(3).

Section 313(3) of the Telecommunications Act 1997 is the provision under which carriers are asked to give help reasonably necessary for enforcing the criminal law and protecting public revenue. Three days into the response, the department was preparing to use it.

By late afternoon a second instrument was in play:

Saturday 24 September, 1724 – Departmental email to MHA/MO with draft action direction correspondence and WOG paper on data exchange.

And at nine that night, a third:

Saturday 24 September, 2100 – Departmental email to MHA with AGS advice on the use of SOCI.

The Security of Critical Infrastructure Act 2018 gives government step-in powers over critical infrastructure assets during a cyber incident. Whether it could be used here was a live question at the time, publicly unresolved. The chronology does not say what the Australian Government Solicitor advised. It says when the advice arrived: 9pm on a Saturday, the same hour as a call between the head of the Cyber and Infrastructure Security Centre and Optus’s Vice President for Regulatory and Public Affairs.

At 19.00 the same evening an interdepartmental committee convened by Home Affairs and the Department of the Prime Minister and Cabinet met, with the Attorney-General’s Department, the Australian Signals Directorate, the Office of the Australian Information Commissioner, Infrastructure, Treasury and APRA in attendance. The same committee met again at 13.00 on the Sunday.

The second report#

One entry sits apart from the rest:

Wednesday 28 September, 1339 – Optus made a further mandatory cyber incident report about a separate issue.

A week into a response consuming seven agencies and the Minister’s weekend, the same company lodged a second mandatory report, and the chronology records that it concerned a separate issue. It says nothing further — not the nature of the issue, not the outcome. We could find no public account of a second mandatory report from this period.

Where the timeline stops#

The last entry is:

Saturday 1 September, 1100 – PMC called IDC.

The month is wrong: the entries around it run through late September, and 1 October 2022 fell on a Saturday. It reads as a typing error, and we treat it as one — there is nothing in the document to suggest otherwise.

The more useful observation is where the chronology ends rather than how the last line is dated. It stops on 1 October. The hearing it was written for was on 28 October. Officials went into that hearing with a written chronology covering the first eleven days of the response and nothing about the four weeks immediately preceding their appearance.

What the documents do not say#

Almost everything of substance. This is a list of meetings, calls and emails. It records that AGS advice on SOCI was provided; not what it said. It records that s313(3) correspondence was drafted; not whether it was sent, or what it asked for. It records draft “action direction” correspondence; not the direction.

Nothing about the customers. Forty entries about the machinery of government contain no reference to the people whose data was taken, beyond one internal discussion on 29 September about “impact on Departmental services provided by Optus”.

Nothing after 1 October. The response continued; this record does not.

Nothing about what was decided. Interdepartmental committees are minuted. Those minutes are not here, and on this evidence would be a reasonable thing to ask for next.

How to check this#

Both pages are in the single PDF linked at the top of this page. The document has a text layer, so the quotations can be extracted directly. There are no page references in the quotations above because every quotation is from page 1; page 2 is the signature block.

Two pages is a small release, and this is a short article on purpose. There is no more in it than we have set out here.

Sources

  1. FA 22/11/00128 — Optus timeline from the October 2022 Budget Estimates Briefing Pack — Department of Home Affairs (accessed 2 Aug 2026)
  2. FOI disclosure log 2022 — Department of Home Affairs (accessed 2 Aug 2026)
  3. Telecommunications Act 1997 — s 313 — Federal Register of Legislation (accessed 2 Aug 2026)
  4. Security of Critical Infrastructure Act 2018 — Federal Register of Legislation (accessed 2 Aug 2026)