Optus, owned by Singapore Telecommunications, is Australia’s second-largest telecommunications company and has suffered three catastrophic failures in three years: a 2022 data breach exposing millions of customer records, a November 2023 national outage that cost the chief executive her job, and a firewall upgrade on 18 September 2025 that caused roughly 600 Triple Zero calls to fail over about 13 hours, with deaths linked to the failure. The regulator has taken it to the Federal Court.
The Optus sequence is the most serious corporate governance failure in Australian telecommunications, and it is a failure of operational risk management rather than of strategy or finance. The company had a viable business, a competitive network and adequate capital throughout. What it did not have was the discipline to ensure that routine changes to critical infrastructure could not disable the one service that must never fail. This article covers what happened and what it means for anyone running critical systems.
Who owns Optus?
Singapore Telecommunications, which acquired it in 2001. Singtel board directors have appeared before an Australian parliamentary inquiry into the 2025 outage, which raised foreign ownership of critical infrastructure as a public issue.
What happened in September 2025?
A routine firewall upgrade beginning around 12:30am on 18 September caused Triple Zero calls to fail intermittently across four states and territories for around 13 hours. Approximately 600 calls failed and deaths were linked to the outage.
What are the consequences?
More than A$12 million in infringement notice penalties across Singtel Optus subsidiaries, Federal Court proceedings brought by ACMA, an independent review led by Dr Kerry Schott AO, and a parliamentary inquiry.
How did Optus become Australia’s second carrier?
By being created for the purpose. Optus emerged from the deliberate introduction of competition into Australian telecommunications, acquiring the government’s AUSSAT satellite operator and building a mobile network and fixed infrastructure to compete with the incumbent. It became the country’s second full-service carrier by design rather than by market evolution.
Singapore Telecommunications acquired it in 2001, giving Optus access to the capital of a large regional carrier and giving Singtel a substantial position in a developed, high-margin market. For two decades that arrangement worked commercially, with Optus holding a solid second position in mobile and competing effectively on price and content.
The ownership structure has become a political issue only recently. When Singtel board directors appeared before an Australian parliamentary inquiry into the 2025 outage, questions about foreign ownership of critical infrastructure were raised directly, and the company deflected them. That is a new form of exposure for a business that had operated without controversy on the point for twenty years.
What happened in the 2022 data breach?
Personal information belonging to millions of current and former customers was exposed, including in many cases identity document details such as passport, licence and Medicare numbers. It was among the largest breaches in Australian history by number of affected individuals and it triggered a national response.
The consequences extended well beyond Optus. Because identity document numbers were exposed, state and federal governments faced the cost of reissuing licences and passports, banks faced elevated fraud risk, and the incident directly influenced the substantial increase in Australian privacy penalties that followed. A single company’s security failure became a national identity infrastructure problem.
The regulatory legacy is the more important part. Australia raised maximum penalties for serious or repeated privacy breaches dramatically in the wake of the Optus and Medibank incidents, moving from a nominal amount to figures calculated on turnover. Data security moved from a compliance line item to a board risk in Australian companies almost overnight.
What went wrong in September 2025?
A change to firewall systems, described as a regular upgrade, began at approximately 12:30am on Thursday 18 September 2025 and caused Triple Zero calls to fail intermittently across the Northern Territory, South Australia, Western Australia and New South Wales. Normal calls were unaffected, which is why the failure went undetected for so long.
That detail is the heart of the failure. Because ordinary calls continued working, standard network monitoring showed a healthy network. The specific path that emergency calls take was broken while everything else functioned, and Optus did not have monitoring capable of detecting that a critical subset of traffic was failing. The outage ran roughly 13 hours before resolution.
Approximately 600 emergency calls failed and at least four people who attempted to reach Triple Zero during the outage were confirmed to have died. Optus accepted full accountability, commissioned an independent review led by Dr Kerry Schott AO, and appointed external consultants to provide oversight and quality assurance over its network management processes.
What is the regulatory response?
Escalating and now litigious. Singtel Optus subsidiaries including Optus Mobile paid more than A$12 million in infringement notice penalties for breaches relating to emergency calls, and the Australian Communications and Media Authority subsequently commenced Federal Court proceedings over the 2025 outage.
The regulator was explicit about why. The recurrence of a major network outage affecting emergency calls so soon after the November 2023 outage was cited as a significant reason for taking the matter to court rather than settling administratively, with ACMA stating it would not hesitate to take strong enforcement action where telco failures jeopardised access to emergency services.
The systemic dimension is what makes this more than one company’s problem. TPG Telecom suffered a comparable emergency calling failure in November 2025 due to outdated software, with a death also confirmed, and a subsequent Telstra outage affected Triple Zero calls as well. Three carriers failing on the same function within roughly a year suggests a sector-wide problem in how emergency call paths are engineered, tested and monitored.
What should boards take from this?
First, that criticality is not the same as volume. Emergency calls are a minuscule fraction of network traffic and the only fraction that cannot fail. Systems should be engineered, monitored and change-controlled in proportion to consequence rather than to usage, and most organisations do the opposite by default.
Second, that repeated incidents are governance failures rather than bad luck. A single outage is an operational event. Three catastrophic failures in three years indicates that the lessons from each were not converted into structural change, and that is a board accountability question. The independent review and external quality assurance arrangements are the standard remedy, and they arrive after the damage.
Third, that ownership structure matters when public trust collapses. A foreign-owned operator of critical national infrastructure faces political scrutiny that a domestic one does not, and Singtel directors apologising before an Australian parliamentary committee is a form of exposure no commercial risk register captures. Companies operating critical infrastructure in another country should assume that a serious failure becomes a sovereignty debate.
How did the breach change Australian privacy law?
By making the maximum penalty large enough to matter. Before the Optus and Medibank incidents, the maximum penalty for a serious or repeated privacy breach was small enough that many organisations treated it as a cost of doing business. Australia subsequently raised it dramatically, calculated by reference to turnover or the benefit obtained.
The change in quantum produced a change in behaviour. Data security moved from an information technology budget line to a board risk register item, and questions about what data is held, why, and for how long began appearing in audit committee papers. That shift is the most durable consequence of the breach.
Broader reform followed, covering the definition of personal information, direct rights of action for individuals, and obligations around data retention and destruction. The direction is toward the European model of treating personal data as something an organisation holds under obligation rather than owns outright, and Australian companies handling consumer data should plan on that basis.
What does the independent review process achieve?
It establishes facts that the company cannot credibly establish itself. Optus commissioned a review led by Dr Kerry Schott AO to examine the technical, operational and governance factors contributing to the outage, with findings to be reported to the board and subsequently made public, and separately appointed external consultants for oversight and quality assurance.
The structure matters. A reviewer with public standing, reporting to the board rather than to management, with a commitment to publication, produces findings that regulators and parliamentary committees will accept. An internal review reaching the same conclusions would not, regardless of its rigour.
The limitation is timing. Independent reviews are commissioned after the failure, and their value depends entirely on whether the recommendations are implemented and verified. Optus had already been through the aftermath of a 2022 breach and a 2023 outage before the 2025 failure occurred, which is the strongest argument that post-incident reviews are necessary but not sufficient.
What does this mean for critical infrastructure obligations?
Australia has been progressively tightening obligations on operators of systems of national significance, covering telecommunications, energy, water, health and finance, with requirements around risk management programmes, incident reporting and in some cases government assistance powers during a serious incident.
The Optus and TPG emergency calling failures accelerated that direction for telecommunications specifically. Emergency call access is being reframed from a licence condition into a resilience obligation with mandatory testing, monitoring and reporting requirements, and the regulator has demonstrated it will litigate rather than negotiate when the obligation is breached.
For any operator of critical services, the practical implication is that regulators now expect evidence rather than assurance. Demonstrating that a critical function works requires continuous independent testing that produces a record, not an internal statement that the systems are monitored. Organisations that cannot produce that evidence after an incident are in a materially worse position than those that can.
The commercial consequence is easy to underestimate. Optus competes in a market where the leading rival’s entire positioning is reliability, and three public failures in three years hands that rival its marketing message for free. Winning back a customer who left because they could not reach emergency services is not a pricing problem or a service problem; for many households it is simply not achievable at any price. Reputational damage of that kind shows up in churn for years after the incident has left the news cycle.
Frequently Asked Questions
Who owns Optus?
Singapore Telecommunications acquired Optus in 2001 and remains its owner. Singtel board members appeared before an Australian parliamentary inquiry following the September 2025 emergency calling outage.
What caused the September 2025 Optus outage?
A routine firewall upgrade beginning around 12:30am on 18 September 2025, which caused Triple Zero calls to fail intermittently across four states and territories for around 13 hours while ordinary calls continued working normally.
How many people died?
At least four people who attempted to call Triple Zero during the outage were confirmed to have died, with approximately 600 emergency calls identified as having failed.
What penalties has Optus faced?
Singtel Optus subsidiaries paid more than A$12 million in infringement notice penalties relating to emergency call breaches, and ACMA has commenced Federal Court proceedings over the 2025 outage.
Discover more from Kurums | Business Intelligence
Subscribe to get the latest posts sent to your email.


