News Articles

News Articles


When public information becomes a security risk in the AI age

A cloned number plate and an unexpected speeding fine have highlighted a much bigger question for Australian organisations: in the age of AI, how secure is information simply because it is publicly accessible?

When PharmacyID founder Geoff Stockton received a speeding infringement in the mail, his first instinct was that there had been a mistake.

The notice alleged his BMW M3 had been travelling at 84km/h on Ballarat Road in Melbourne's west at 2.50am.

Geoff hadn’t driven a car at that time of night for around 30 years.

On legal advice, he requested the road safety camera image – and immediately realised something was wrong.

The vehicle captured by the camera displayed Geoff's registration number, but the plate wasn’t his. The colours were different. The markings were different. Even the spacing of the characters differed from those on his genuine plate.

Someone appeared to be driving another vehicle using a copy of his registration.

The matter has since been reported to Victoria Police and VicRoads.

But for Geoff, a former Victoria Police Inspector who spent 22 years investigating fraud and identity crime, the speeding fine is only the tip of the iceberg.

He says cloned registration plates could potentially allow stolen vehicles to be driven under the identity of legitimately registered cars – with any speeding, toll or other infringements sent to the innocent registered owner, potentially weeks after the event.

“The speeding fine is the least of my concerns,” Geoff says. “If someone can put a legitimate registration number onto a stolen car that matches its make, model and colour, that vehicle could potentially be driven around appearing to be legitimately registered.

“By the time the real owner receives a fine and realises something is wrong, that car could be long gone. It raises a much bigger question about how cloned plates could be used in other criminal activity and the challenge that creates for police.”

For PharmacyID Head of Technology Michael Everett, the incident raises an equally important question about the information that could potentially enable this type of crime in the first place.

Information doesn’t need to be top-secret to create a risk

Vehicle registration checking services exist for legitimate reasons. A person considering buying a vehicle, for example, may want to confirm basic information about it.

While the Victorian registration checking service prohibits data mining, Michael says an automated program could theoretically be designed to generate large numbers of possible registration combinations and record which searches returned a valid vehicle.

A single vehicle search may reveal little, but potentially millions of searches, if an automated system were able to make them, could create something much more valuable.

“Going back 12 months, you’d have to be an experienced software engineer to do this kind of stuff,” Michael says. “Now you don’t need to be; you can get AI to generate code for you.”

There is no evidence that this is how Geoff’s registration number was obtained, but the theoretical possibility demonstrates an important principle of modern cybersecurity: information that appears relatively harmless in isolation can become far more powerful when it can be collected, combined and analysed at scale.

AI has changed the game

Automation isn’t new, but what’s changed is who can build it.

Tasks that once required considerable programming knowledge can increasingly be undertaken with assistance from generative AI.

“Because AI is very much flavour of the month, this is just one example of how it can potentially be used to pull data together much faster,” Michael says. “The capability is moving incredibly quickly, and organisations have to move with it.”

For Michael, the answer isn’t to fear AI or remove every piece of useful information from the internet. It’s to design systems around the environment in which they now operate.

That means considering rate limits, bot detection, monitoring, access controls, the amount of information returned by a query and whether seemingly harmless data could become sensitive when collected at scale.

Security by design

Every day, Australians provide organisations with some of their most sensitive information to prove who they are, complete a police check or undertake a Verification of Identity.

For PharmacyID, protecting that information isn’t simply about responding to known threats.

It means considering how information could be exploited before a system is built and continuing to reassess those risks as technology changes.

That security posture has included investing in an independent assessment under the Australian Government’s Information Security Registered Assessors Program (IRAP), which assesses ICT systems against Australian Government security standards and controls.

For organisations familiar with government information security requirements, IRAP provides an important independent measure of the maturity of the systems and controls used to protect sensitive information.

“When we talk about security posture, a lot of organisations in Australia simply aren’t where they need to be,” Michael says.

“The technology available to people who want to exploit systems is getting more sophisticated and much easier to access.

“Security has to evolve just as quickly.”

shape shape