Statement - AltiusRT Data Exposure Incident
All Australian Hockey Organisations are committed to protecting the privacy and security of our members' information.
We have been notified of an inadvertent data exposure involving the AltiusRT competition management platform which resulted in some personal information being unintentionally accessible. This issue has now been resolved within Hockey platforms.
The AltiusRT platform is used at National Championships, State Championships and some grades of state hockey.
AltiusRT has confirmed that some personal information, dates of birth and email addresses) was unintentionally accessible within the background code of public match pages. While this information was not directly visible, it could have been accessed by individuals with technical knowledge or automated systems that scan web data.
The exposure was limited to athletes who had either scored a goal or received a card during a match and some match/team officials. The majority of affected individuals only had their date of birth exposed whilst a smaller percentage also had their email address included.
The data exposure has impacted multiple hockey organisations. In total, over 40,000 individuals globally were affected, including approximately 21,700 Australians.
The exposure was identified via external independent testing. Whilst there is no evidence of misuse, we are treating this matter seriously and are working with AltiusRT to ensure all necessary protections and compliance measures are in place. We are also engaging with regulatory bodies such as the Office of the Australian Information Commissioner to address compliance obligations under the Notifiable Data Breach scheme and the Privacy Act 1988 (Cth).
Upon being notified of the issue, AltiusRT took immediate action to contain and resolve the exposure. The following measures have been implemented;
- The underlying vulnerability has been fixed, ensuring that affected data is no longer accessible.
- Privacy settings have been strengthened, restricting access to personal information to authenticated users only.
- Additional security controls and database protections have been enhanced to further enhance data integrity.
- Cybersecurity experts have supported the assessment and remediation process, ensuring best-practice security measures are in place.
All Australian Hockey Organisations take cybersecurity seriously and encourage all members of our hockey community to take steps to protect their personal information online. While there is no evidence of misuse, cybercriminals may exploit publicly available data to impersonate trusted organisations or attempt fraud.
To help keep your accounts and personal data safe, we recommend the following:
- Be cautious of unexpected emails or messages claiming to be from hockey organisations.
- Do not click on links or open attachments in unsolicited emails, especially if they ask for login credentials, personal details or financial information.
- Verify emails before responding – If you receive an unexpected email, check the sender’s email address carefully and contact the organisation directly via its official website or phone number.
- Enable Multi-Factor Authentication (MFA) – If available, turn on MFA for your email, banking, and online accounts to add an extra layer of security.
- Monitor your accounts for unusual activity – Watch out for unexpected password reset requests, login attempts from unknown locations or changes to your account details.
- Use strong, unique passwords – Avoid using personal details like your date of birth in passwords or security questions.
We are continuing to monitor the situation and will provide updates if necessary. If you have any concerns or require further information, please contact us at ha@hockey.org.au.
We remain committed to ensuring the security of our members’ information and strengthening protections across all digital platforms used within Australian hockey.
We appreciate the cooperation and understanding of our hockey community as we work to address this matter.














