Tessera tenants weigh their options after cloud-key breach

Customer Reactions
Data Breach

Publication: The Digital Ledger (Australia) Date: 12 March 2025 Author: Laura King

Tessera is working to retain enterprise tenants after its February data breach, with at least one major customer publicly reassessing the relationship and the company bracing for churn.

The Perth-based platform notified the Office of the Australian Information Commissioner last month after a long-lived cloud access key, exposed through a public source-code repository, was used to read roughly 14,000 tenant records. Tessera has told tenants the exposure arose from a leaked static key and an unsegmented network path, and that encryption and multi-factor authentication were not the point of failure.

For tenants, the technical detail has cut two ways. Several told The Digital Ledger that the company’s openness about the cause — a static key and a missing segmentation boundary rather than a phished login — was more reassuring than a vague “sophisticated attack” would have been. Others said the specifics were precisely what worried them.

“It’s the kind of failure that’s easy to explain and hard to forgive,” said a technology lead at a mid-sized tenant who asked not to be named. “A static key in a public repo shouldn’t exist in 2025. The question I have to answer for my board is whether the rest of their environment is built the same way.”

Olivia Tan, Director of Operations at Northbridge Group, an enterprise tenant, said the incident had prompted a formal review. “We hold our suppliers to the same bar we’re held to,” she said. “Tessera notified us promptly and were clear about what happened and what they’re fixing. That counts for something. But we’ll make a decision on the relationship on the basis of the remediation, not the apology.”

Tessera has said it expects around 23 tenants not to renew as a consequence of the incident, and has put the first-year impact at roughly $1.8 million. The company is offering affected individuals support and has stood up a dedicated contact line.

Industry observers said the churn figure will be the real test of how the incident lands. “Notification speed gets you credit, but retention is decided by whether tenants believe the root cause is fixed,” said Amanda Lewis, a technology analyst at TechVentures. “For a multi-tenant provider, the segmentation question is the one every customer will now ask.”

Tessera said the breach has accelerated its ISO/IEC 27001:2022 certification-readiness programme and its work to remove static access keys and complete control-plane isolation. Whether that is enough to hold its enterprise base will become clearer at renewal.