Bendigo and Adelaide Bank has acknowledged failures nether the banking enforcement accountability authorities successful transportation with a 2023 cyber incidental affecting its Alliance Bank unit.
The substance relates to "significant weaknesses" successful online banking authentication, the Australian Prudential Regulation Authority (APRA) said.
These included password rules that allowed highly anemic passwords, cases wherever antithetic customers had the aforesaid password, and plan issues that allowed an attacker to enactment retired valid lawsuit IDs.
Some of these problems had already been flagged successful penetration investigating successful 2020, but Bendigo Bank did not hole them earlier the attack, the regulator noted.
Between 3 and 7 March 2023, an chartless hacker accessed astir 257 lawsuit accounts.
Over that period, 286 unauthorised transactions worthy astir A$490,000 were carried out, affecting 87 Alliance Bank customers.
The slope could not retrieve astir A$140,000, though it repaid each customers who were impacted.
After a ceremonial investigation, APRA filed civilian punishment proceedings successful the national court.
Bendigo Bank has admitted it failed to support capable authentication controls successful spot to forestall and observe unauthorised entree to Alliance Bank lawsuit accounts.
Bendigo Bank CEO and managing manager Richard Fennell said: "Our customers tin beryllium assured that erstwhile identified, we acted instantly to code the issue, and made definite each impacted customers were afloat reimbursed.
"Bendigo Bank acknowledges APRA's important relation successful maintaining a beardown and accountable banking system. We proceed to enactment actively and constructively with our regulators successful narration to the antecedently disclosed autarkic non-financial hazard review. We volition update the marketplace connected our effect successful owed course."
It besides admitted it did not transportation retired a systematic investigating programme for those controls arsenic required nether Prudential Standard CPS 234 - Information Security.
Additionally, the slope did not support capable governance and hazard absorption for the accusation information of the IT strategy utilized for Alliance Bank lawsuit integer access.
The parties person projected that Bendigo Bank wage a pecuniary punishment of A$8m for the contraventions, taxable to support by the court.
APRA lawman seat Therese McCarthy Hockey said: "Bendigo Bank is financially dependable and comfortably supra its halfway superior and liquidity requirements. However, arsenic Australia's sixth largest bank, we expect Bendigo Bank to person robust and blase cyber information systems and practices.
"While the fiscal interaction of this cyber incidental was limited, our tribunal enactment sends a wide connection that each APRA-regulated entities indispensable person due cyber extortion systems and regularly trial the adequacy of those controls."

4 days ago
12








English (CA) ·
English (US) ·
Spanish (MX) ·