APRA has launched civil penalty proceedings, seeking an $8 million penalty over authentication control failures that exposed customer accounts
Bendigo and Adelaide Bank has acknowledged breaching its obligations under the Banking Executive Accountability Regime (BEAR) in connection with a March 2023 cyber attack targeting its Alliance Bank business.
The Australian Prudential Regulation Authority (APRA) commenced civil penalty proceedings in the Federal Court following a formal investigation into the incident.
The breach stemmed from significant weaknesses in customer authentication controls for Alliance Bank's online banking platform. These included password settings that permitted very weak passwords, multiple accounts sharing identical passwords, and system design features that allowed a threat actor to identify valid customer IDs.
Notably, some of these weaknesses had been identified through penetration testing conducted in 2020, yet were not remediated before the attack occurred.
Between 3 and 7 March 2023, an unidentified attacker gained access to approximately 257 customer accounts, executing 286 unauthorised transactions totalling around $490,000 across 87 Alliance Bank customers. Bendigo Bank was unable to recover approximately $140,000 of the stolen funds but reimbursed all affected customers in full.
Bendigo Bank has admitted it breached the BEAR by failing to maintain adequate authentication controls to prevent and detect unauthorised account access; conduct systematic testing of Alliance Bank's authentication controls as required under Prudential Standard CPS 234 – Information Security; maintain adequate governance and risk management over the IT system enabling customer digital access; and ensure accountable persons' responsibilities appropriately covered Alliance Bank's IT systems.
The parties have proposed that Bendigo Bank pay a pecuniary penalty of $8 million, subject to court approval. It remains for the Federal Court to determine whether to make the declarations and impose the penalty.
APRA noted that the conduct and control weaknesses at the centre of the proceedings were satisfactorily remediated following the attack and that it holds no current concerns about the adequacy of Bendigo Bank's information security controls.
"Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements," said Therese McCarthy Hockey (pictured right), APRA deputy chair. "However, as Australia's sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cyber security systems and practices.
"While the financial impact of this cyber incident was limited, our court action sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls."
Want to be regularly updated with mortgage news and features? Get exclusive interviews, breaking news, and industry events in your inbox – subscribe to our FREE daily newsletter. You can also follow us on Facebook, X (formerly Twitter), and LinkedIn.