Brokernews.Au
Bendigo Bank Faces $8M Penalty for 2023 Cyberattack Breaches
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Bendigo and Adelaide Bank admitted to breaching the Banking Executive Accountability Regime (BEAR) following a cyberattack in March 2023 that compromised 257 customer accounts. An unidentified hacker exploited significant weaknesses in the bank's online banking authentication controls, including weak password settings and flaws that allowed valid customer IDs to be identified. The attack resulted in 286 unauthorized transactions totaling $490,000, with the bank unable to recover approximately $140,000. APRA has initiated civil penalty proceedings in the Federal Court, proposing an $8 million penalty for the bank's failure to maintain adequate security measures. Although historical weaknesses were identified during a 2020 penetration test, they were not remediated before the attack occurred. Bendigo Bank has since addressed these vulnerabilities, and APRA does not currently have concerns regarding the bank's information security controls. However, the regulator emphasizes the need for robust cybersecurity practices in major financial institutions.
Key Points: • Bendigo Bank faces an $8 million penalty for breaching cybersecurity accountability laws. • The 2023 cyberattack compromised 257 customer accounts and involved unauthorized transactions totaling $490,000. • Significant weaknesses in authentication controls were identified but not remediated prior to the attack.