Bendigo and Adelaide Bank Limited (Bendigo Bank) has conceded it has breached its obligations under the Banking Executive Accountability Regime (BEAR) in relation to a 2023 cyber attack involving its Alliance Bank 1 business.
There were significant weaknesses in customer authentication controls for online banking, including password settings that permitted very weak passwords, multiple customer accounts with identical passwords and system design features that enabled a threat actor to identify valid customer IDs.
A number of those weaknesses were identified by penetration testing conducted in 2020 but were not addressed by Bendigo Bank prior to the cyber attack.
As a result, an unidentified hacker was able to conduct an attack between 3 and 7 March 2023 and gain access to approximately 257 customer accounts. During that time, the attacker made 286 unauthorised transactions totalling about $490,000 affecting 87 separate Alliance Bank customers. Bendigo Bank was unable to recover about $140,000 of this money but reimbursed all affected customers.
Following a formal investigation, APRA commenced civil penalty proceedings in the Federal Court yesterday against Bendigo Bank.
Bendigo Bank admits that it breached its obligations under the BEAR by failing to:
- maintain adequate customer authentication controls for the prevention and detection of unauthorised access to Alliance Bank customer accounts;
- undertake a systematic testing program for the customer authentication controls of Alliance Bank as required by Prudential Standard CPS 234 - Information Security;
- have adequate governance and risk management for the information security of the IT system that enabled digital access for customers of Alliance Bank; and
- ensure that the responsibilities of the accountable persons of Bendigo Bank and its subsidiaries appropriately covered the IT system of Alliance Bank.
The parties propose orders in the proceedings that Bendigo Bank pays a pecuniary penalty of $8 million in respect of its contraventions of the BEAR, subject to Court approval. It is a matter for the Court to determine whether the declarations and the imposition of a penalty are appropriate and to make other orders.
The proceedings relate to historical conduct and control weaknesses that were satisfactorily remediated following the cyber attack. APRA does not currently have concerns regarding the adequacy of Bendigo Bank's information security controls.
APRA Deputy Chair Therese McCarthy Hockey said: "Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements. However, as Australia's sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cyber security systems and practices.
"While the financial impact of this cyber incident was limited, our court action sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls."