Bendigo and Adelaide Bank has admitted breaching its obligations under the Banking Executive Accountability Regime (BEAR) in relation to a 2023 cyber attack on its Alliance Bank network, with APRA commencing civil penalty proceedings in the Federal Court over the bank's failure to adequately secure customer accounts.
The bank's customer authentication controls for online banking contained significant weaknesses, including settings that allowed very weak passwords, multiple accounts sharing identical passwords, and system design flaws that let a threat actor identify valid customer IDs.
Penetration testing conducted in 2020 had already identified a number of these weaknesses, but they weren't addressed before the attack occurred.
An unidentified hacker exploited the gaps between 3 and 7 March 2023, gaining access to roughly 257 customer accounts and making 286 unauthorised transactions worth about $490,000 across 87 Alliance Bank customers. Bendigo Bank was unable to recover around $140,000 of that money but reimbursed all affected customers in full.
The parties have proposed a pecuniary penalty of $8 million, subject to Federal Court approval.
Bendigo Bank has admitted it breached its BEAR obligations by failing to maintain adequate authentication controls to prevent and detect unauthorised access, failing to run a systematic testing program as required under Prudential Standard CPS 234, failing to maintain adequate governance and risk management over the Alliance Bank IT system, and failing to ensure accountable persons at the bank and its subsidiaries had appropriate oversight of that system.
APRA said the proceedings related to historical weaknesses that have since been satisfactorily remediated, and the regulator does not currently have concerns about the adequacy of Bendigo Bank's information security controls.
APRA deputy chair Therese McCarthy Hockey said the bank's overall financial position remained sound.
"Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements. However, as Australia's sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cyber security systems and practices," McCarthy Hockey said.
She said the action was intended to reinforce expectations across the sector more broadly.
"While the financial impact of this cyber incident was limited, our court action sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls," McCarthy Hockey said.
Get the hottest and freshest property and mortgage news delivered right into your inbox. Subscribe now to our FREE daily newsletter.