Bendigo and Adelaide Bank has faced two separate APRA enforcement actions within a week, with the regulator imposing licence conditions over "prevalent" risk management failures just days after the bank admitted breaching its accountability obligations over a 2023 cyber attack.
On 11 August, Bendigo Bank conceded it had breached the Banking Executive Accountability Regime (BEAR) in relation to a cyber attack on its Alliance Bank business, where a hacker exploited weak customer authentication controls between 3 and 7 March 2023. The attacker accessed roughly 257 customer accounts and made 286 unauthorised transactions totalling about $490,000, affecting 87 customers. Notably, penetration testing had flagged a number of the relevant weaknesses back in 2020, but they went unaddressed before the attack occurred. Bendigo Bank has since reimbursed all affected customers and proposed an $8 million pecuniary penalty, subject to Federal Court approval.
A week later, APRA escalated its scrutiny further, imposing formal licence conditions on the bank following an independent Deloitte root cause analysis commissioned in December 2025. The review found non-financial risk management weaknesses "prevalent across the organisation," with material deficiencies in governance, accountability and risk oversight capability that had persisted despite years of remediation under the bank's BEN+ transformation program.
APRA Deputy Chair Therese McCarthy Hockey was measured but firm in her assessment, noting that “Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements.” However, she stressed that "as Australia's sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cyber security systems and practices."
On the broader risk management findings, McCarthy Hockey said the issues identified were "significant, longstanding" and required "decisive action," while acknowledging Bendigo Bank's "constructive and cooperative engagement" with the regulator.
For brokers and their clients, the immediate financial impact is limited — APRA has confirmed it does not currently have concerns about the adequacy of Bendigo Bank's information security controls, and the bank remains well capitalised. The new licence conditions, however, require a comprehensive rectification program and independent assurance.
Alongside the retained $50 million operational risk capital add-on, this signals ongoing supervisory attention that borrowers and property investors banking with Bendigo may want to watch, particularly if remediation costs or governance changes affect service levels or product settings over the coming months.
See the latest APRA media release.
Get the hottest and freshest property and mortgage news delivered right into your inbox. Subscribe now to our FREE daily newsletter.