Brought to you by:

Bank faces record penalty over cybersecurity failings

Bendigo and Adelaide Bank faces an $8 million fine over failings that enabled a hacker to make more than 280 unauthorised transactions from customer accounts.

The regional lender “acknowledges and accepts responsibility” for the 2023 cyberattack, according to a statement of agreed facts and admissions made to the Federal Court.

Civil penalty proceedings were launched last week by the Australian Prudential Regulation Authority.

APRA and Bendigo Bank have proposed the lender pay a pecuniary penalty of $8 million for breaching its obligations under the Banking Executive Accountability Regime (BEAR).

The cyberattack from March 3-7 2023 targeted Bendigo’s Alliance Bank customers. The hacker gained access to about 257 customer accounts and made 286 unauthorised transactions totalling about $490,000, affecting 87 customers.

The bank was unable to recover about $140,000 of that money but reimbursed all affected customers.

Security weaknesses identified by penetration testing in 2020 had not been addressed by the bank.

“There were significant weaknesses in customer authentication controls for online banking, including password settings that permitted very weak passwords … and system design features that enabled a threat actor to identify valid customer IDs,” APRA said.

“The proceedings relate to historical conduct and control weaknesses that were satisfactorily remediated following the cyberattack.”

APRA deputy chair Therese McCarthy Hockey says the action sends a “clear message that all regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls”.

Herbert Smith Freehills Kramer partner Christine Wong says the proposed fine would be the largest to date for a cyber failing.

“Expect that penalties for the same conduct today would be higher (noting that this occurred in 2023), with growing regulatory expectations,” she wrote on LinkedIn.

“This also confirms continued focus on executives for management of these risks under the then BEAR (now Financial Accountability Regime).

“This extends in a similar way to directors and officers under general directors’ duties.”