Bendigo and Adelaide Bank has acknowledged failures under the banking executive accountability regime in connection with a 2023 cyber incident affecting its Alliance Bank unit.

The matter relates to “significant weaknesses” in online banking authentication, the Australian Prudential Regulation Authority (APRA) said.

Access deeper industry intelligence

Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.

Find out more

These included password rules that allowed extremely weak passwords, cases where different customers had the same password, and design issues that allowed an attacker to work out valid customer IDs.

Some of these problems had already been flagged in penetration testing in 2020, but Bendigo Bank did not fix them before the attack, the regulator noted.

Between 3 and 7 March 2023, an unknown hacker accessed about 257 customer accounts.

Over that period, 286 unauthorised transactions worth roughly A$490,000 were carried out, affecting 87 Alliance Bank customers.

The bank could not recover about A$140,000, although it repaid all customers who were impacted.

After a formal investigation, APRA filed civil penalty proceedings in the federal court.

Bendigo Bank has admitted it failed to keep adequate authentication controls in place to prevent and detect unauthorised access to Alliance Bank customer accounts.

Bendigo Bank CEO and managing director Richard Fennell said: “Our customers can be assured that once identified, we acted immediately to address the issue, and made sure all impacted customers were fully reimbursed.

“Bendigo Bank acknowledges APRA’s important role in maintaining a strong and accountable banking system. We continue to work actively and constructively with our regulators in relation to the previously disclosed independent non-financial risk review. We will update the market on our response in due course.”

It also admitted it did not carry out a systematic testing programme for those controls as required under Prudential Standard CPS 234 – Information Security.

Additionally, the bank did not maintain adequate governance and risk management for the information security of the IT system used for Alliance Bank customer digital access.

The parties have proposed that Bendigo Bank pay a pecuniary penalty of A$8m for the contraventions, subject to approval by the court.

APRA deputy chair Therese McCarthy Hockey said: “Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements. However, as Australia’s sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cyber security systems and practices.

“While the financial impact of this cyber incident was limited, our court action sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls.”

Affected customers of Alliance Bank were fully reimbursed, the bank said in an exchange filing.

The matter was limited to the Service One Alliance Bank business and systems, which are no longer in operation, and all remaining remediation work has been completed.

Meanwhile, late last year, Bendigo Bank agreed to acquire the retail lending and deposit business of RACQ Bank.

The acquisition will see the transfer of more than 90,000 RACQ Bank customers to Bendigo Bank, pending regulatory approval.