Bendigo and Adelaide Bank is facing a proposed $8 million penalty after admitting to numerous cybersecurity failures in the lead-up to an incident involving almost $500,000 in unauthorised transactions.
In March 2023, an unidentified hacker exploited weaknesses in the bank’s online banking systems to gain brute-force access to about 257 customer accounts at the since-discontinued Service One Alliance Bank business.
The attacker used weaknesses in the Alliance Bank online banking platform to lodge 286 unauthorised transactions worth about $490,000 across 87 separate customers.
On Tuesday, Australia’s financial safety watchdog announced Bendigo Bank had conceded to breaching its obligations under the Banking Executive Accountability Regime (BEAR) – a legislative framework designed to keep authorised deposit-taking institutions and their senior executives accountable.
The Australian Prudential Regulation Authority (APRA) pointed out “significant weaknesses in customer authentication controls for online banking” leading up to the cyberattack.
These included “password settings that permitted very weak passwords”, multiple customer accounts with identical passwords, and system design features that enabled the threat actor to identify valid customer IDs.
“At the time that the Cyber Attack started, there were 1,598 accounts of Service One Alliance Bank customers that were protected by the password ‘123456’,” read court documents.
Following a formal investigation, APRA has commenced civil penalty proceedings against Bendigo Bank in the Federal Court.
Information Age understands both parties have jointly proposed a pecuniary penalty of $8 million, subject to court approval.
“Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements,” said APRA deputy chair Therese Hockey.
“However, as Australia’s sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cybersecurity systems and practices.”
Bendigo Bank was unable to recover about $140,000 of the misappropriated funds, but all affected customers were appropriately reimbursed.
In an announcement to the Australian Securities Exchange, the bank accepted the proposed penalty and said it would also incur $2.6 million in additional legal costs.
"Our customers can be assured that once identified, we acted immediately to address the issue, and made sure all impacted customers were fully reimbursed,” said Bendigo Bank chief executive and managing director Richard Fennell.
Issues left unfixed after pentest
APRA noted some of the security weaknesses were identified during penetration testing in 2020, but were not addressed prior to the attack.
The bank also breached BEAR obligations by failing to ensure the “responsibilities of the accountable persons of Bendigo Bank and its subsidiaries” appropriately covered the IT system used by Alliance Bank.
Vaughan Shanks, chief executive of Melbourne-based incident response vendor Cydarm Technologies, said penetration testing is only useful if there is someone prepared to take responsibility for addressing any found vulnerabilities.
“Many software developers do not understand the intent and capability of cyberattackers, so the remediation work doesn’t get prioritised,” Shanks told Information Age.
“This was an issue in 2020 when the pentest was conducted and is an even bigger issue now in the age of automated vulnerability discovery and vibe coding.”
According to court documents, a threat actor attempted to conduct similar brute force login attacks on systems used by Alliance Bank in October 2022.
Though the board was subsequently told Bendigo Bank was at a “critical point of needing further investment in resourcing and capability”, the bank did not “subsequently undertake a substantive review” of the attacks.
The bank admitted it breached BEAR obligations related to Alliance Bank by failing to maintain adequate customer authentication controls, and by neglecting to undertake a systematic testing program for them.
It also conceded there were inadequate governance and risk management arrangements for information security relating to the IT system that provided Alliance Bank customers with digital access.
Penalties an incentive for customer safety
Shanks said financial penalties were necessary to give businesses an incentive to address cybersecurity vulnerabilities.
When asked whether the proposed $8 million penalty was an appropriate resolution, he said fines helped organisations factor cybersecurity risks into their expected financial losses.
“[This enables] regulated entities to calculate the return on investment of fixing these bugs,” said Shanks.
“The financial compensation to customers is insufficient motivation.”
Andrew Kay, director of systems engineering for Asia Pacific and Japan at breach containment platform Illumio, said APRA’s action demonstrated that organisations are “increasingly being held accountable not only for breaches, but for failing to remediate known security risks”.
“The size of the penalty, particularly compared with the relatively small amount of money ultimately lost, also reinforces the importance of governance, oversight and ensuring security controls are maintained, tested and actually work as intended,” Kay told Information Age.
APRA stressed the proceedings related strictly to historical conduct and “control weaknesses” that were satisfactorily remediated after the cyberattack.
The regulator no longer has concerns about the adequacy of Bendigo Bank’s information security controls.
“While the financial impact of this cyber incident was limited, our court action sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls,” said Hockey.