GeekStuff
← Back to News

APRA Seeks $8M Penalty Against Bendigo Bank Over Cyber Control Failures

APRA has commenced Federal Court proceedings against Bendigo and Adelaide Bank, proposing an $8 million civil penalty for breaches of the Banking Executive Accountability Regime (BEAR). The action stems from a March 2023 cyber attack on the bank's former Alliance Bank business, in which an attacker accessed 257 customer accounts, made 286 unauthorised transactions affecting 87 customers, and moved approximately $490,000 — roughly $140,000 of which was never recovered. All affected customers were reimbursed.

APRA's investigation found "significant weaknesses" in Alliance Bank's online banking authentication controls — and the really damning part is that some of these were flagged in penetration testing back in 2020 but were never remediated before the 2023 attack. The bank has admitted it failed to maintain adequate controls, didn't run systematic testing on those controls, and lacked proper governance and risk management over the IT system underpinning digital access.

The basic password failures

  • Permitted very weak passwords with no meaningful complexity requirements
  • Allowed multiple customer accounts to share identical passwords
  • Exposed a feature that let an attacker enumerate valid customer IDs — effectively handing over half the login puzzle

Lessons for businesses of any size

  • A penetration test is worthless if the findings sit in a drawer. Every "high" or "critical" finding needs a remediation deadline, not just a report.
  • Password policies aren't red tape. If your system accepts "password123", so will an attacker. Enforce minimum complexity and block common passwords.
  • Someone needs to own cybersecurity accountability — not just in name, but with actual oversight of the systems they're responsible for.

The Federal Court still needs to approve the $8M penalty, but the message is clear: regulators expect businesses to fix known weaknesses, not just identify them.