Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

APRA seeks $8m Bendigo cyber control penalty

A major prudential action has put digital controls and accountability under scrutiny at Australia’s sixth-largest bank.

user icon Charlie Tchetchenian Tue, 11 Aug 2026
APRA seeks $8m Bendigo cyber control penalty

The Australian Prudential Regulation Authority (APRA) has commenced Federal Court proceedings against Bendigo and Adelaide Bank, seeking approval for an $8 million penalty after the bank admitted that it had breached executive-accountability obligations tied to a 2023 cyberattack on its former Alliance Bank business.

The proposed civil penalty follows an APRA investigation into the March 2023 attack, in which an unidentified threat actor accessed approximately 257 customer accounts and made 286 unauthorised transactions affecting 87 Alliance Bank customers.

The transactions totalled about $490,000 and while Bendigo Bank was unable to recover roughly $140,000, it stressed that all affected customers had been reimbursed.

 
 

The Alliance Bank business was subsequently discontinued in September 2024.

Known weaknesses left unresolved says APRA

APRA said Bendigo Bank conceded that it had breached obligations under the Banking Executive Accountability Regime (BEAR), which is designed to assign clear responsibility to senior executives and directors for prudential matters.

The regulator identified “significant weaknesses” in Alliance Bank’s online-banking customer authentication controls.

These included password settings that allowed “very weak” passwords, multiple customer accounts with identical passwords, and system features that enabled an attacker to identify valid customer IDs.

APRA added that some of the relevant weaknesses had been identified during penetration testing in 2020 but had not been addressed before the attack between 3 and 7 March 2023.

The regulator said the bank had admitted that it failed to maintain adequate authentication controls to prevent and detect unauthorised access, did not run a systematic testing program for those controls, and lacked adequate governance and risk management over the IT system enabling Alliance Bank’s digital access.

It also admitted the responsibilities of Bendigo Bank’s accountable persons, including those in subsidiaries, did not appropriately cover the relevant Alliance Bank IT system.

The parties have proposed that Bendigo Bank pay an $8 million pecuniary penalty for the BEAR contraventions.

However, APRA stressed that the Federal Court needed to determine whether declarations and the penalty was appropriate.

Regulator delivers cyber message

APRA deputy chair Therese McCarthy Hockey said Bendigo Bank’s capital and liquidity position did not lessen the regulator’s expectations that a major institution should have sophisticated cyber-security capabilities.

“Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements. However, as Australia’s sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cyber security systems and practices,” McCarthy Hockey said.

McCarthy Hockey said that the the enforcement action carried a wider message for every APRA-regulated entity on control testing and cyber resilience.

“While the financial impact of this cyber incident was limited, our court action sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls,” she said.

Bendigo accepts proposed sanction

In an ASX statement released on Tuesday (11 August), Bendigo Bank acknowledged the Federal Court proceedings and said that it accepted the proposed $8 million legal penalty.

The bank said the penalty, together with $2.6 million in additional legal costs, would be recognised as a non-cash item in its FY26 results.

Bendigo Bank chief executive and managing director Richard Fennell said the bank had acted immediately after identifying the issue.

“Our customers can be assured that once identified, we acted immediately to address the issue, and made sure all impacted customers were fully reimbursed,” Fennell said.

“Bendigo Bank acknowledges APRA’s important role in maintaining a strong and accountable banking system. We continue to work actively and constructively with our regulators in relation to the previously disclosed independent non-financial risk review.”


This story was originally published by Cyber Daily's sister brand, The Adviser.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: