08/11/2026 | Press release | Distributed by Public on 08/10/2026 16:36
Bendigo and Adelaide Bank Limited (Bendigo Bank) has conceded it has breached its obligations under the Banking Executive Accountability Regime (BEAR) in relation to a 2023 cyber attack involving its Alliance Bank business.
There were significant weaknesses in customer authentication controls for online banking, including password settings that permitted very weak passwords, multiple customer accounts with identical passwords and system design features that enabled a threat actor to identify valid customer IDs.
A number of those weaknesses were identified by penetration testing conducted in 2020 but were not addressed by Bendigo Bank prior to the cyber attack.
As a result, an unidentified hacker was able to conduct an attack between 3 and 7 March 2023 and gain access to approximately 257 customer accounts. During that time, the attacker made 286 unauthorised transactions totalling about $490,000 affecting 87 separate Alliance Bank customers. Bendigo Bank was unable to recover about $140,000 of this money but reimbursed all affected customers.
Following a formal investigation, APRA commenced civil penalty proceedings in the Federal Court yesterday against Bendigo Bank.
Bendigo Bank admits that it breached its obligations under the BEAR by failing to:
The parties propose orders in the proceedings that Bendigo Bank pays a pecuniary penalty of $8 million in respect of its contraventions of the BEAR, subject to Court approval. It is a matter for the Court to determine whether the declarations and the imposition of a penalty are appropriate and to make other orders.
The proceedings relate to historical conduct and control weaknesses that were satisfactorily remediated following the cyber attack. APRA does not currently have concerns regarding the adequacy of Bendigo Bank's information security controls.
APRA Deputy Chair Therese McCarthy Hockey said: "Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements. However, as Australia's sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cyber security systems and practices.
"While the financial impact of this cyber incident was limited, our court action sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls."
Originating Application
Statement of Agreed Facts and Admissions