On 26 September 2022, a bank executive signed a document that removed a system from their individual list of responsibilities. The system was the internet banking platform used by roughly 38,000 customers. The words were plain enough: "IT Operations for Alliance Bank is excluded."
The responsibility was not reassigned. It appeared in no other accountable person's statement. It simply stopped being anybody's job.
Five months later, an attacker logged into 211 customer accounts using the password "123456".
On 11 August 2026, the Australian Prudential Regulation Authority announced that Bendigo and Adelaide Bank Limited had admitted breaching its obligations under the Banking Executive Accountability Regime. The parties have proposed a pecuniary penalty of $8 million, subject to Federal Court approval. The media release runs a few hundred words. The Statement of Agreed Facts and Admissions runs 43 pages, and it is one of the most useful documents an Australian or New Zealand board might read this year.
Between 3 and 7 March 2023, an unidentified attacker ran a brute force attack against the online banking platform used by Service One Alliance Bank, one of five authorised representatives operating under Bendigo Bank's licence.
The attacker accessed approximately 257 customer accounts. At least 211 were opened using "123456". Another 18 used "12345678". When the attack began, 1,598 Service One accounts were protected by "123456". The attacker changed the password on at least 218 accounts, locking customers out of their own banking, created new payees where one-time password controls had not been switched on, and executed 286 transactions across 87 accounts worth about $490,000. Automated fraud controls stopped $133,030. The remaining $140,110 could not be recovered. Every affected customer was refunded within four days.
The bank learned of the attack four days after it started, when a customer rang to report fraudulent transactions. Not the monitoring platform. A customer, on the phone.
Bendigo Bank admitted four breaches:
Inadequate customer authentication controls
No systematic testing program for those controls as required by Prudential Standard CPS 234 Information Security
Inadequate governance and risk management for the platform, and
failure to ensure the responsibilities of accountable persons covered the system at all.
Minimum password lengths of six characters, and four at two of the Alliance banks, where the most common password at one was "1234" and some customers still held passwords issued in 2008 and 2012. No mandatory multi-factor authentication. Error messages that told an attacker which member numbers were valid, so accounts could be enumerated one at a time. Meanwhile customers on the bank's own core platform had eight character minimums, complexity requirements and mandatory multi-factor authentication.
From 29 August 2022 to 30 August 2023, no accountability statement of any accountable person covered the information technology operations of Alliance Bank. Not the Chief Transformation Officer, who had just excluded it. Not the Chief Customer Officer, whose statements referenced Alliance Bank branches and distribution but never its IT. Nobody.
A slide deck in August 2022 proposed the responsibility pass to "Alliance Bank & CCO, Consumer (TBC)". A later version carried the note "12/08 - roles confirmed". It never reached a signed accountability statement. The paperwork said the handover happened. The statements said otherwise.
This is not a cyber security failure. It is an operating model failure that a cyber security failure walked straight through.
On 2 June 2020, an external provider delivered a penetration test report on the Service One platform's customer authentication controls. It found users could set easily guessed passwords such as "password1". It found weak password policies made brute force attacks easier. It found valid member numbers could be identified by reading the different error messages returned. It warned that combining the two made password spray attacks straightforward.
Every one of those findings describes the attack that happened 33 months later.
The findings were rated "moderate". They were logged in a vulnerability tracking tool. They were not escalated to management. They were not assessed against the bank's own operational risk escalation matrix. They were not sent to the hosting provider, despite an internal suggestion that they should be. They were not sent to the Business System Owner responsible for the platform, who was also the registered risk owner for the "Breach of IT Security" risk in the bank's own register, and who had no professional background or formal qualifications in information technology or information security.
No equivalent test was run on the other four Alliance instances before March 2023. Post-incident testing found the same vulnerabilities. The bank's own accountability review concluded the attack might have been avoided had the 2020 findings been properly assessed, escalated and managed.
The tests worked. The escalation did not. Buying more testing without fixing escalation only buys a better documented record of what you are not going to fix.
There was also a dress rehearsal.
On 27 October 2022, a threat actor ran brute force attacks against two Alliance platforms. Nothing was compromised, but thousands of customers were locked out, and again the bank found out because customers rang. Login activity was not monitored, only transactions. Both the hosting provider and the software vendor then recommended multi-factor authentication, CAPTCHA, longer passwords and non-numeric member IDs. Before March 2023, one was implemented: CAPTCHA, on online banking. It was inadvertently not applied to mobile banking. The March 2023 attack came through mobile banking.
The Financial Accountability Regime replaced it for banks on 15 March 2024 and extended to insurers, licensed non-operating holding companies and superannuation trustees on 15 March 2025. FAR captures directors as well as senior executives, and the accountability mapping obligation Bendigo Bank failed now applies to a far larger population. If your organisation completed a FAR map in 2024 or 2025 and has not revisited it, this case describes your risk, not somebody else's.
A third party core banking product, hosted by a third party managed service provider, operated by a business unit rather than the technology division. Annual assurance reports arrived from both providers and neither examined the customer authentication controls that failed. This is the ground CPS 230 Operational Risk Management now covers through material service provider obligations. A supplier assurance report you have not read closely enough to know what it excludes is worse than no report, because it manufactures confidence.
The Reserve Bank of New Zealand requires registered banks, non-bank deposit takers and insurers to report material cyber incidents within 72 hours. BS11 outsourcing requirements came into full effect for the largest New Zealand banks in late 2023. The standards under the Deposit Takers Act 2023, including the proposed governance, risk management and operational resilience standards, will sharpen director due diligence duties in exactly this territory.
Bendigo Bank remediated thoroughly, closed all 48 post-incident action items by May 2024, and APRA has said it does not currently have concerns about the bank's information security controls. It still faces an $8 million penalty for weaknesses identified in a report it commissioned and paid for in June 2020. Response costs ran to roughly $610,000 in external incident response and $140,000 in customer remediation, before the penalty. Closing the gap in 2020 would have cost a fraction of that, had a single moderate rated finding reached someone with the authority and expertise to act.
This is what we mean when we say cybersecurity is a business problem, not just a technology one. There is always more technology to throw at it. None of it would have helped here. What was missing was a name against a system, an escalation path that carried a finding upward instead of sideways, and a board asking who owns this before the answer mattered.
Bendigo and Adelaide Bank is Australia's sixth largest bank. It had an information security policy, a technology risk framework, a CPS 234 controls testing framework, a password standard, an escalation matrix, three lines of defence, a risk register and a board technology committee.
It had all of the documents. It did not have an owner.
What Bendigo Bank's case shows is that governance frameworks don't fail loudly. They fail by quietly excluding one thing and never noticing.
Insicon Cyber helps boards and executive teams across Australia and New Zealand find that one thing before a regulator does: Board Cyber Advisory for accountability mapping and FAR and CPS 230 readiness, CISO-as-a-Service to put qualified accountability behind systems whose owners lack the technical background, Managed Compliance across Essential Eight, ISO 27001, ISO 42001 and NZISM including material service provider assurance, and our Adaptive SOC (aSOC) for the 24/7 login and authentication anomaly monitoring that neither attack described here triggered.