Skip to the main content.

5 min read

What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand

What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand
What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand
13:15

On 26 September 2022, a bank executive signed a document that removed a system from their individual list of responsibilities. The system was the internet banking platform used by roughly 38,000 customers. The words were plain enough: "IT Operations for Alliance Bank is excluded."

The responsibility was not reassigned. It appeared in no other accountable person's statement. It simply stopped being anybody's job.
Five months later, an attacker logged into 211 customer accounts using the password "123456".

On 11 August 2026, the Australian Prudential Regulation Authority announced that Bendigo and Adelaide Bank Limited had admitted breaching its obligations under the Banking Executive Accountability Regime. The parties have proposed a pecuniary penalty of $8 million, subject to Federal Court approval. The media release runs a few hundred words. The Statement of Agreed Facts and Admissions runs 43 pages, and it is one of the most useful documents an Australian or New Zealand board might read this year.

 

What happened

Between 3 and 7 March 2023, an unidentified attacker ran a brute force attack against the online banking platform used by Service One Alliance Bank, one of five authorised representatives operating under Bendigo Bank's licence.

The attacker accessed approximately 257 customer accounts. At least 211 were opened using "123456". Another 18 used "12345678". When the attack began, 1,598 Service One accounts were protected by "123456". The attacker changed the password on at least 218 accounts, locking customers out of their own banking, created new payees where one-time password controls had not been switched on, and executed 286 payment or transfer transactions across 87 accounts worth about $490,000. Automated fraud controls stopped $133,030 of payments, but $140,110 could not be recovered. Every affected customer was refunded within four days.

The bank learned of the attack four days after it started, when a customer rang to report fraudulent transactions. Not the monitoring platform. A customer, on the phone.

 

The failure that matters most

Bendigo Bank admitted four breaches:

  1. Inadequate customer authentication controls

  2. No systematic testing program for those controls as required by Prudential Standard CPS 234 Information Security

  3. Inadequate governance and risk management for the platform, and

  4. failure to ensure the responsibilities of accountable persons covered the system at all.

The first three will get the headlines

Minimum password lengths of six characters, and four at two of the Alliance banks, where the most common password at one was "1234" and some customers still held passwords issued in 2008 and 2012. No mandatory multi-factor authentication. Error messages that told an attacker which member numbers were valid, so accounts could be enumerated one at a time.

The fourth failure is the one for your next board meeting

From 29 August 2022 to 30 August 2023, no accountability statement of any accountable person covered the information technology operations of Alliance Bank. Not the Chief Transformation Officer, who had just excluded it. Not the Chief Customer Officer. Nobody.

A slide deck in August 2022 proposed the responsibility pass to "Alliance Bank & CCO, Consumer (TBC)". A later version carried the note "12/08 - roles confirmed". It never reached a signed accountability statement. The paperwork said the handover happened. The statements said otherwise.

This is not a cyber security failure. It is an operating model failure that a cyber security failure walked straight through.

Where do you actually stand?

Australian and New Zealand regulators are now asking for evidence, not assurances.

APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.

 

The penetration test that went nowhere

On 2 June 2020, an external provider delivered a penetration test report on the Service One platform's customer authentication controls. It found users could set easily guessed passwords such as "password1". It found weak password policies made brute force attacks easier. It found valid member numbers could be identified by reading the different error messages returned. It warned that combining the two made password spray attacks straightforward.

Every one of those findings describes the attack that happened 33 months later.

The findings were rated "moderate". They were logged in a vulnerability tracking tool. They were not escalated to management. They were not assessed against the bank's own operational risk escalation matrix. They were not sent to the hosting provider. They were not sent to the Business System Owner responsible for the platform.

No equivalent test was run on the other four Alliance instances before March 2023. Post-incident testing found the same vulnerabilities. The bank's own accountability review concluded the attack might have been avoided had the 2020 findings been properly assessed, escalated and managed.

The tests worked. The escalation did not. Buying more testing without fixing escalation only buys a better documented record of what you are not going to fix.

There was also a dress rehearsal.

On 27 October 2022, a threat actor ran brute force attacks against two Alliance platforms. Nothing was compromised, but thousands of customers were locked out, and again the bank found out because customers rang. Login activity was not monitored, only transactions. Both the hosting provider and the software vendor then recommended multi-factor authentication, CAPTCHA, longer passwords and non-numeric member IDs. Before March 2023, one was implemented: CAPTCHA, on online banking. It was inadvertently not applied to mobile banking. The March 2023 attack came through mobile banking.

 

Why this is not only a banking story

BEAR no longer exists

The Financial Accountability Regime replaced it for banks on 15 March 2024 and extended to insurers, licensed non-operating holding companies and superannuation trustees on 15 March 2025. FAR captures directors as well as senior executives, and the accountability mapping obligation Bendigo Bank failed now applies to a far larger population.

The structural cause was outsourced and business managed technology

A third party core banking product, hosted by a third party managed service provider, operated by a business unit rather than the technology division. Annual assurance reports arrived from both providers and neither examined the customer authentication controls that failed. This is the ground CPS 230 Operational Risk Management now covers through material service provider obligations.

New Zealand is moving the same way

The Reserve Bank of New Zealand requires registered banks, non-bank deposit takers and insurers to report material cyber incidents within 72 hours. The standards under the Deposit Takers Act 2023 will sharpen director due diligence duties in exactly this territory.

 

Five questions for your next board or risk committee

  1. Which systems appear in no executive's accountability statement? Stick with the phrasing. Ask for the gap analysis, not the coverage map. If it takes more than a week to produce, that is the finding.
  2. Who owns the systems a business unit runs without the technology function? Name the owner, then ask whether that owner has the capability to discharge the responsibility.
  3. Where do "moderate" findings go? Trace one, from report to risk register to remediation plan to closure evidence. Wherever it stops moving, you have found the control failure APRA just penalised.
  4. What would tell us first? Two attacks, two detections, both by customer phone call. If the honest answer is "someone would ring us", the monitoring gap is the exposure.
  5. What do our supplier assurance reports specifically not cover? Ask for the scope exclusions in writing, on one page.

 

The uncomfortable part

Bendigo Bank remediated thoroughly, closed all 48 post-incident action items by May 2024, and APRA has said it does not currently have concerns about the bank's information security controls. It still faces an $8 million penalty for weaknesses identified in a report it commissioned and paid for in June 2020.

This is what we mean when we say cybersecurity is a business problem, not just a technology one. There is always more technology to throw at the problem. None of it would have helped here. What was missing was a name against a system, an escalation path that carried a finding upward instead of sideways, and a board asking who owns this before the answer mattered.

 

Closing the accountability gap

Insicon Cyber helps boards and executive teams across Australia and New Zealand find that one thing before a regulator does: Board Cyber Advisory for accountability mapping and FAR and CPS 230 readiness, CISO-as-a-Service to put qualified accountability behind systems whose owners lack the technical background, Managed Compliance across Essential Eight, ISO 27001, ISO 42001 and NZISM including material service provider assurance, and our Adaptive SOC (aSOC) for 24/7 login and authentication anomaly monitoring.

 

Sources

What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand

What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand

On 26 September 2022, a bank executive signed a document that removed a system from their individual list of responsibilities. The system was the...

Read More
You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

Black Hat always has a session everyone talks about, and this year it was OpenAI telling the room we're all gonna need a bigger boat. Their own...

Read More
ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

The Australian Signals Directorate has moved the frontier AI conversation into the boardroom, and it has brought the Australian Institute of Company...

Read More
APRA Has Named Four AI Governance Failures. Every Regulated Entity in Australia and New Zealand Is in Scope.

1 min read

APRA Has Named Four AI Governance Failures. Every Regulated Entity in Australia and New Zealand Is in Scope.

On 30th April 2026, APRA published a letter to all regulated entities on artificial intelligence. It is not a discussion paper. It is not a...

Read More
APRA Tightens the Screws: New Authentication Requirements for Super Funds

1 min read

APRA Tightens the Screws: New Authentication Requirements for Super Funds

31 August 2025 deadline looms as regulator demands immediate action following devastating cyber attacks If you thought APRA's existing cybersecurity...

Read More
ASIC Has Drawn the Line on Frontier AI. Australian and New Zealand Boards Now Have a Reading List.

1 min read

ASIC Has Drawn the Line on Frontier AI. Australian and New Zealand Boards Now Have a Reading List.

On 8 May 2026, ASIC Commissioner Simone Constant issued an open letter to AFS licensees and market participants. It runs to four pages. It is not a...

Read More