
Bendigo and Adelaide Bank faces $8M penalty over cyber breach
- Bendigo and Adelaide Bank has agreed to a joint $8 million civil penalty with APRA following a 2023 cyberattack.
- The financial penalty and associated legal costs will be recorded in the company's financial results.
- The regulatory action aims to reinforce required standards for cybersecurity controls across regulated financial entities.
Bendigo and Adelaide Bank (ASX:BEN) agreed to pay an $8 million penalty in the Federal Court after admitting to breaches of accountability obligations following a 2023 cyber-attack on its former Alliance Bank operations.
The prudential regulator commenced civil penalty proceedings after discovering that online banking settings permitted weak passwords and vulnerable system designs during a 2020 penetration test.
“Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements, but as Australia’s sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cybersecurity systems and practices,” said Australian Prudential Regulation Authority Deputy Chair Therese McCarthy Hockey.
The security failure allowed an unauthorised party to access 257 customer accounts and complete 286 unauthorised transactions totalling $490,000, though all affected customers received full reimbursements despite $140,000 remaining unrecovered.
The institution stated that the resolution addresses historical control weaknesses and that all necessary remediation activities for the discontinued Alliance Bank sector have been completed.
Following the announcement, the Bendigo and Adelaide Bank share price was down at $11.24.
The regional lender operates a network of community bank branches across Australia alongside residential mortgage, commercial lending, and wealth management divisions.
The company has historically focused on organic retail growth while occasionally acquiring smaller cooperative banking partners to expand its regional footprint.
-640x360.png&w=3840&q=75)