Bendigo Bank Faces Regulatory Action After 2023 Cyber Breach Exploiting Unaddressed Vulnerabilities
Between 3 and 7 March 2023, a hacker exploited weak customer authentication controls in Bendigo Bank’s Alliance Bank business, accessing 257 customer accounts and executing 286 unauthorized transactions totaling $490,000, affecting 87 customers. The breach stemmed from vulnerabilities flagged during a 2020 penetration test that remained unaddressed.
In response, Bendigo Bank reimbursed all affected customers and proposed an $8 million pecuniary penalty, pending Federal Court approval. However, the incident triggered heightened scrutiny from the Australian Prudential Regulation Authority (APRA), which imposed formal licence conditions on the bank following an independent Deloitte root cause analysis commissioned in December 2025.
The review uncovered "prevalent" non-financial risk management weaknesses across the organization, including material deficiencies in governance, accountability, and risk oversight issues that persisted despite years of remediation under the bank’s BEN+ transformation program. While APRA Deputy Chair Therese McCarthy Hockey confirmed the bank remains financially sound, she emphasized that as Australia’s sixth-largest bank, Bendigo must maintain "robust and sophisticated cybersecurity systems."
The new licence conditions require a comprehensive rectification program and independent assurance, alongside a retained $50 million operational risk capital add-on. Though APRA has not raised concerns about the bank’s current information security controls, the enforcement actions signal ongoing supervisory attention that may impact service levels or product settings in the coming months.
Bendigo Bank also admitted breaching the Banking Executive Accountability Regime (BEAR) in relation to the attack, marking the second regulatory action against the bank in a week. While the immediate financial impact is limited, the dual enforcement actions underscore longstanding risk management concerns that the bank has pledged to address through cooperative engagement with regulators.
Bendigo Bank cybersecurity rating report: https://www.rankiteo.com/company/bendigobank
"id": "BEN1787034582",
"linkid": "bendigobank",
"type": "Breach",
"date": "3/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '87 customers (257 accounts '
'accessed)',
'industry': 'Financial Services',
'location': 'Australia',
'name': 'Bendigo Bank (Alliance Bank business)',
'size': 'Australia’s sixth-largest bank',
'type': 'Bank'}],
'attack_vector': 'Weak customer authentication controls',
'customer_advisories': 'Affected customers reimbursed, no current concerns '
'about information security controls.',
'data_breach': {'number_of_records_exposed': '257 accounts accessed',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (personally identifiable and '
'financial information)',
'type_of_data_compromised': 'Customer account information, '
'transaction details'},
'date_detected': '2023-03-03',
'description': 'Between 3 and 7 March 2023, a hacker exploited weak customer '
'authentication controls in Bendigo Bank’s Alliance Bank '
'business, accessing 257 customer accounts and executing 286 '
'unauthorized transactions totaling $490,000, affecting 87 '
'customers. The breach stemmed from vulnerabilities flagged '
'during a 2020 penetration test that remained unaddressed.',
'impact': {'brand_reputation_impact': 'Heightened regulatory scrutiny and '
'enforcement actions',
'data_compromised': 'Customer account information',
'financial_loss': '$490,000 (unauthorized transactions)',
'identity_theft_risk': 'High (customer accounts accessed)',
'legal_liabilities': '$8 million proposed pecuniary penalty, BEAR '
'breach admission',
'operational_impact': 'Regulatory scrutiny, formal licence '
'conditions imposed',
'payment_information_risk': 'High (unauthorized transactions '
'executed)',
'systems_affected': 'Alliance Bank business customer '
'authentication systems'},
'investigation_status': 'Completed (Deloitte root cause analysis finalized)',
'lessons_learned': 'Persistent non-financial risk management weaknesses, '
'including governance, accountability, and risk oversight '
'deficiencies. Unaddressed vulnerabilities from prior '
'assessments can lead to significant breaches and '
'regulatory actions.',
'motivation': 'Financial gain',
'post_incident_analysis': {'corrective_actions': 'Comprehensive rectification '
'program, independent '
'assurance, enhanced '
'monitoring, and governance '
'reforms under BEN+ '
'transformation program.',
'root_causes': 'Unaddressed vulnerabilities from '
'2020 penetration test, weak '
'customer authentication controls, '
'material deficiencies in '
'governance, accountability, and '
'risk oversight.'},
'recommendations': 'Implement a comprehensive rectification program, '
'independent assurance, enhanced governance and risk '
'oversight, and cooperative engagement with regulators.',
'references': [{'source': 'Australian Prudential Regulation Authority '
'(APRA)'}],
'regulatory_compliance': {'fines_imposed': '$8 million proposed pecuniary '
'penalty',
'legal_actions': 'Federal Court approval pending, '
'formal licence conditions imposed '
'by APRA',
'regulations_violated': ['Banking Executive '
'Accountability Regime '
'(BEAR)'],
'regulatory_notifications': 'APRA, Federal Court'},
'response': {'containment_measures': 'Reimbursement of affected customers',
'remediation_measures': 'Proposed $8 million pecuniary penalty, '
'rectification program under licence '
'conditions',
'third_party_assistance': 'Independent Deloitte root cause '
'analysis'},
'stakeholder_advisories': 'APRA imposed formal licence conditions, $50 '
'million operational risk capital add-on retained, '
'potential impact on service levels or product '
'settings.',
'title': 'Bendigo Bank Cyber Breach Exploiting Unaddressed Vulnerabilities',
'type': 'Data Breach',
'vulnerability_exploited': 'Unaddressed vulnerabilities from a 2020 '
'penetration test'}