Media release

Bendigo and Adelaide Bank admits to breaching its BEAR obligations in relation to cyber incident

Bendigo and Adelaide Bank Limited (Bendigo Bank) has conceded it has breached its obligations under the Banking Executive Accountability Regime (BEAR) in relation to a 2023 cyber attack involving its Alliance Bank business.
Banking
Published
11 August 2026

Bendigo and Adelaide Bank Limited (Bendigo Bank) has conceded it has breached its obligations under the Banking Executive Accountability Regime (BEAR) in relation to a 2023 cyber attack involving its Alliance Bank1 business.

There were significant weaknesses in customer authentication controls for online banking, including password settings that permitted very weak passwords, multiple customer accounts with identical passwords and system design features that enabled a threat actor to identify valid customer IDs.

A number of those weaknesses were identified by penetration testing conducted in 2020 but were not addressed by Bendigo Bank prior to the cyber attack.

As a result, an unidentified hacker was able to conduct an attack between 3 and 7 March 2023 and gain access to approximately 257 customer accounts. During that time, the attacker made 286 unauthorised transactions totalling about $490,000 affecting 87 separate Alliance Bank customers. Bendigo Bank was unable to recover about $140,000 of this money but reimbursed all affected customers.

Following a formal investigation, APRA commenced civil penalty proceedings in the Federal Court yesterday against Bendigo Bank.

Bendigo Bank admits that it breached its obligations under the BEAR by failing to:

  • maintain adequate customer authentication controls for the prevention and detection of unauthorised access to Alliance Bank customer accounts; 
  • undertake a systematic testing program for the customer authentication controls of Alliance Bank as required by Prudential Standard CPS 234 - Information Security;
  • have adequate governance and risk management for the information security of the IT system that enabled digital access for customers of Alliance Bank; and
  • ensure that the responsibilities of the accountable persons of Bendigo Bank and its subsidiaries appropriately covered the IT system of Alliance Bank.

The parties propose orders in the proceedings that Bendigo Bank pays a pecuniary penalty of $8 million in respect of its contraventions of the BEAR, subject to Court approval. It is a matter for the Court to determine whether the declarations and the imposition of a penalty are appropriate and to make other orders.

The proceedings relate to historical conduct and control weaknesses that were satisfactorily remediated following the cyber attack. APRA does not currently have concerns regarding the adequacy of Bendigo Bank’s information security controls.

APRA Deputy Chair Therese McCarthy Hockey said: “Bendigo Bank is financially sound and comfortably above its core capital and liquidity requirements. However, as Australia’s sixth largest bank, we expect Bendigo Bank to have robust and sophisticated cyber security systems and practices.

“While the financial impact of this cyber incident was limited, our court action sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls.”

Attachments

Originating Application

Statement of Agreed Facts and Admissions 

Media enquiries

Contact APRA Media Unit, on +61 2 9210 3636

All other enquiries

For more information contact APRA on 1300 558 849.

 

The Australian Prudential Regulation Authority (APRA) is the prudential regulator of the financial services industry. It oversees banks, mutuals, general insurance and reinsurance companies, life insurance, private health insurers, friendly societies, and most members of the superannuation industry. APRA currently supervises institutions holding around $9.8 trillion in assets for Australian depositors, policyholders and superannuation fund members. 

Footnotes

  • 1

    During the relevant period, Bendigo Bank operated the Alliance Bank network under its ADI licence, which comprised five authorised representatives: AWA Mutual Limited, BDCU Limited, Circle Mutual Limited, Service One Mutual Limited and Nova Mutual Limited.