Bendigo Bank faces $5.65m penalty after 2023 Alliance Bank breach
Deck
Bendigo and Adelaide Bank has conceded that it breached its accountability obligations in a 2023 cyber-attack involving its Alliance Bank business, the Australian Prudential Regulation Authority (APRA) said.
Bendigo Bank faces a penalty of $5.65m (A$8m), subject to court approval.
Between 3 and 7 March 2023, an unidentified hacker was able to gain access to approximately 257 customer accounts of Alliance Bank. The hacker made 286 unauthorized transactions totalling $490,000, affecting 87 customers, APRA said.
Bendigo Bank was reportedly unable to recover about $98,800 (A$140,000) of this money but reimbursed all affected customers.
Earlier in 2020, a penetration test identified a number of weaknesses in the bank’s customer authentication controls, yet Bendigo Bank did not address these prior to the cyberattack, APRA said.
Bendigo Bank admitted that it breached obligations under the Banking Executive Accountability Regime (BEAR) in its failure to maintain adequate customer authentication controls to prevent and detect unauthorised access to Alliance Bank customer accounts.
It also failed its BEAR obligations in undertaking a systemic testing program for customer authentication controls of Alliance Bank.
Bendigo Bank also admitted that it failed to have adequate governance and risk management for the information security of the IT system that enabled digital access for customers of Alliance Bank; and to ensure that the responsibilities of the accountable persons of Bendigo Bank and its subsidiaries appropriately covered the IT system of Alliance Bank.
APRA commenced civil penalty proceedings in Australia's Federal Court against Bendigo Bank on 10 August 2026.
(US$1 = A$1.42, as of 11 August 2026)