Bendigo Bank Admits BEAR Breaches Over Cyberattack: What APRA-Regulated Entities Should Know

Published By:

Hannah Deuk

Founder & Principal Lawyer

Key Takeaways:

  • Remediate and escalate known vulnerabilities: APRA-regulated entities must assign an owner and set a remediation timeframe, as Bendigo Bank’s 2020 defects sat unremediated until March 2023 and enabled the attack.
  • Test the controls that matter: Paragraph 27 of Prudential Standard CPS 234 Information Security requires a systematic testing program that exercises critical authentication controls—broad assurance reports are not enough.
  • Allocate executive accountability for every system: Bendigo Bank breached former s 37D(1)(a)(i) of the Banking Act 1959 (Cth) when Alliance Bank’s IT operations fell outside any accountability statement.
  • FAR carries forward BEAR’s principles: BEAR was replaced by the Financial Accountability Regime from 15 March 2024, yet the diligence and responsibility-allocation obligations persist—with the proposed $8 million penalty still subject to Federal Court approval.
Jump to...
August 12, 2026

Introduction

Bendigo and Adelaide Bank Limited has admitted breaching its obligations under the former Banking Executive Accountability Regime (BEAR) following a 2023 cyberattack involving its Alliance Bank business.

On 10 August 2026, the Australian Prudential Regulation Authority (APRA) commenced civil penalty proceedings in the Federal Court over weaknesses in Bendigo Bank’s customer authentication controls, security testing, information security governance and allocation of executive accountability. APRA and Bendigo Bank have jointly proposed an $8 million pecuniary penalty, subject to Federal Court approval.

The case provides an important example of how unresolved cyber vulnerabilities can develop into broader prudential and executive accountability failures.

What Happened in the Alliance Bank Cyberattack?

During the relevant period, Bendigo Bank operated the Alliance Bank network under its authorised deposit-taking institution (ADI) licence. The network included five authorised representatives and used the Ultracs banking system to provide customers with digital access to their accounts.

Penetration testing conducted in June 2020 identified several weaknesses in the customer authentication controls used by Service One Alliance Bank, including:

  • password settings that allowed easily guessed passwords;
  • different login error messages that could help an attacker determine whether a customer number was valid;
  • the absence of CAPTCHA protections; and
  • one-time-password multi-factor authentication being optional rather than automatically applied.

These vulnerabilities were not merely theoretical. According to the agreed facts:

  • the identified weaknesses were not remediated until March 2023;
  • they were not appropriately escalated to Alliance Bank or Bendigo Bank management; and
  • similar testing was not conducted across several other Alliance Bank partners before the attack.

Between 3 and 7 March 2023, an unidentified attacker carried out a brute-force attack against Service One Alliance Bank. At the time, 1,598 customer accounts were protected by the password “123456”, with other accounts using similarly weak passwords.

The attacker:

  • gained access to approximately 257 customer accounts;
  • made 286 unauthorised transactions;
  • affected 87 Alliance Bank customers; and
  • transferred approximately $490,000.

Although some payments were stopped or recovered, approximately $140,000 could not be recovered. Bendigo Bank reimbursed all affected customers.

What Has Bendigo Bank Admitted?

APRA’s proceeding relies on provisions of the Banking Act 1959 (Cth) that formed part of the BEAR at the time of the relevant conduct.

Failure to Conduct the Business With Due Skill, Care & Diligence

Former Section 37C(a) of the Banking Act 1959 (Cth) required an ADI to take reasonable steps to conduct its business with honesty and integrity and with due skill, care, and diligence.

Bendigo Bank admits that, between June 2020 and June 2023, it failed to take reasonable steps to conduct the Alliance Bank business with due skill, care, and diligence.

APRA’s case identifies three interconnected failures:

  • inadequate customer authentication controls;
  • the absence of an adequate systematic testing program for those controls; and
  • inadequate governance and risk management of the systems supporting Alliance Bank’s digital services.

Importantly, the proceeding is not based simply on the fact that a cyberattack occurred. Cyber incidents can occur even where strong controls are in place. The admitted contraventions concern the steps Bendigo Bank took — or failed to take — to identify, test, govern and remediate known information security risks before the attack occurred.

Failure to Ensure Complete Executive Accountability

Bendigo Bank has also admitted breaching former Section 37D(1)(a)(i) of the Banking Act 1959 (Cth).

That provision required the bank to ensure that the responsibilities of its accountable persons, together with those of its subsidiaries, collectively covered all parts or aspects of its operations.

From 29 August 2022 to 30 August 2023, the information technology operations of Alliance Bank were not covered by the accountability statement of any Bendigo Bank accountable person.

According to the agreed facts:

  • responsibility had been removed from the Chief Transformation Officer’s updated accountability statement; and
  • that responsibility was not then allocated to another accountable person.

The Chief Transformation Officer and Chief Information Security Officer did in practice take responsibility for responding to the March 2023 attack. However, this did not address the underlying accountability gap.

The BEAR obligation concerned whether responsibility for that part of the business had been properly allocated before the incident occurred.

Why CPS 234 Was Central to APRA’s Case

The proceeding also highlights the importance of APRA’s Prudential Standard CPS 234 Information Security.

CPS 234 is an outcomes-based prudential standard rather than a prescriptive cybersecurity checklist. It does not, for example, prescribe one universal password length or require a specific type of multifactor authentication in every circumstance.

Instead, APRA-regulated entities must maintain information security controls that are appropriate having regard to matters such as:

  • vulnerabilities and threats;
  • the criticality and sensitivity of information assets; and
  • the potential consequences of an information security incident.

Of particular relevance is paragraph 27 of CPS 234, which requires an APRA-regulated entity to test the effectiveness of its information security controls through a systematic testing program.

The nature and frequency of that testing must reflect matters including:

  • changing threats and vulnerabilities;
  • the criticality and sensitivity of relevant information assets; and
  • the potential consequences of an information security incident.

CPS 234 also requires:

  • deficiencies that cannot be remediated in a timely manner to be escalated to the Board or senior management;
  • testing to be conducted by appropriately skilled and functionally independent specialists; and
  • the sufficiency of the testing program to be reviewed at least annually or following a material change.

The agreed facts indicate that Bendigo Bank had received annual assurance reports relating to relevant service providers and had also conducted a control validation exercise. However, those reviews did not actually test the customer authentication controls used for Alliance Bank’s online and mobile banking services.

Between January 2021 and March 2023, Bendigo Bank did not perform control testing of those authentication controls, including password configuration.

For APRA-regulated entities, this creates an important distinction: having security reports, audits, or penetration testing somewhere within a governance framework does not necessarily demonstrate that the relevant security controls have been adequately tested.

Identifying Cyber Risks Is Not Enough if They Are Not Remediated

One of the most significant features of the case is the time between identifying the vulnerabilities and addressing them.

The 2020 penetration test identified issues including:

  • weak password controls;
  • the ability to use different error messages to identify valid member numbers; and
  • weaknesses in authentication protections.

Those vulnerabilities were recorded internally, but the agreed facts state that they were:

  • not appropriately escalated;
  • not properly assessed against Bendigo Bank’s operational risk framework; and
  • not remediated until March 2023.

There had also been brute-force attacks against Alliance Bank systems in October 2022 that attempted to exploit similar authentication weaknesses.

Following those attacks, additional controls were recommended, including:

  • stronger password requirements;
  • multi-factor authentication; and
  • CAPTCHA.

The practical lesson is that identifying a vulnerability is only the beginning of the risk-management process.

Material security findings should ordinarily have:

  • a clearly identified owner;
  • an assessment of the associated risk;
  • an appropriate remediation timeframe;
  • a process for monitoring remediation; and
  • escalation to senior management or the Board where remediation cannot occur within an appropriate timeframe.

BEAR Has Been Replaced by FAR — So Why Does This Case Still Matter?

The conduct involved in the Bendigo Bank proceeding occurred while BEAR applied to ADIs.

BEAR was subsequently replaced for the banking industry by the Financial Accountability Regime (FAR) from 15 March 2024.

However, the underlying governance lessons about executive accountability remain highly relevant.

Under s 20 of the Financial Accountability Regime Act 2023 (Cth), an accountable entity must take reasonable steps to comply with its accountability obligations. These include conducting its business with due skill, care and diligence and taking reasonable steps to ensure its accountable persons comply with their own accountability obligations.

The FAR also retains requirements concerning the allocation of responsibility. Under s 23 of the Financial Accountability Regime Act 2023 (Cth), accountable entities have key personnel obligations that include ensuring that responsibilities are appropriately allocated across accountable persons.

In practical terms, regulated entities should be able to identify who is accountable for important areas such as:

  • cyber security;
  • information technology systems;
  • digital customer services;
  • operational resilience;
  • third-party technology arrangements; and
  • information security risk.

A critical technology function should not sit between business units or executives without clearly allocated responsibility.

APRA and ASIC announced proposed changes in June 2026 intended to reduce some FAR administrative requirements, including changes relating to key-function and accountability-map reporting. However, those proposed reforms do not remove the underlying statutory accountability obligations imposed by the FAR.

What Should APRA-Regulated Entities Review Following This Case?

The Bendigo Bank proceeding provides a useful opportunity for regulated entities to test whether their cyber governance operates effectively in practice, rather than simply whether required policies and documents exist.

Businesses should consider reviewing whether:

  • Authentication controls remain appropriate: Password requirements, multi-factor authentication and other access controls should reflect current threats and the sensitivity of the relevant systems.
  • Penetration test findings are actually remediated: Material findings should be assessed, allocated to an owner, tracked and escalated where appropriate.
  • Testing covers the controls that matter: Third-party reports or broad assurance exercises may not be sufficient if they do not test critical customer-facing or security controls.
  • CPS 234 testing is systematic: Testing should cover relevant information assets and security controls and evolve as threats, systems and vulnerabilities change.
  • Executive responsibility is clearly allocated: FAR accountability arrangements should reflect responsibility for cyber, IT and information security across business units, subsidiaries and external platforms.
  • Organisational changes trigger accountability reviews: Changes to executive roles, reporting lines or technology ownership may create gaps if accountability statements and governance arrangements are not updated.
  • Operational risk and cyber risk are considered together: Current CPS 230 Operational Risk Management obligations require APRA-regulated entities to manage operational risk, maintain effective controls and appropriately manage risks associated with service providers.

These steps should be tailored to the nature, scale and complexity of the particular entity, and if you are unsure how they apply to your organisation, you can speak with our financial services lawyers.

The Bendigo Bank case should not be interpreted as establishing a single technical standard that every regulated entity must follow. Rather, it demonstrates the regulatory consequences that can arise when known vulnerabilities, incomplete testing and unclear accountability operate together.

The Proposed $8 Million Penalty Is Not Yet Final

APRA and Bendigo Bank have proposed that the Federal Court impose an $8 million pecuniary penalty for the admitted BEAR contraventions.

APRA’s originating application seeks declarations and pecuniary penalties under the applicable provisions of the former BEAR framework, including former s 37G and Schedule 2 of the Banking Act 1959 (Cth).

However, the proposed penalty is not yet a final court-imposed penalty. It remains for the Federal Court to determine:

  • whether the proposed declarations should be made;
  • whether a pecuniary penalty is appropriate;
  • the appropriate amount of any penalty; and
  • whether any other orders should be made.

The agreed facts also record Bendigo Bank’s cooperation, acceptance of responsibility and remediation following the incident.

APRA has expressly stated that the proceedings relate to historical conduct and control weaknesses that were satisfactorily remediated following the cyber attack. APRA has also confirmed that it does not currently have concerns about the adequacy of Bendigo Bank’s information security controls.

That context is important, but the proceeding also demonstrates that later remediation does not necessarily prevent enforcement action for earlier compliance failures.

Conclusion

The Bendigo Bank proceeding shows that cyber security is not simply an IT issue. For APRA-regulated entities, weaknesses in technical controls can also raise questions about prudential compliance, risk management and whether executive accountability has been properly allocated.

The key lesson is to ensure that material vulnerabilities are identified, tested, remediated and escalated appropriately, with clear responsibility for critical systems under the FAR. Regularly reviewing cyber controls and accountability arrangements can help identify gaps before they develop into broader regulatory issues — contact our financial services lawyers at Click Legal to review these arrangements for your organisation.

Frequently Asked Questions

JUMP TO...
Table of Contents

Published By:

Hannah Deuk

Founder & Principal Lawyer

Request A Free Consultation

Our senior lawyers will contact you to discuss your situation & outline next steps.

Insights Library

Legal & Compliance Insights

Browse practical articles, guides & updates from our lawyers on key legal & compliance issues.

Join our Newsletter

Subscribe to our newsletter for the latest legal updates, insights, and firm news delivered straight to your inbox.

What Our Clients Say About Working With Us

Ready-to-Use Legal & Compliance Templates

Lawyer‑drafted legal templates in downloadable Word format.

CONTACT

Request A Consultation

Not sure which matter or service is right for you? Leave your details & our lawyers will contact you to discuss your situation & outline next steps.

Inquire Now

Tell us briefly what you need help with & we’ll reply within 1 business day.