Home/Incidents/Bendigo and Adelaide Bank (Alliance Bank)

Bendigo and Adelaide Bank (Alliance Bank)

11 Aug 2026 · National · Finance & Insurance
Unauthorised Access CRITICAL ✓ Verified

What happened

The Australian Prudential Regulation Authority (APRA) initiated Federal Court civil penalty proceedings against Bendigo and Adelaide Bank, with the bank admitting to breaching Banking Executive Accountability Regime (BEAR) and Prudential Standard CPS 234 obligations. The enforcement action relates to a March 2023 cyber incident targeting its former Alliance Bank digital banking platform, where an attacker exploited weak authentication controls and identical password settings to compromise 257 customer accounts and execute $490,000 in fraudulent transactions across 87 users. APRA revealed 2020 penetration testing had identified the specific authentication vulnerabilities, but the bank failed to remediate them prior to the attack. Bendigo Bank agreed to a proposed $8 million pecuniary penalty.

Incident details

Organisation
Bendigo and Adelaide Bank (Alliance Bank)
Date
11 Aug 2026
Attack type
Unauthorised Access
Severity
CRITICAL
Sector
Finance & Insurance
State
National
Records affected
257
Threat actor
Unknown

Source

apra.gov.au ↗
← Back to all incidents