APRACivil Money Penaltyhigh

Bendigo and Adelaide Bank

Bendigo, Victoria, Australia

APRA commenced Federal Court proceedings against Bendigo and Adelaide Bank on Aug 11, 2026, seeking court approval for an $8 million penalty. The bank admitted it had breached executive-accountability obligations connected to a March 2023 cyber attack on its former Alliance Bank business. An unidentified threat actor accessed approximately 257 customer accounts during the attack.

The breach resulted in 286 unauthorised transactions affecting 87 Alliance Bank customers. APRA's proposed civil penalty followed an investigation into the incident and the bank's handling of its accountability standards. The action puts scrutiny on digital controls and executive responsibility at Australia's sixth-largest bank.

Implications
  1. Demonstrates that prudential regulators globally are holding banks accountable for cyber risk management failures tied to technology operations
  2. Executive accountability frameworks may be applied to BaaS banks whose fintech partnerships introduce cyber risk
  3. Banks offering technology-dependent services face heightened scrutiny over operational resilience controls
Source
Related
Share