Intelligence

Bendigo Bank Ran 38,000 Customers on a Platform Nobody Owned.For a year, no accountable person held it.

Evidence-based analysis of threats, regulatory developments and security failures affecting Australian organisations. Passive OSINT only.

RegulatoryCategory
9 minRead time
2026Published
CPS 234 · BEARFrameworks referenced

Passive only — no systems, networks or accounts are accessed at any point.

On 10 August 2026, APRA filed civil penalty proceedings in the Federal Court against Bendigo and Adelaide Bank. Most of the coverage led with a password. At the moment the attack began, 1,598 customer accounts were protected by “123456”.

That is the memorable detail. It is not the important one.

The important one is that from 29 August 2022 to 30 August 2023 — a full year, spanning the attack — no accountable person at Bendigo held responsibility for the IT operations of Alliance Bank, a network of five consumer banking brands serving 38,000 of the bank’s own customers.

Not because anyone refused it. Because in August 2022, during an exercise expressly designed to identify accountability gaps, the responsibility was excluded from the Chief Technology Officer’s accountability statement. A slide deck circulated to the executive team recorded the intended recipient as “TBC”. A later version was annotated “roles confirmed”. The statement was signed the following month.

The TBC was never resolved. The responsibility landed nowhere.

What has actually been decidedNothing yet. Bendigo has admitted the conduct and the parties have jointly proposed an $8 million penalty, but the originating application nominates no figure at all — it asks the Court to fix an appropriate amount. Reports that Bendigo has been “fined” or “hit with” $8 million are premature. No declarations have been made and no penalty ordered.
APRA v Bendigo and Adelaide Bank — VID897/2026
0
between the vulnerability being found and being exploited
0
accounts using the password “123456” when the attack began
0
moved across 286 unauthorised transactions
0
governance frameworks in force that did not reach Alliance Bank
Source: Statement of Agreed Facts and Admissions, VID897/2026, Federal Court of Australia (10 August 2026).

The platform that sat outside

Alliance Bank was a network of five former credit unions — AWA, BDCU, Circle, Service One and Nova — operating as authorised representatives under Bendigo’s banking licence. Its customers were Bendigo’s customers. Its regulatory obligations were Bendigo’s obligations.

But it did not run on Bendigo’s platform. It ran on Ultracs, core banking software licensed from Ultradata and hosted by a third party, across four separate instances with similar but not identical access control configurations. A migration onto Bendigo’s own systems had been contemplated within two years of launch in 2015. Eight years later it still had not happened.

It was run under a “business managed IT” model, meaning the business unit using the technology owned it rather than the Technology division. The person responsible for information security at Alliance Bank, and the business system owner for Ultracs, was the Head of Alliance Bank — who was not an accountable person under the BEAR, and had no professional background or formal qualifications in information technology or information security.

Bendigo’s own committees and board raised the risks of that model repeatedly between 2020 and 2022, including the observation that it meant the bank did not know all the technology in use across the organisation and could therefore be harbouring unidentified vulnerabilities. One board query asked why an agreed position was taking so long to action.

Thirty-three months, three chances

From finding to exploitation
Click any point to read what happened

Bendigo repaid every affected customer within four days, and has since remediated comprehensively: 48 post-incident actions completed by May 2024, business managed IT dismantled, Alliance Bank discontinued and its customers migrated by June 2024. APRA has stated the conduct is historical and satisfactorily remediated, and that it does not currently have concerns about Bendigo’s information security controls.

What Bendigo already had

This is the part that should give practitioners pause.

In force at the time of the attack

  • Information Security Policy
  • Operational Risk Framework with a formal escalation matrix
  • Technology Risk Management Framework
  • Password Management Standard
  • Business System Ownership Policy and Control Standard
  • CPS 234 Controls Testing Framework, in force since September 2020
  • Cyber incident and major incident response plans
  • Three lines of defence model and annual control self-assessments
  • Enterprise operational risk system
  • Register of accountable persons with signed statements

That is a more complete framework estate than most Australian organisations maintain. Put it in front of a conventional maturity assessment and it returns a clean result.

Every one of those instruments existed. None of them reached Alliance Bank.

The CPS 234 Controls Testing Framework was not applied to Alliance Bank’s authentication controls. The Password Management Standard applied on paper and was not implemented. The penetration test findings were never assessed against the Operational Risk Framework and never escalated to anyone. The platform was never adequately integrated into Bendigo’s security monitoring, so notable events could not be detected.

The frameworks were not deficient. One part of the business sat outside them, and the instruments that should have detected that were pointed elsewhere.

Why the assurance did not help

Bendigo held four separate assurance artefacts covering the Alliance Bank environment. The failed control appeared in none of them.

  • ASAE 3402 — annual reports received from the hosting provider, covering managed operations infrastructure. The standard is scoped to controls relevant to user entities’ financial reporting. It was never going to consider whether a customer’s password could be guessed.
  • ASAE 3150 — a report from the software vendor assessing the design and implementation of the vendor’s own corporate infrastructure at a single date. Not the instances Alliance Bank customers logged into, and no operating effectiveness over a period.
  • BDO control validation — a 2022 documentation review of back-end operational control areas. Customer authentication for online and mobile banking was explicitly out of scope.
  • Business unit testing — annual internal control testing that, other than the 2020 penetration test, did not include customer authentication controls.

None of these was a bad report. Each did precisely what its scope required. Two of them were received from vendors rather than commissioned by Bendigo — entirely ordinary, since a service provider commissions one report and distributes it across its client base, which is why the scope reflects the vendor’s purposes rather than any particular client’s obligations.

The transferable pointAn assurance report you did not scope is evidence about your vendor. It is not evidence about your obligation. Four artefacts, individually valid, were filed against a requirement that none of them answered.

Bendigo’s own CPS 234 Framework called for assurance mapping to confirm the testing program was complete and identify gaps. It was not applied here. The admitted contravention is not that the assurance was poor — it is that there was no systematic testing program determining what needed testing and confirming it had been done.

How the accountability disappeared

The second contravention is the more instructive one, and it has the wider application.

Bendigo’s CTO had been an accountable person since November 2019, with responsibility covering the direction of business- and function-managed IT operations so they did not compromise confidentiality, integrity or availability. From August 2020 a qualification was added carving out systems and software run by particular business units — without naming which ones.

In June 2022 Bendigo began updating executive accountability statements. In August, a deck circulated to the executive team listed the proposed exclusions for each executive alongside the executive who would inherit them, and asked executives to review the exclusions to identify gaps. Item six read: IT Operations for Alliance Bank is excluded. A later version showed the proposed recipient as “Alliance Bank & CCO, Consumer (TBC)”, annotated “roles confirmed”. The CTO signed the updated statement in September, effective 29 August 2022.

The excluded responsibilities had never appeared in Bendigo’s accountability statements before, and were never directly written into any other accountable person’s statement. The Chief Customer Officer’s statement of the very same date did not pick them up. The Rural Bank executive who had previously held Alliance Bank responsibilities had departed in February 2022, and those statements had never referenced IT operations or information security in any event.

The obligation was carved out of one statement in a process built to find exactly this, marked provisional, and never landed. The CTO’s next signed statement, dated 30 August 2023 — after the attack — no longer contained the exclusions.

Why this matters beyond bankingThe BEAR has been replaced by the Financial Accountability Regime, which now extends across insurance and superannuation. The same failure mode — an exclusion drafted, workshopped, circulated, annotated and signed, with the receiving owner never confirmed — now applies to a far wider population of entities than it did in 2022.

Three questions worth asking this quarter

None of these is a framework question. All three are coverage questions, and all three are answerable in an afternoon.

  • Show me the coverage map, not the framework. Every information asset against every control test, with dates. Not the policy requiring testing — the record of what was actually tested and when. If the answer for any asset is “we would have to check”, that asset is in the position Alliance Bank was in for three years.
  • Reconcile every accountability exclusion against its inclusion. Take each carve-out from every accountability statement and trace where the responsibility landed. Anything marked provisional, pending or to be confirmed is an open gap until a corresponding signed inclusion exists.
  • Which assets are outside the security operating model? Not “do we have monitoring” — which assets are not in it. Which systems are owned by business units rather than technology. Which run on infrastructure that is not yours, under a licence that is. That population is almost always larger than the executive expects, and it is where accountability quietly stops.
Would the same gap exist in your organisation?
Tick every statement that is true of your organisation today.
We can produce a map of every information asset against the control tests that cover it.
We know which of our assurance reports we scoped, and which arrived from a vendor.
Every accountability exclusion has a matching, signed inclusion elsewhere.
No customer-facing platform is owned by a business unit without security capability.
Every system holding customer data feeds our security monitoring.
We monitor authentication attempts, not only transactions.
Findings rated ‘moderate’ still reach the person who owns the asset.
Tick every statement that is true of your organisation

The timing

What survives this case is the precedent. This is APRA taking a control failure — a password policy and a testing program — to the Federal Court, rather than resolving it supervisorily. APRA’s stated message was that regulated entities must have appropriate cyber protection systems and must regularly test whether those controls are adequate.

It arrives six weeks after CPS 230 took full effect on 1 July 2026, a standard that presses considerably harder on service provider management and operational resilience than CPS 234 did alone.

The organisations most exposed are not the ones with weak frameworks. They are the ones with strong frameworks and an unexamined assumption about how far those frameworks reach.

Passive only — no systems accessedBlackFlag Advisory maps the platforms, brands, interfaces and third-party infrastructure your organisation presents to the internet — the estate as an attacker sees it, not as the asset register describes it. Exclusively passive OSINT using publicly available data. No systems, networks or accounts are accessed, probed or tested.
Related Assessment
CPS 234 Assessment

An independent, evidenced view of what your organisation exposes — including the platforms and brands that sit outside the core estate. Passive only, no systems accessed. From $1,500 ex GST.

View Assessment Start with a Threat Scan →

Frequently Asked Questions

What did Bendigo Bank admit to?

Two contraventions of the Banking Act 1959 arising from a March 2023 cyber attack on Alliance Bank: failing to conduct its business with due skill, care and diligence, and failing to ensure the responsibilities of accountable persons covered all parts of its operations. The admitted failures were inadequate customer authentication controls, no systematic testing program under CPS 234, inadequate governance of the platform, and no accountable person covering Alliance Bank IT operations.

Has Bendigo Bank been fined $8 million?

No penalty has been ordered. APRA and Bendigo have jointly proposed an $8 million pecuniary penalty, but the originating application nominates no figure and asks the Federal Court to fix an appropriate amount. It remains for the Court to determine whether the declarations and any penalty are appropriate.

Why did the assurance reports not identify the problem?

Because each was scoped to something else. ASAE 3402 is scoped to controls relevant to user entities’ financial reporting; the ASAE 3150 report covered the software vendor’s own corporate infrastructure; the BDO validation reviewed back-end operational documentation with customer authentication out of scope. The admitted contravention was the absence of a systematic testing program, not deficient assurance work.

What does this mean under the Financial Accountability Regime?

The accountability failure arose when a responsibility was excluded from one executive’s statement and never written into another, with the intended recipient recorded as to be confirmed. The FAR has replaced the BEAR and extends to insurance and superannuation, so the same failure mode now applies far more widely. Every exclusion should be treated as an open gap until a corresponding signed inclusion exists.

Is Bendigo Bank still exposed?

APRA has stated the conduct is historical and satisfactorily remediated, and that it does not currently have concerns about Bendigo’s information security controls. Alliance Bank was discontinued and its customers migrated by June 2024, the business managed IT model was dismantled, and 48 post-incident remediation actions were completed by May 2024.

SourcesStatement of Agreed Facts and Admissions and Originating Application filed in Australian Prudential Regulation Authority v Bendigo and Adelaide Bank Limited (VID897/2026, Federal Court of Australia, 10 August 2026); APRA media release, 11 August 2026; Banking Act 1959 (Cth) ss 37C, 37D and Schedule 2; Prudential Standard CPS 234 Information Security; Prudential Standard CPS 230 Operational Risk Management. The allegations have been admitted for the purposes of the proceeding only; no declarations have been made and no penalty ordered as at the date of publication. Analysis by BlackFlag Advisory. This article is not legal advice.

Your Frameworks Are Fine.
Do You Know What They Cover?

A BlackFlag Advisory passive assessment maps the platforms, brands and interfaces your organisation actually presents to the internet — then asks who owns each one. That is the question this case turned on.

Request an Assessment →
Passive Only — No Systems Accessed

All BlackFlag Advisory assessments use exclusively passive OSINT techniques and publicly available data sources. No systems, networks, or accounts are accessed, probed, or tested at any time. Board-ready output delivered within three to seven business days.

Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber SOCI / Critical Infrastructure Obligation Tool →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report