On 10 August 2026, APRA filed civil penalty proceedings in the Federal Court against Bendigo and Adelaide Bank. Most of the coverage led with a password. At the moment the attack began, 1,598 customer accounts were protected by “123456”.
That is the memorable detail. It is not the important one.
The important one is that from 29 August 2022 to 30 August 2023 — a full year, spanning the attack — no accountable person at Bendigo held responsibility for the IT operations of Alliance Bank, a network of five consumer banking brands serving 38,000 of the bank’s own customers.
Not because anyone refused it. Because in August 2022, during an exercise expressly designed to identify accountability gaps, the responsibility was excluded from the Chief Technology Officer’s accountability statement. A slide deck circulated to the executive team recorded the intended recipient as “TBC”. A later version was annotated “roles confirmed”. The statement was signed the following month.
The TBC was never resolved. The responsibility landed nowhere.
The platform that sat outside
Alliance Bank was a network of five former credit unions — AWA, BDCU, Circle, Service One and Nova — operating as authorised representatives under Bendigo’s banking licence. Its customers were Bendigo’s customers. Its regulatory obligations were Bendigo’s obligations.
But it did not run on Bendigo’s platform. It ran on Ultracs, core banking software licensed from Ultradata and hosted by a third party, across four separate instances with similar but not identical access control configurations. A migration onto Bendigo’s own systems had been contemplated within two years of launch in 2015. Eight years later it still had not happened.
It was run under a “business managed IT” model, meaning the business unit using the technology owned it rather than the Technology division. The person responsible for information security at Alliance Bank, and the business system owner for Ultracs, was the Head of Alliance Bank — who was not an accountable person under the BEAR, and had no professional background or formal qualifications in information technology or information security.
Bendigo’s own committees and board raised the risks of that model repeatedly between 2020 and 2022, including the observation that it meant the bank did not know all the technology in use across the organisation and could therefore be harbouring unidentified vulnerabilities. One board query asked why an agreed position was taking so long to action.
Thirty-three months, three chances
Bendigo repaid every affected customer within four days, and has since remediated comprehensively: 48 post-incident actions completed by May 2024, business managed IT dismantled, Alliance Bank discontinued and its customers migrated by June 2024. APRA has stated the conduct is historical and satisfactorily remediated, and that it does not currently have concerns about Bendigo’s information security controls.
What Bendigo already had
This is the part that should give practitioners pause.
In force at the time of the attack
- Information Security Policy
- Operational Risk Framework with a formal escalation matrix
- Technology Risk Management Framework
- Password Management Standard
- Business System Ownership Policy and Control Standard
- CPS 234 Controls Testing Framework, in force since September 2020
- Cyber incident and major incident response plans
- Three lines of defence model and annual control self-assessments
- Enterprise operational risk system
- Register of accountable persons with signed statements
That is a more complete framework estate than most Australian organisations maintain. Put it in front of a conventional maturity assessment and it returns a clean result.
Every one of those instruments existed. None of them reached Alliance Bank.
The CPS 234 Controls Testing Framework was not applied to Alliance Bank’s authentication controls. The Password Management Standard applied on paper and was not implemented. The penetration test findings were never assessed against the Operational Risk Framework and never escalated to anyone. The platform was never adequately integrated into Bendigo’s security monitoring, so notable events could not be detected.
The frameworks were not deficient. One part of the business sat outside them, and the instruments that should have detected that were pointed elsewhere.
Why the assurance did not help
Bendigo held four separate assurance artefacts covering the Alliance Bank environment. The failed control appeared in none of them.
- ASAE 3402 — annual reports received from the hosting provider, covering managed operations infrastructure. The standard is scoped to controls relevant to user entities’ financial reporting. It was never going to consider whether a customer’s password could be guessed.
- ASAE 3150 — a report from the software vendor assessing the design and implementation of the vendor’s own corporate infrastructure at a single date. Not the instances Alliance Bank customers logged into, and no operating effectiveness over a period.
- BDO control validation — a 2022 documentation review of back-end operational control areas. Customer authentication for online and mobile banking was explicitly out of scope.
- Business unit testing — annual internal control testing that, other than the 2020 penetration test, did not include customer authentication controls.
None of these was a bad report. Each did precisely what its scope required. Two of them were received from vendors rather than commissioned by Bendigo — entirely ordinary, since a service provider commissions one report and distributes it across its client base, which is why the scope reflects the vendor’s purposes rather than any particular client’s obligations.
Bendigo’s own CPS 234 Framework called for assurance mapping to confirm the testing program was complete and identify gaps. It was not applied here. The admitted contravention is not that the assurance was poor — it is that there was no systematic testing program determining what needed testing and confirming it had been done.
How the accountability disappeared
The second contravention is the more instructive one, and it has the wider application.
Bendigo’s CTO had been an accountable person since November 2019, with responsibility covering the direction of business- and function-managed IT operations so they did not compromise confidentiality, integrity or availability. From August 2020 a qualification was added carving out systems and software run by particular business units — without naming which ones.
In June 2022 Bendigo began updating executive accountability statements. In August, a deck circulated to the executive team listed the proposed exclusions for each executive alongside the executive who would inherit them, and asked executives to review the exclusions to identify gaps. Item six read: IT Operations for Alliance Bank is excluded. A later version showed the proposed recipient as “Alliance Bank & CCO, Consumer (TBC)”, annotated “roles confirmed”. The CTO signed the updated statement in September, effective 29 August 2022.
The excluded responsibilities had never appeared in Bendigo’s accountability statements before, and were never directly written into any other accountable person’s statement. The Chief Customer Officer’s statement of the very same date did not pick them up. The Rural Bank executive who had previously held Alliance Bank responsibilities had departed in February 2022, and those statements had never referenced IT operations or information security in any event.
The obligation was carved out of one statement in a process built to find exactly this, marked provisional, and never landed. The CTO’s next signed statement, dated 30 August 2023 — after the attack — no longer contained the exclusions.
Three questions worth asking this quarter
None of these is a framework question. All three are coverage questions, and all three are answerable in an afternoon.
- Show me the coverage map, not the framework. Every information asset against every control test, with dates. Not the policy requiring testing — the record of what was actually tested and when. If the answer for any asset is “we would have to check”, that asset is in the position Alliance Bank was in for three years.
- Reconcile every accountability exclusion against its inclusion. Take each carve-out from every accountability statement and trace where the responsibility landed. Anything marked provisional, pending or to be confirmed is an open gap until a corresponding signed inclusion exists.
- Which assets are outside the security operating model? Not “do we have monitoring” — which assets are not in it. Which systems are owned by business units rather than technology. Which run on infrastructure that is not yours, under a licence that is. That population is almost always larger than the executive expects, and it is where accountability quietly stops.
The timing
What survives this case is the precedent. This is APRA taking a control failure — a password policy and a testing program — to the Federal Court, rather than resolving it supervisorily. APRA’s stated message was that regulated entities must have appropriate cyber protection systems and must regularly test whether those controls are adequate.
It arrives six weeks after CPS 230 took full effect on 1 July 2026, a standard that presses considerably harder on service provider management and operational resilience than CPS 234 did alone.
The organisations most exposed are not the ones with weak frameworks. They are the ones with strong frameworks and an unexamined assumption about how far those frameworks reach.
An independent, evidenced view of what your organisation exposes — including the platforms and brands that sit outside the core estate. Passive only, no systems accessed. From $1,500 ex GST.
View Assessment Start with a Threat Scan →Frequently Asked Questions
What did Bendigo Bank admit to?
Two contraventions of the Banking Act 1959 arising from a March 2023 cyber attack on Alliance Bank: failing to conduct its business with due skill, care and diligence, and failing to ensure the responsibilities of accountable persons covered all parts of its operations. The admitted failures were inadequate customer authentication controls, no systematic testing program under CPS 234, inadequate governance of the platform, and no accountable person covering Alliance Bank IT operations.
Has Bendigo Bank been fined $8 million?
No penalty has been ordered. APRA and Bendigo have jointly proposed an $8 million pecuniary penalty, but the originating application nominates no figure and asks the Federal Court to fix an appropriate amount. It remains for the Court to determine whether the declarations and any penalty are appropriate.
Why did the assurance reports not identify the problem?
Because each was scoped to something else. ASAE 3402 is scoped to controls relevant to user entities’ financial reporting; the ASAE 3150 report covered the software vendor’s own corporate infrastructure; the BDO validation reviewed back-end operational documentation with customer authentication out of scope. The admitted contravention was the absence of a systematic testing program, not deficient assurance work.
What does this mean under the Financial Accountability Regime?
The accountability failure arose when a responsibility was excluded from one executive’s statement and never written into another, with the intended recipient recorded as to be confirmed. The FAR has replaced the BEAR and extends to insurance and superannuation, so the same failure mode now applies far more widely. Every exclusion should be treated as an open gap until a corresponding signed inclusion exists.
Is Bendigo Bank still exposed?
APRA has stated the conduct is historical and satisfactorily remediated, and that it does not currently have concerns about Bendigo’s information security controls. Alliance Bank was discontinued and its customers migrated by June 2024, the business managed IT model was dismantled, and 48 post-incident remediation actions were completed by May 2024.