Major Australian Bank Faces Proposed $8M Penalty Over Cybersecurity Failures
August 18, 2026Read also: The UK’s ICO reprimands ACRO over a security breach; California fines two data brokers; and more.

Bendigo Bank faces proposed $8M penalty over cybersecurity failures
Bendigo and Adelaide Bank is facing a proposed $8 million penalty after admitting to cybersecurity failures that led to almost $500,000 in unauthorized transactions.
In March 2023, a hacker exploited weaknesses in the online banking system of the since-discontinued Service One Alliance Bank. The attacker gained access to about 257 customer accounts and made 286 unauthorized transactions worth around $490,000 across 87 customers.
The Australian Prudential Regulation Authority (APRA), the country’s financial safety regulator, said the bank had significant weaknesses in its customer authentication controls, including weak password settings, customers sharing identical passwords and system features that allowed attackers to identify valid customer IDs.
Some of the issues had been found during penetration testing in 2020 but were not addressed before the attack. The intruder carried out the activity between 3 and 7 March 2023. Bendigo Bank was unable to recover about $140,000 but reimbursed all affected customers.
APRA has since started civil penalty proceedings against the bank in the Federal Court. Bendigo Bank has admitted breaching its obligations under the Banking Executive Accountability Regime (BEAR), including failures in customer security, testing, governance and risk management. The proposed penalty will now be considered by the Federal Court.
California Privacy Agency fines a data broker $116,490
California’s privacy regulator has fined Iowa-based data broker LocateSmarter $116,490 for making it difficult for consumers to opt out of the sale of their personal information.
The penalty is the agency’s first enforcement action involving violations of both the California Consumer Privacy Act and the state’s Delete Act. According to the California Privacy Protection Agency, LocateSmarter failed to register as a data broker and required consumers to provide the last four digits of their Social Security numbers to submit opt-out requests.
The company collected sensitive personal information, including names, driver’s license details, dates of birth, employment records, and bankruptcy and litigation information, according to the watchdog. Requiring consumers to provide unnecessary personal data to exercise their privacy rights violated the state’s data-minimization requirements.
Under the settlement, LocateSmarter must register as a data broker and revise its practices to make it easier for consumers to exercise their privacy rights.
Separately, the regulator fined another data broker, Cybba, Inc., $52,400 for failing to register with the state’s Data Broker Registry by the 2025 deadline. Cybba sells personal data, including location and internet activity, for targeted advertising. The watchdog also requires Cybba to provide privacy-rights information on its website, use the DROP system, and process future deletion requests. DROP allows consumers to ask all registered data brokers to delete their personal information with one request.
US mortgage lender ordered to pay $825,000 for data security failures
The California Department of Financial Protection and Innovation (DFPI) has ordered Utah-based Academy Mortgage Corporation to pay $825,000 after finding that the company failed to properly protect the personal information of more than 284,443 people.
The DFPI found that the company had long-running cybersecurity and recordkeeping problems that made the firm vulnerable to a ransomware attack in March 2023. The breach was discovered only after employee credentials were stolen and network security systems were disabled.
The regulator also found that Academy Mortgage did not obtain a written forensic report documenting the breach, limiting information about what happened. Affected customers were notified of the data breach in December 2023.
The consent order between the DFPI and Academy Mortgage Corporation also requires the company to notify all affected California customers that they can receive 12 months of identity theft insurance. Customers will need to opt in, and the company will provide instructions on how to do so, along with a contact for questions. Academy Mortgage must also comply with California laws and maintain proper cybersecurity systems and procedures.
ORC, Purpleline fined GH¢360,000 for cybersecurity breaches
Ghana’s Cyber Security Authority (CSA) has fined the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited a total of GH¢360,000 (€28,235) for breaching the country’s cybersecurity regulations.
The ORC was fined GH¢240,000 (€18,823) for failing to comply with a directive to use only licensed cybersecurity service providers for services involving its critical information infrastructure.
The CSA said the ORC contracted Purpleline Solutions even though the company did not have the required cybersecurity license. The ORC was fined 10,000 penalty units for each of two breaches and has been given one month to comply with the outstanding directives.
Purpleline Solutions was separately fined GH¢120,000 (€9,412) for providing regulated cybersecurity services without a license. The company applied for a license on July 15, 2026, but the CSA said the application came after it had already been engaged by the ORC.
The UK’s ICO reprimands ACRO over a security breach that exposed personal data
The UK’s Information Commissioner’s Office (ICO) has reprimanded the ACRO Criminal Records Office after cybersecurity failings potentially exposed the personal information of up to 10,920 people.
ACRO is a national police unit responsible for services including police certificates, international child protection certificates, subject access requests and record deletion requests.
The ICO found that a hacker gained unauthorized access to ACRO’s website and content management system between August 2022 and March 2023. It’s not clear if the information was stolen because ACRO didn’t have enough logs to confirm the data was actually exfiltrated from its systems.
The breach potentially exposed names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank information and biometric data. Some records also contained sensitive criminal offense and other special category information. The affected people included applicants for police certificates, international child protection certificates and subject access requests, as well as third parties linked to those applications.
In one incident, an SQL injection attack exposed 15 usernames and passwords, most of them belonging to ACRO employees. The ICO said the most serious incident took place between 5 August 2022 and 14 March 2023. During this period, the attacker maintained access to ACRO’s website and CMS environment.
The ICO found that ACRO used third-party companies to provide some security services, including software updates. However, the agency did not clearly assign responsibility for finding and checking important security updates for its CMS. It also did not have an effective process for applying updates and did not properly investigate security warnings alerting to the possible breach.
The ICO decided to issue a reprimand but considered several factors that reduced the seriousness of the situation. ACRO’s network was separated into different parts, which stopped the hacker from reaching its main systems through the affected website. The ICO also recognized the steps ACRO took after the incident, including shutting down the affected systems, moving services to different infrastructure, adding better security monitoring, improving its ability to detect cyber threats, and strengthening the separation between its networks.
What’s next:
- Request a free product demo or pricing
- Register for our webinars and product trainings
- Read our Cybercrime Investigations weekly blog
- Follow us on LinkedIn, X, Telegram and WhatsApp
- Subscribe to our Newsletter
- Join our Partner Program