The Australian Prudential Regulation Authority has commenced Federal Court civil penalty proceedings against Bendigo and Adelaide Bank over admitted breaches of the Banking Executive Accountability Regime linked to a March 2023 cyberattack on its Alliance Bank business. The parties have proposed an AUD 8 million penalty, subject to the court determining whether the declarations, penalty and other orders are appropriate. Bendigo Bank admitted that it failed to maintain adequate customer authentication controls, systematically test those controls as required by Prudential Standard CPS 234 Information Security, establish adequate information security governance and risk management, and assign accountability for Alliance Bank’s IT system to an accountable person. Weaknesses identified in 2020 penetration testing remained unresolved, including weak password settings and a system feature that exposed valid customer IDs. The attacker accessed approximately 257 accounts and made 286 unauthorized transactions totaling about AUD 490,000 across 87 customers. The bank could not recover about AUD 140,000 but reimbursed all affected customers. The proceedings concern historical weaknesses that were remediated after the attack. APRA said it has no current concerns about the adequacy of Bendigo Bank’s information security controls.