Berliner Boersenzeitung - Repeat hacks highlight Australia's cyber flaws

EUR -
AED 4.093506
AFN 76.885697
ALL 99.156844
AMD 431.61136
ANG 2.009212
AOA 1033.996627
ARS 1072.997336
AUD 1.641238
AWG 2.006096
AZN 1.894898
BAM 1.953947
BBD 2.250965
BDT 133.223643
BGN 1.952711
BHD 0.420041
BIF 3231.776803
BMD 1.114498
BND 1.440534
BOB 7.703555
BRL 6.123719
BSD 1.114843
BTN 93.176654
BWP 14.737155
BYN 3.64844
BYR 21844.159752
BZD 2.247128
CAD 1.513226
CDF 3199.72349
CHF 0.948009
CLF 0.037589
CLP 1037.207355
CNY 7.861562
CNH 7.857762
COP 4641.270973
CRC 578.440993
CUC 1.114498
CUP 29.534196
CVE 110.159036
CZK 25.061677
DJF 198.518152
DKK 7.458688
DOP 66.916533
DZD 147.443868
EGP 54.087145
ERN 16.717469
ETB 129.365881
FJD 2.455963
FKP 0.848756
GBP 0.838887
GEL 3.04302
GGP 0.848756
GHS 17.526063
GIP 0.848756
GMD 76.360453
GNF 9631.735079
GTQ 8.617904
GYD 233.214621
HKD 8.68467
HNL 27.654771
HRK 7.577484
HTG 147.097844
HUF 393.219452
IDR 16938.139791
ILS 4.215003
IMP 0.848756
INR 93.066206
IQD 1460.414859
IRR 46912.005489
ISK 152.106934
JEP 0.848756
JMD 175.153874
JOD 0.78973
JPY 160.913487
KES 143.815085
KGS 93.883634
KHR 4527.705666
KMF 491.883517
KPW 1003.04752
KRW 1489.253392
KWD 0.340031
KYD 0.929027
KZT 534.493464
LAK 24617.20987
LBP 99832.321807
LKR 340.137394
LRD 222.964527
LSL 19.571513
LTL 3.290823
LVL 0.674149
LYD 5.294169
MAD 10.810335
MDL 19.453724
MGA 5042.127276
MKD 61.543927
MMK 3619.845856
MNT 3787.063972
MOP 8.948752
MRU 44.304377
MUR 51.133282
MVR 17.119128
MWK 1932.93201
MXN 21.562748
MYR 4.686458
MZN 71.160467
NAD 19.571337
NGN 1827.163772
NIO 41.030532
NOK 11.743114
NPR 149.085599
NZD 1.79238
OMR 0.429047
PAB 1.114823
PEN 4.178581
PGK 4.364018
PHP 62.09258
PKR 309.759007
PLN 4.271826
PYG 8697.750557
QAR 4.064445
RON 4.974451
RSD 117.076905
RUB 103.223004
RWF 1502.88806
SAR 4.182122
SBD 9.258064
SCR 14.81171
SDG 670.372494
SEK 11.382251
SGD 1.441191
SHP 0.848756
SLE 25.463272
SLL 23370.458959
SOS 637.101453
SRD 33.663463
STD 23067.857331
SVC 9.754617
SYP 2800.209454
SZL 19.578606
THB 36.808558
TJS 11.850548
TMT 3.900743
TND 3.377996
TOP 2.610264
TRY 38.023817
TTD 7.582672
TWD 35.665604
TZS 3038.346537
UAH 46.080848
UGX 4130.23089
USD 1.114498
UYU 46.065689
UZS 14186.544671
VEF 4037327.360851
VES 40.96537
VND 27422.221975
VUV 132.315435
WST 3.117767
XAF 655.323694
XAG 0.035728
XAU 0.000426
XCD 3.011987
XDR 0.826216
XOF 655.326631
XPF 119.331742
YER 278.9867
ZAR 19.526231
ZMK 10031.815557
ZMW 29.514477
ZWL 358.867884
  • RIO

    -1.3800

    63.8

    -2.16%

  • CMSC

    0.0300

    25.15

    +0.12%

  • BCC

    -1.1190

    143.571

    -0.78%

  • BTI

    -0.1250

    37.445

    -0.33%

  • SCS

    -0.2600

    13.05

    -1.99%

  • CMSD

    0.0300

    25.04

    +0.12%

  • NGG

    0.8000

    69.63

    +1.15%

  • RYCEF

    0.0100

    6.96

    +0.14%

  • BP

    -0.0450

    32.715

    -0.14%

  • RBGPF

    3.5000

    60.5

    +5.79%

  • JRI

    -0.0750

    13.325

    -0.56%

  • BCE

    -0.2800

    34.91

    -0.8%

  • GSK

    -0.6250

    40.995

    -1.52%

  • RELX

    -0.0350

    48.095

    -0.07%

  • AZN

    -0.2400

    78.66

    -0.31%

  • VOD

    -0.0400

    10.02

    -0.4%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: Muhammad FAROOQ - AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

(T.Burkhard--BBZ)