The China Mail - Repeat hacks highlight Australia's cyber flaws

USD -
AED 3.6725
AFN 64.000071
ALL 82.507456
AMD 367.703735
ANG 1.790403
AOA 917.486806
ARS 1481.204487
AUD 1.455583
AWG 1.8
AZN 1.702518
BAM 1.713097
BBD 2.011903
BDT 123.11735
BGN 1.69088
BHD 0.37663
BIF 2971.783429
BMD 1
BND 1.292103
BOB 6.917906
BRL 5.173975
BSD 0.998945
BTN 94.390722
BWP 13.575192
BYN 2.897008
BYR 19600
BZD 2.009013
CAD 1.42389
CDF 2274.999746
CHF 0.809855
CLF 0.023433
CLP 922.240245
CNY 6.79395
CNH 6.794015
COP 3444.75
CRC 453.094276
CUC 1
CUP 26.5
CVE 96.581777
CZK 21.29395
DJF 177.883078
DKK 6.56346
DOP 59.402385
DZD 133.344161
EGP 49.318599
ERN 15
ETB 161.045542
EUR 0.87812
FJD 2.24975
FKP 0.75464
GBP 0.75585
GEL 2.640095
GGP 0.75464
GHS 11.298312
GIP 0.75464
GMD 73.505896
GNF 8757.385047
GTQ 7.621225
GYD 208.956139
HKD 7.842625
HNL 26.733762
HRK 6.615302
HTG 130.560263
HUF 311.496947
IDR 17901.8
ILS 2.983605
IMP 0.75464
INR 94.644501
IQD 1308.597856
IRR 1376000.0002
ISK 126.459561
JEP 0.75464
JMD 157.289691
JOD 0.709016
JPY 162.355504
KES 129.450268
KGS 87.450264
KHR 4016.834619
KMF 431.999871
KPW 900.00035
KRW 1548.204971
KWD 0.30975
KYD 0.832454
KZT 485.019949
LAK 22404.211245
LBP 89452.529331
LKR 335.883613
LRD 181.802256
LSL 16.412646
LTL 2.95274
LVL 0.60489
LYD 6.417595
MAD 9.36107
MDL 17.65605
MGA 4250.809125
MKD 54.129403
MMK 2099.487458
MNT 3582.059186
MOP 8.069687
MRU 39.866691
MUR 47.189577
MVR 15.45991
MWK 1732.206908
MXN 17.492503
MYR 4.072201
MZN 63.849923
NAD 16.412646
NGN 1380.330343
NIO 36.762097
NOK 9.958035
NPR 151.021499
NZD 1.770775
OMR 0.384501
PAB 0.998971
PEN 3.411304
PGK 4.385719
PHP 61.271501
PKR 277.769934
PLN 3.766495
PYG 6083.007432
QAR 3.641301
RON 4.604802
RSD 103.084981
RUB 76.98988
RWF 1466.390474
SAR 3.752458
SBD 8.065041
SCR 13.42013
SDG 600.518606
SEK 9.737355
SGD 1.294798
SHP 0.746601
SLE 24.803463
SLL 20969.503664
SOS 570.895539
SRD 37.494501
STD 20697.981008
STN 21.459979
SVC 8.74059
SYP 110.532098
SZL 16.408648
THB 33.282006
TJS 9.260125
TMT 3.51
TND 2.958885
TOP 2.40776
TRY 46.658977
TTD 6.790721
TWD 31.854498
TZS 2628.473028
UAH 44.832941
UGX 3661.287144
UYU 40.195503
UZS 12039.275454
VES 622.24352
VND 26310
VUV 119.95305
WST 2.78094
XAF 574.561715
XAG 0.017427
XAU 0.000251
XCD 2.70255
XCG 1.800321
XDR 0.71457
XOF 574.541585
XPF 104.460551
YER 238.60124
ZAR 16.46094
ZMK 9001.203007
ZMW 18.085232
ZWL 321.999592
  • CMSC

    0.1300

    22.06

    +0.59%

  • CMSD

    0.1300

    21.9

    +0.59%

  • RBGPF

    0.6100

    65.61

    +0.93%

  • RELX

    -0.0500

    31.29

    -0.16%

  • BCE

    -0.6600

    22.26

    -2.96%

  • BCC

    -1.7600

    79.26

    -2.22%

  • RIO

    0.5500

    94.29

    +0.58%

  • VOD

    -0.2000

    13.69

    -1.46%

  • NGG

    0.7500

    83.76

    +0.9%

  • RYCEF

    0.2900

    18.68

    +1.55%

  • JRI

    0.0700

    12.86

    +0.54%

  • GSK

    0.3100

    52.81

    +0.59%

  • BTI

    -0.0200

    62.74

    -0.03%

  • AZN

    2.5400

    190.95

    +1.33%

  • BP

    0.2200

    37.35

    +0.59%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: © AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

A.Kwok--ThChM