The China Mail - Repeat hacks highlight Australia's cyber flaws

USD -
AED 3.672504
AFN 66.344071
ALL 83.58702
AMD 382.869053
ANG 1.789982
AOA 917.000367
ARS 1405.057166
AUD 1.540832
AWG 1.805
AZN 1.70397
BAM 1.691481
BBD 2.013336
BDT 122.007014
BGN 1.69079
BHD 0.374011
BIF 2943.839757
BMD 1
BND 1.3018
BOB 6.91701
BRL 5.332404
BSD 0.999615
BTN 88.59887
BWP 13.420625
BYN 3.406804
BYR 19600
BZD 2.010326
CAD 1.40485
CDF 2150.000362
CHF 0.80538
CLF 0.024066
CLP 944.120396
CNY 7.11935
CNH 7.12515
COP 3780
CRC 501.883251
CUC 1
CUP 26.5
CVE 95.363087
CZK 21.009504
DJF 177.720393
DKK 6.457204
DOP 64.223754
DZD 129.411663
EGP 46.950698
ERN 15
ETB 154.306137
EUR 0.86435
FJD 2.28425
FKP 0.759642
GBP 0.759936
GEL 2.70504
GGP 0.759642
GHS 10.930743
GIP 0.759642
GMD 73.000355
GNF 8677.076622
GTQ 7.659909
GYD 209.133877
HKD 7.78025
HNL 26.282902
HRK 6.514104
HTG 133.048509
HUF 332.660388
IDR 16685.5
ILS 3.26205
IMP 0.759642
INR 88.639504
IQD 1309.474904
IRR 42100.000352
ISK 126.580386
JEP 0.759642
JMD 160.439
JOD 0.70904
JPY 153.43504
KES 129.203801
KGS 87.450384
KHR 4023.264362
KMF 421.00035
KPW 899.998686
KRW 1455.990383
KWD 0.306904
KYD 0.83302
KZT 524.767675
LAK 21703.220673
LBP 89512.834262
LKR 304.684561
LRD 182.526573
LSL 17.315523
LTL 2.95274
LVL 0.60489
LYD 5.458091
MAD 9.265955
MDL 17.042585
MGA 4492.856402
MKD 53.206947
MMK 2099.464216
MNT 3582.836755
MOP 8.007472
MRU 39.595594
MUR 45.910378
MVR 15.405039
MWK 1733.369658
MXN 18.451604
MYR 4.176039
MZN 63.950377
NAD 17.315148
NGN 1436.000344
NIO 36.782862
NOK 10.160376
NPR 141.758018
NZD 1.776515
OMR 0.38142
PAB 0.999671
PEN 3.37342
PGK 4.220486
PHP 58.805504
PKR 282.656184
PLN 3.665615
PYG 7072.77311
QAR 3.643196
RON 4.398804
RSD 102.170373
RUB 80.869377
RWF 1452.42265
SAR 3.750713
SBD 8.230592
SCR 13.652393
SDG 600.503676
SEK 9.529804
SGD 1.301038
SHP 0.750259
SLE 23.203667
SLL 20969.499529
SOS 571.228422
SRD 38.599038
STD 20697.981008
STN 21.189281
SVC 8.746265
SYP 11056.879504
SZL 17.321588
THB 32.395038
TJS 9.226139
TMT 3.51
TND 2.954772
TOP 2.342104
TRY 42.209038
TTD 6.77604
TWD 30.981804
TZS 2455.000335
UAH 41.915651
UGX 3498.408635
UYU 39.809213
UZS 12055.19496
VES 228.194038
VND 26310
VUV 122.189231
WST 2.820904
XAF 567.301896
XAG 0.020684
XAU 0.00025
XCD 2.70255
XCG 1.801521
XDR 0.707015
XOF 567.306803
XPF 103.14423
YER 238.503589
ZAR 17.303704
ZMK 9001.203584
ZMW 22.615629
ZWL 321.999592
  • SCS

    0.0000

    15.76

    0%

  • BCC

    -0.0900

    70.64

    -0.13%

  • CMSD

    0.0900

    24.1

    +0.37%

  • RELX

    -1.1200

    42.27

    -2.65%

  • BCE

    0.0200

    23.19

    +0.09%

  • CMSC

    0.0700

    23.85

    +0.29%

  • NGG

    1.4600

    77.75

    +1.88%

  • RBGPF

    -0.7800

    75.22

    -1.04%

  • RIO

    0.0600

    69.33

    +0.09%

  • JRI

    -0.0100

    13.74

    -0.07%

  • RYCEF

    0.0800

    14.88

    +0.54%

  • GSK

    -0.4700

    46.63

    -1.01%

  • VOD

    0.2400

    11.58

    +2.07%

  • BTI

    0.3800

    54.59

    +0.7%

  • BP

    0.7600

    36.58

    +2.08%

  • AZN

    0.8100

    84.58

    +0.96%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: © AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

A.Kwok--ThChM