The China Mail - Repeat hacks highlight Australia's cyber flaws

USD -
AED 3.672501
AFN 63.000275
ALL 82.697811
AMD 377.229941
ANG 1.790083
AOA 916.999848
ARS 1391.828097
AUD 1.443545
AWG 1.8025
AZN 1.701068
BAM 1.685671
BBD 2.013678
BDT 122.977207
BGN 1.709309
BHD 0.377518
BIF 2965
BMD 1
BND 1.28264
BOB 6.908351
BRL 5.154994
BSD 0.999815
BTN 92.79256
BWP 13.597831
BYN 2.973319
BYR 19600
BZD 2.010774
CAD 1.387495
CDF 2295.000278
CHF 0.79374
CLF 0.023121
CLP 912.959992
CNY 6.872032
CNH 6.876455
COP 3673.42
CRC 464.839659
CUC 1
CUP 26.5
CVE 95.501128
CZK 21.147006
DJF 177.720133
DKK 6.445503
DOP 60.498182
DZD 132.786355
EGP 53.516702
ERN 15
ETB 157.000501
EUR 0.862499
FJD 2.253801
FKP 0.758501
GBP 0.751285
GEL 2.690026
GGP 0.758501
GHS 10.999694
GIP 0.758501
GMD 73.500677
GNF 8779.999839
GTQ 7.648319
GYD 209.250209
HKD 7.83755
HNL 26.620289
HRK 6.500499
HTG 131.237691
HUF 330.560504
IDR 16937
ILS 3.13645
IMP 0.758501
INR 92.64295
IQD 1309.5
IRR 1318875.000028
ISK 124.5498
JEP 0.758501
JMD 158.120413
JOD 0.708971
JPY 158.726981
KES 130.050003
KGS 87.449658
KHR 4010.50148
KMF 426.749751
KPW 899.943346
KRW 1513.249796
KWD 0.30946
KYD 0.833229
KZT 475.292069
LAK 21952.505413
LBP 89195.600604
LKR 315.172096
LRD 183.849818
LSL 16.944964
LTL 2.95274
LVL 0.60489
LYD 6.374968
MAD 9.325007
MDL 17.611846
MGA 4175.000008
MKD 53.184193
MMK 2100.405998
MNT 3572.722217
MOP 8.072575
MRU 40.129569
MUR 46.78984
MVR 15.449535
MWK 1736.999767
MXN 17.82435
MYR 4.020498
MZN 63.960387
NAD 16.944979
NGN 1380.03048
NIO 36.709931
NOK 9.71384
NPR 148.468563
NZD 1.739025
OMR 0.384493
PAB 0.999836
PEN 3.47801
PGK 4.358966
PHP 60.180014
PKR 279.201607
PLN 3.694545
PYG 6493.344193
QAR 3.644504
RON 4.397298
RSD 101.201993
RUB 80.300679
RWF 1461
SAR 3.753461
SBD 8.009975
SCR 14.03822
SDG 601.000186
SEK 9.41201
SGD 1.282745
SHP 0.750259
SLE 24.609359
SLL 20969.510825
SOS 571.497886
SRD 37.363999
STD 20697.981008
STN 21.5
SVC 8.748077
SYP 110.747305
SZL 16.93499
THB 32.602324
TJS 9.560589
TMT 3.5
TND 2.91425
TOP 2.40776
TRY 44.491695
TTD 6.785987
TWD 32.016996
TZS 2589.999963
UAH 43.749677
UGX 3724.309718
UYU 40.637618
UZS 12199.999993
VES 473.325203
VND 26335
VUV 120.24399
WST 2.777713
XAF 565.390002
XAG 0.013235
XAU 0.000209
XCD 2.70255
XCG 1.801759
XDR 0.710952
XOF 564.498872
XPF 103.303045
YER 238.624981
ZAR 16.809899
ZMK 9001.197909
ZMW 19.270981
ZWL 321.999592
  • RBGPF

    -13.5000

    69

    -19.57%

  • CMSD

    0.0500

    22.15

    +0.23%

  • NGG

    2.2400

    86.84

    +2.58%

  • BCE

    0.1400

    25.38

    +0.55%

  • CMSC

    0.0900

    21.99

    +0.41%

  • RIO

    1.5200

    94.81

    +1.6%

  • RYCEF

    0.9500

    16

    +5.94%

  • GSK

    0.8000

    55.99

    +1.43%

  • AZN

    3.5100

    200.73

    +1.75%

  • RELX

    0.0800

    33.23

    +0.24%

  • BTI

    -0.5800

    57.89

    -1%

  • BCC

    -0.7700

    75.08

    -1.03%

  • VOD

    0.1100

    15.13

    +0.73%

  • JRI

    0.2200

    12.52

    +1.76%

  • BP

    -0.8300

    46.17

    -1.8%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: © AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

A.Kwok--ThChM