The China Mail - Repeat hacks highlight Australia's cyber flaws

USD -
AED 3.673042
AFN 71.000368
ALL 87.350403
AMD 389.04246
ANG 1.80229
AOA 917.000367
ARS 1126.879559
AUD 1.55885
AWG 1.8
AZN 1.70397
BAM 1.738435
BBD 2.018337
BDT 121.453999
BGN 1.737995
BHD 0.376954
BIF 2932.5
BMD 1
BND 1.297726
BOB 6.907279
BRL 5.648504
BSD 0.999613
BTN 85.311254
BWP 13.553823
BYN 3.271247
BYR 19600
BZD 2.00792
CAD 1.39435
CDF 2872.000362
CHF 0.831705
CLF 0.024339
CLP 934.000361
CNY 7.237304
CNH 7.24022
COP 4237.5
CRC 507.357483
CUC 1
CUP 26.5
CVE 98.250394
CZK 22.179804
DJF 177.720393
DKK 6.632104
DOP 58.850393
DZD 133.028566
EGP 50.592208
ERN 15
ETB 132.903874
EUR 0.888604
FJD 2.269204
FKP 0.751086
GBP 0.751654
GEL 2.74504
GGP 0.751086
GHS 13.15039
GIP 0.751086
GMD 71.503851
GNF 8655.503848
GTQ 7.68865
GYD 209.738061
HKD 7.778675
HNL 25.840388
HRK 6.698104
HTG 130.545889
HUF 359.260388
IDR 16550.45
ILS 3.54625
IMP 0.751086
INR 85.42235
IQD 1310
IRR 42100.000352
ISK 130.610386
JEP 0.751086
JMD 158.892834
JOD 0.709304
JPY 145.377504
KES 129.503801
KGS 87.450384
KHR 4015.00035
KMF 436.503794
KPW 899.980663
KRW 1396.150383
KWD 0.306704
KYD 0.833015
KZT 515.881587
LAK 21610.000349
LBP 89600.000349
LKR 298.663609
LRD 199.503772
LSL 18.250381
LTL 2.95274
LVL 0.60489
LYD 5.435039
MAD 9.252504
MDL 17.132267
MGA 4465.000347
MKD 54.675907
MMK 2099.383718
MNT 3576.154424
MOP 8.008568
MRU 39.550379
MUR 45.710378
MVR 15.403739
MWK 1737.000345
MXN 19.43815
MYR 4.297039
MZN 63.903729
NAD 18.250377
NGN 1607.110377
NIO 36.475039
NOK 10.37227
NPR 136.497651
NZD 1.692119
OMR 0.384771
PAB 0.999604
PEN 3.641039
PGK 4.063039
PHP 55.367038
PKR 281.203701
PLN 3.76205
PYG 7991.751368
QAR 3.64075
RON 4.549804
RSD 104.183425
RUB 82.455285
RWF 1424
SAR 3.750833
SBD 8.343881
SCR 14.195211
SDG 600.503676
SEK 9.712185
SGD 1.298204
SHP 0.785843
SLE 22.750371
SLL 20969.483762
SOS 571.503662
SRD 36.702504
STD 20697.981008
SVC 8.746395
SYP 13001.597108
SZL 18.250369
THB 32.960369
TJS 10.345808
TMT 3.51
TND 3.01625
TOP 2.342104
TRY 38.771315
TTD 6.790839
TWD 30.261404
TZS 2697.503631
UAH 41.524787
UGX 3658.552845
UYU 41.785367
UZS 12885.000334
VES 92.71499
VND 25978.5
VUV 121.153995
WST 2.778453
XAF 583.049567
XAG 0.03055
XAU 0.0003
XCD 2.70255
XDR 0.718649
XOF 575.503595
XPF 106.450363
YER 244.450363
ZAR 18.19765
ZMK 9001.203587
ZMW 26.314503
ZWL 321.999592
  • NGG

    0.5100

    70.69

    +0.72%

  • RIO

    0.8000

    59.98

    +1.33%

  • CMSC

    -0.0500

    22.06

    -0.23%

  • SCS

    -0.0200

    10.46

    -0.19%

  • BCC

    -0.9600

    88.62

    -1.08%

  • BCE

    0.4800

    22.71

    +2.11%

  • CMSD

    0.0100

    22.34

    +0.04%

  • RBGPF

    65.2700

    65.27

    +100%

  • RYCEF

    0.0500

    10.55

    +0.47%

  • BTI

    -1.6600

    41.64

    -3.99%

  • JRI

    0.0300

    12.98

    +0.23%

  • VOD

    0.0500

    9.3

    +0.54%

  • BP

    1.1800

    29.77

    +3.96%

  • GSK

    -0.2500

    36.62

    -0.68%

  • RELX

    0.3486

    53.85

    +0.65%

  • AZN

    0.2700

    67.57

    +0.4%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: © AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

A.Kwok--ThChM