The China Mail - Repeat hacks highlight Australia's cyber flaws

USD -
AED 3.672501
AFN 64.498808
ALL 81.039781
AMD 377.510312
ANG 1.79008
AOA 916.999994
ARS 1404.499139
AUD 1.404494
AWG 1.8
AZN 1.687314
BAM 1.642722
BBD 2.014547
BDT 122.351617
BGN 1.67937
BHD 0.377025
BIF 2955
BMD 1
BND 1.262741
BOB 6.911728
BRL 5.200898
BSD 1.000176
BTN 90.647035
BWP 13.104482
BYN 2.868926
BYR 19600
BZD 2.011608
CAD 1.35844
CDF 2225.000269
CHF 0.771425
CLF 0.021644
CLP 854.639905
CNY 6.91325
CNH 6.90663
COP 3671.28
CRC 494.712705
CUC 1
CUP 26.5
CVE 92.897402
CZK 20.43085
DJF 177.71998
DKK 6.2955
DOP 62.625003
DZD 129.582328
EGP 46.776799
ERN 15
ETB 155.050186
EUR 0.84264
FJD 2.18635
FKP 0.731875
GBP 0.73435
GEL 2.69028
GGP 0.731875
GHS 11.005005
GIP 0.731875
GMD 73.501046
GNF 8779.999882
GTQ 7.671019
GYD 209.257595
HKD 7.81621
HNL 26.505002
HRK 6.344696
HTG 131.086819
HUF 319.663499
IDR 16800.45
ILS 3.077095
IMP 0.731875
INR 90.73605
IQD 1310.5
IRR 42125.000158
ISK 122.359394
JEP 0.731875
JMD 156.494496
JOD 0.709003
JPY 153.421964
KES 128.999894
KGS 87.450398
KHR 4029.999687
KMF 414.999797
KPW 899.999067
KRW 1449.960032
KWD 0.30697
KYD 0.83354
KZT 493.505294
LAK 21445.000286
LBP 89733.661066
LKR 309.394121
LRD 186.550374
LSL 15.860192
LTL 2.95274
LVL 0.60489
LYD 6.288836
MAD 9.13875
MDL 16.898415
MGA 4430.000238
MKD 51.915295
MMK 2099.913606
MNT 3568.190929
MOP 8.053234
MRU 39.905058
MUR 45.679983
MVR 15.4599
MWK 1736.505582
MXN 17.206096
MYR 3.915502
MZN 63.8841
NAD 15.960196
NGN 1351.579862
NIO 36.714983
NOK 9.49152
NPR 145.034815
NZD 1.654135
OMR 0.384495
PAB 1.000181
PEN 3.354986
PGK 4.183501
PHP 58.284977
PKR 279.587483
PLN 3.552305
PYG 6605.156289
QAR 3.64125
RON 4.289598
RSD 98.889046
RUB 77.10069
RWF 1452.5
SAR 3.750395
SBD 8.048395
SCR 13.767722
SDG 601.502932
SEK 8.901904
SGD 1.262605
SHP 0.750259
SLE 24.249903
SLL 20969.499267
SOS 571.510487
SRD 37.77701
STD 20697.981008
STN 20.95
SVC 8.752
SYP 11059.574895
SZL 15.85973
THB 31.110186
TJS 9.391982
TMT 3.5
TND 2.83525
TOP 2.40776
TRY 43.637199
TTD 6.783192
TWD 31.350903
TZS 2590.154015
UAH 43.034895
UGX 3536.076803
UYU 38.350895
UZS 12300.000058
VES 388.253525
VND 26000
VUV 119.366255
WST 2.707053
XAF 550.953523
XAG 0.012153
XAU 0.000198
XCD 2.70255
XCG 1.802643
XDR 0.685659
XOF 549.506089
XPF 100.749968
YER 238.406014
ZAR 15.880545
ZMK 9001.202368
ZMW 19.029301
ZWL 321.999592
  • RBGPF

    0.1000

    82.5

    +0.12%

  • BCC

    -0.3200

    89.41

    -0.36%

  • JRI

    0.3500

    13.13

    +2.67%

  • GSK

    -0.3300

    58.49

    -0.56%

  • CMSC

    0.0084

    23.7

    +0.04%

  • NGG

    1.8800

    90.64

    +2.07%

  • AZN

    11.3600

    204.76

    +5.55%

  • BCE

    -0.1800

    25.65

    -0.7%

  • RELX

    -1.5600

    27.73

    -5.63%

  • RYCEF

    -0.4800

    16.93

    -2.84%

  • RIO

    2.2800

    99.52

    +2.29%

  • CMSD

    -0.0100

    24.07

    -0.04%

  • VOD

    0.4300

    15.68

    +2.74%

  • BP

    1.5800

    38.55

    +4.1%

  • BTI

    0.1400

    60.33

    +0.23%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: © AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

A.Kwok--ThChM