Zürcher Nachrichten - Repeat hacks highlight Australia's cyber flaws

EUR -
AED 4.309328
AFN 75.686443
ALL 95.456633
AMD 432.519171
ANG 2.10026
AOA 1077.186483
ARS 1637.502559
AUD 1.6273
AWG 2.11213
AZN 1.994862
BAM 1.953628
BBD 2.367368
BDT 144.219672
BGN 1.95736
BHD 0.443929
BIF 3498.325843
BMD 1.173406
BND 1.488052
BOB 8.121971
BRL 5.804016
BSD 1.175393
BTN 110.787838
BWP 15.738309
BYN 3.321707
BYR 22998.748453
BZD 2.363972
CAD 1.602584
CDF 2717.606917
CHF 0.915467
CLF 0.026564
CLP 1045.469272
CNY 7.981328
CNH 7.985148
COP 4388.161205
CRC 539.228116
CUC 1.173406
CUP 31.095247
CVE 110.142555
CZK 24.308914
DJF 209.307315
DKK 7.472499
DOP 69.905861
DZD 154.98577
EGP 61.855722
ERN 17.601083
ETB 183.539445
FJD 2.568822
FKP 0.863007
GBP 0.865445
GEL 3.144651
GGP 0.863007
GHS 13.2233
GIP 0.863007
GMD 85.658792
GNF 10316.059203
GTQ 8.975023
GYD 245.916616
HKD 9.191198
HNL 31.224111
HRK 7.537016
HTG 153.949511
HUF 356.847858
IDR 20354.831106
ILS 3.404466
IMP 0.863007
INR 110.605789
IQD 1537.161249
IRR 1540564.124637
ISK 143.800686
JEP 0.863007
JMD 185.143644
JOD 0.831922
JPY 184.035757
KES 151.744974
KGS 102.579694
KHR 4714.778704
KMF 491.657324
KPW 1056.077778
KRW 1712.879072
KWD 0.361338
KYD 0.979511
KZT 544.334867
LAK 25794.324631
LBP 105257.585883
LKR 378.489236
LRD 215.690219
LSL 19.208025
LTL 3.464761
LVL 0.709781
LYD 7.434735
MAD 10.72786
MDL 20.222519
MGA 4880.823595
MKD 61.681812
MMK 2463.965572
MNT 4201.314278
MOP 9.48066
MRU 47.030122
MUR 54.82158
MVR 18.134946
MWK 2044.072648
MXN 20.279263
MYR 4.596187
MZN 74.977041
NAD 19.208459
NGN 1595.955879
NIO 43.069885
NOK 10.909092
NPR 177.269995
NZD 1.975017
OMR 0.451177
PAB 1.175393
PEN 4.05705
PGK 5.115575
PHP 71.114218
PKR 327.514152
PLN 4.2314
PYG 7194.002478
QAR 4.274695
RON 5.263664
RSD 117.401569
RUB 87.597326
RWF 1723.272367
SAR 4.429954
SBD 9.425096
SCR 16.401448
SDG 704.633198
SEK 10.883231
SGD 1.48904
SHP 0.876066
SLE 28.862889
SLL 24605.722832
SOS 670.599169
SRD 43.921728
STD 24287.125444
STN 24.474044
SVC 10.284567
SYP 129.717992
SZL 19.208208
THB 37.866319
TJS 10.984189
TMT 4.118653
TND 3.367093
TOP 2.825279
TRY 53.158433
TTD 7.951161
TWD 36.853263
TZS 3049.692885
UAH 51.471511
UGX 4396.112872
USD 1.173406
UYU 46.997753
UZS 14243.165973
VES 582.254457
VND 30872.299582
VUV 138.571802
WST 3.181704
XAF 655.262055
XAG 0.01479
XAU 0.000249
XCD 3.171187
XCG 2.118345
XDR 0.814936
XOF 655.228587
XPF 119.331742
YER 279.964716
ZAR 19.299467
ZMK 10562.055152
ZMW 22.391108
ZWL 377.836103
  • RBGPF

    0.0000

    63.18

    0%

  • NGG

    -1.9400

    85.91

    -2.26%

  • BTI

    -1.4800

    58.08

    -2.55%

  • AZN

    -2.4000

    182.52

    -1.31%

  • GSK

    -0.0300

    50.5

    -0.06%

  • BP

    -0.8200

    43.81

    -1.87%

  • BCE

    0.3400

    24.57

    +1.38%

  • CMSC

    -0.0400

    22.97

    -0.17%

  • RIO

    -2.4000

    103.11

    -2.33%

  • RYCEF

    -0.0500

    17.45

    -0.29%

  • CMSD

    0.0000

    23.42

    0%

  • JRI

    -0.0200

    13.15

    -0.15%

  • VOD

    -0.4400

    15.69

    -2.8%

  • BCC

    -1.4800

    72.76

    -2.03%

  • RELX

    -1.5900

    34.16

    -4.65%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: Muhammad FAROOQ - AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

L.Zimmermann--NZN