Zürcher Nachrichten - Repeat hacks highlight Australia's cyber flaws

EUR -
AED 4.353382
AFN 77.05154
ALL 96.6659
AMD 452.980789
ANG 2.12196
AOA 1087.011649
ARS 1715.27374
AUD 1.700138
AWG 2.136683
AZN 2.016962
BAM 1.955717
BBD 2.406598
BDT 146.013807
BGN 1.990725
BHD 0.449081
BIF 3539.949869
BMD 1.1854
BND 1.513236
BOB 8.25665
BRL 6.231058
BSD 1.194849
BTN 109.725346
BWP 15.634337
BYN 3.403256
BYR 23233.834642
BZD 2.403098
CAD 1.611918
CDF 2684.930667
CHF 0.911329
CLF 0.026011
CLP 1027.065402
CNY 8.240602
CNH 8.248669
COP 4350.11551
CRC 591.674907
CUC 1.1854
CUP 31.413093
CVE 110.260324
CZK 24.336607
DJF 212.770976
DKK 7.470147
DOP 75.22681
DZD 154.464449
EGP 55.903629
ERN 17.780996
ETB 185.616528
FJD 2.613392
FKP 0.865856
GBP 0.861451
GEL 3.194656
GGP 0.865856
GHS 13.089445
GIP 0.865856
GMD 86.534664
GNF 10484.555345
GTQ 9.164611
GYD 249.979398
HKD 9.259098
HNL 31.537662
HRK 7.536653
HTG 156.373368
HUF 380.868342
IDR 19883.302315
ILS 3.66336
IMP 0.865856
INR 108.694634
IQD 1565.333613
IRR 49934.963672
ISK 144.986215
JEP 0.865856
JMD 187.242059
JOD 0.840447
JPY 183.458423
KES 154.263458
KGS 103.663312
KHR 4804.796226
KMF 491.940791
KPW 1066.859756
KRW 1719.772596
KWD 0.363823
KYD 0.995758
KZT 600.944514
LAK 25713.909461
LBP 106999.862086
LKR 369.514329
LRD 215.370866
LSL 18.971995
LTL 3.500177
LVL 0.717036
LYD 7.497682
MAD 10.83854
MDL 20.097148
MGA 5339.773538
MKD 61.637386
MMK 2489.728817
MNT 4227.587506
MOP 9.608592
MRU 47.674978
MUR 53.852825
MVR 18.326127
MWK 2071.912129
MXN 20.704153
MYR 4.672852
MZN 75.580739
NAD 18.971995
NGN 1643.533583
NIO 43.968135
NOK 11.414558
NPR 175.560554
NZD 1.959292
OMR 0.458021
PAB 1.194849
PEN 3.994931
PGK 5.114783
PHP 69.837845
PKR 334.292423
PLN 4.212869
PYG 8003.660561
QAR 4.356415
RON 5.097103
RSD 117.395021
RUB 90.53616
RWF 1743.326065
SAR 4.447253
SBD 9.54438
SCR 17.20327
SDG 713.019239
SEK 10.549127
SGD 1.506168
SHP 0.889357
SLE 28.834855
SLL 24857.238699
SOS 682.871039
SRD 45.10505
STD 24535.381029
STN 24.498961
SVC 10.454557
SYP 13110.017057
SZL 18.966196
THB 37.222281
TJS 11.154027
TMT 4.148899
TND 3.433054
TOP 2.854158
TRY 51.401896
TTD 8.112656
TWD 37.456216
TZS 3076.769513
UAH 51.211828
UGX 4271.81883
USD 1.1854
UYU 46.368034
UZS 14607.380494
VES 410.078852
VND 30749.268909
VUV 140.815358
WST 3.213359
XAF 655.929182
XAG 0.014004
XAU 0.000244
XCD 3.203602
XCG 2.153409
XDR 0.815765
XOF 655.929182
XPF 119.331742
YER 282.51038
ZAR 19.104199
ZMK 10670.019447
ZMW 23.449006
ZWL 381.698228
  • SCS

    0.0200

    16.14

    +0.12%

  • RBGPF

    1.3800

    83.78

    +1.65%

  • CMSD

    -0.0400

    24.05

    -0.17%

  • CMSC

    0.0500

    23.76

    +0.21%

  • RYCEF

    -0.4300

    16

    -2.69%

  • BTI

    0.4600

    60.68

    +0.76%

  • NGG

    0.2000

    85.27

    +0.23%

  • BP

    -0.1600

    37.88

    -0.42%

  • GSK

    0.9400

    51.6

    +1.82%

  • BCE

    0.3700

    25.86

    +1.43%

  • VOD

    -0.0600

    14.65

    -0.41%

  • RIO

    -4.1000

    91.03

    -4.5%

  • BCC

    0.5100

    80.81

    +0.63%

  • RELX

    -0.3700

    35.8

    -1.03%

  • AZN

    0.1800

    92.77

    +0.19%

  • JRI

    0.1400

    13.08

    +1.07%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: Muhammad FAROOQ - AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

L.Zimmermann--NZN