Zürcher Nachrichten - Repeat hacks highlight Australia's cyber flaws

EUR -
AED 3.823179
AFN 73.001105
ALL 98.504504
AMD 412.3757
ANG 1.872915
AOA 949.283166
ARS 1066.524452
AUD 1.673939
AWG 1.873585
AZN 1.764567
BAM 1.955294
BBD 2.098257
BDT 124.187856
BGN 1.957889
BHD 0.392027
BIF 3073.004603
BMD 1.040881
BND 1.412134
BOB 7.181141
BRL 6.404548
BSD 1.039231
BTN 88.460104
BWP 14.433264
BYN 3.40092
BYR 20401.259466
BZD 2.091159
CAD 1.499877
CDF 2987.32716
CHF 0.936293
CLF 0.037313
CLP 1029.576263
CNY 7.59749
CNH 7.601129
COP 4574.670171
CRC 527.663423
CUC 1.040881
CUP 27.583336
CVE 110.236467
CZK 25.124777
DJF 184.985207
DKK 7.459741
DOP 63.303615
DZD 140.537971
EGP 52.927321
ERN 15.613209
ETB 132.318751
FJD 2.413438
FKP 0.824359
GBP 0.83133
GEL 2.925032
GGP 0.824359
GHS 15.276046
GIP 0.824359
GMD 74.943506
GNF 8981.675239
GTQ 8.004928
GYD 217.423723
HKD 8.080684
HNL 26.404166
HRK 7.466139
HTG 135.884828
HUF 411.358061
IDR 16902.131203
ILS 3.810898
IMP 0.824359
INR 88.820682
IQD 1361.347637
IRR 43808.063934
ISK 145.10928
JEP 0.824359
JMD 161.91809
JOD 0.738298
JPY 164.081297
KES 134.315001
KGS 90.556982
KHR 4176.918872
KMF 485.180442
KPW 936.791944
KRW 1541.762475
KWD 0.320778
KYD 0.866076
KZT 538.370652
LAK 22727.117455
LBP 93062.01241
LKR 306.280724
LRD 189.141044
LSL 19.323598
LTL 3.07345
LVL 0.629618
LYD 5.10168
MAD 10.479987
MDL 19.174037
MGA 4901.731267
MKD 61.498447
MMK 3380.739538
MNT 3536.912092
MOP 8.313648
MRU 41.485262
MUR 48.994142
MVR 16.042942
MWK 1802.033573
MXN 21.059299
MYR 4.661582
MZN 66.516151
NAD 19.323598
NGN 1610.065038
NIO 38.240102
NOK 11.87639
NPR 141.536366
NZD 1.851357
OMR 0.400157
PAB 1.039231
PEN 3.869798
PGK 4.217908
PHP 60.22483
PKR 289.318415
PLN 4.265264
PYG 8104.902178
QAR 3.779622
RON 4.97593
RSD 116.945384
RUB 103.979056
RWF 1449.724762
SAR 3.907467
SBD 8.72628
SCR 14.839859
SDG 626.084302
SEK 11.515892
SGD 1.415931
SHP 0.824359
SLE 23.730894
SLL 21826.748579
SOS 593.946267
SRD 36.491208
STD 21544.126579
SVC 9.093646
SYP 2615.243949
SZL 19.331996
THB 35.567959
TJS 11.369057
TMT 3.653491
TND 3.313642
TOP 2.437843
TRY 36.679575
TTD 7.062172
TWD 34.078272
TZS 2520.147815
UAH 43.574521
UGX 3804.015392
USD 1.040881
UYU 46.258027
UZS 13416.52735
VES 53.814387
VND 26474.797679
VUV 123.575428
WST 2.875732
XAF 655.78726
XAG 0.034862
XAU 0.000395
XCD 2.813032
XDR 0.796794
XOF 655.78726
XPF 119.331742
YER 260.610446
ZAR 19.638138
ZMK 9369.173148
ZMW 28.760556
ZWL 335.163124
  • NGG

    0.0600

    58.92

    +0.1%

  • SCS

    0.1700

    11.9

    +1.43%

  • BCC

    -0.2600

    122.93

    -0.21%

  • JRI

    0.0500

    12.2

    +0.41%

  • CMSC

    -0.1100

    23.66

    -0.46%

  • GSK

    0.0900

    34.12

    +0.26%

  • RIO

    0.0500

    59.25

    +0.08%

  • CMSD

    -0.1740

    23.476

    -0.74%

  • RBGPF

    59.8000

    59.8

    +100%

  • BP

    0.0600

    28.85

    +0.21%

  • BTI

    0.1700

    36.43

    +0.47%

  • RELX

    -0.0300

    45.86

    -0.07%

  • BCE

    -0.0300

    22.87

    -0.13%

  • VOD

    -0.0100

    8.42

    -0.12%

  • RYCEF

    0.0200

    7.27

    +0.28%

  • AZN

    0.2200

    66.52

    +0.33%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: Muhammad FAROOQ - AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

L.Zimmermann--NZN