The Prague Post - Repeat hacks highlight Australia's cyber flaws

EUR -
AED 4.255446
AFN 80.51328
ALL 96.968767
AMD 444.625883
ANG 2.0735
AOA 1062.412792
ARS 1499.234134
AUD 1.77876
AWG 2.08833
AZN 1.967852
BAM 1.944687
BBD 2.340505
BDT 142.005266
BGN 1.952493
BHD 0.436668
BIF 3409.105275
BMD 1.158574
BND 1.489207
BOB 8.038303
BRL 6.489155
BSD 1.159191
BTN 100.399908
BWP 15.625228
BYN 3.793246
BYR 22708.058928
BZD 2.328324
CAD 1.590891
CDF 3347.121128
CHF 0.930764
CLF 0.028313
CLP 1110.713974
CNY 8.316074
CNH 8.321692
COP 4836.862895
CRC 585.503658
CUC 1.158574
CUP 30.702223
CVE 109.079329
CZK 24.586149
DJF 205.901728
DKK 7.462836
DOP 70.383463
DZD 150.476918
EGP 56.525606
ERN 17.378617
ETB 161.241492
FJD 2.611195
FKP 0.857326
GBP 0.867651
GEL 3.139791
GGP 0.857326
GHS 12.107415
GIP 0.857326
GMD 83.417541
GNF 10028.620163
GTQ 8.896395
GYD 242.501225
HKD 9.094804
HNL 30.354542
HRK 7.530849
HTG 151.642329
HUF 397.286616
IDR 19004.096459
ILS 3.88152
IMP 0.857326
INR 100.568314
IQD 1517.73251
IRR 48790.463504
ISK 142.191591
JEP 0.857326
JMD 185.949017
JOD 0.821454
JPY 172.102761
KES 149.98914
KGS 101.143963
KHR 4657.469046
KMF 491.812747
KPW 1042.716996
KRW 1610.059448
KWD 0.353886
KYD 0.965889
KZT 630.192589
LAK 24990.451023
LBP 103750.340804
LKR 349.930153
LRD 232.873348
LSL 20.749852
LTL 3.420969
LVL 0.70081
LYD 6.267525
MAD 10.414136
MDL 19.53054
MGA 5150.191863
MKD 61.21022
MMK 2432.516656
MNT 4156.677842
MOP 9.372237
MRU 46.134608
MUR 52.587735
MVR 17.842133
MWK 2011.866728
MXN 21.741785
MYR 4.901956
MZN 74.102527
NAD 20.750429
NGN 1772.201441
NIO 42.656245
NOK 11.822267
NPR 160.640251
NZD 1.941654
OMR 0.445454
PAB 1.159067
PEN 4.108557
PGK 4.877172
PHP 66.265241
PKR 328.282923
PLN 4.261918
PYG 8682.385324
QAR 4.21808
RON 5.071889
RSD 117.120165
RUB 94.250492
RWF 1676.077545
SAR 4.345997
SBD 9.598899
SCR 16.989088
SDG 695.720595
SEK 11.143928
SGD 1.491253
SHP 0.910458
SLE 26.588958
SLL 24294.73119
SOS 662.116779
SRD 42.35781
STD 23980.151654
STN 24.360688
SVC 10.143039
SYP 15063.555065
SZL 20.750123
THB 37.577633
TJS 11.040358
TMT 4.066596
TND 3.397456
TOP 2.713501
TRY 46.995485
TTD 7.882379
TWD 34.349994
TZS 2977.536016
UAH 48.482072
UGX 4155.219523
USD 1.158574
UYU 46.457331
UZS 14585.345808
VES 139.345685
VND 30354.6502
VUV 137.404105
WST 3.173318
XAF 652.168326
XAG 0.030448
XAU 0.00035
XCD 3.131106
XCG 2.089009
XDR 0.803367
XOF 652.269079
XPF 119.331742
YER 279.158667
ZAR 20.74425
ZMK 10428.561218
ZMW 27.180101
ZWL 373.060495
  • BCC

    -0.9100

    87.23

    -1.04%

  • SCU

    0.0000

    12.72

    0%

  • RIO

    -1.0100

    62.09

    -1.63%

  • JRI

    -0.0750

    13.015

    -0.58%

  • BCE

    -0.2800

    23.92

    -1.17%

  • NGG

    -1.9200

    70.23

    -2.73%

  • CMSD

    0.0130

    22.903

    +0.06%

  • RBGPF

    0.0000

    75

    0%

  • CMSC

    0.0050

    22.49

    +0.02%

  • GSK

    -0.5350

    37.435

    -1.43%

  • AZN

    -0.8900

    71.77

    -1.24%

  • SCS

    0.2350

    10.815

    +2.17%

  • RYCEF

    0.0500

    13.2

    +0.38%

  • BTI

    -0.6850

    51.565

    -1.33%

  • BP

    0.2900

    32.49

    +0.89%

  • VOD

    -0.2950

    11.135

    -2.65%

  • RELX

    -0.9200

    51.81

    -1.78%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: Muhammad FAROOQ - AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

C.Zeman--TPP