The Prague Post - Repeat hacks highlight Australia's cyber flaws

EUR -
AED 4.248508
AFN 76.922753
ALL 96.695331
AMD 444.540616
ANG 2.071219
AOA 1060.827406
ARS 1644.462784
AUD 1.762047
AWG 2.085214
AZN 1.963953
BAM 1.955099
BBD 2.339261
BDT 141.449285
BGN 1.955178
BHD 0.436117
BIF 3422.287775
BMD 1.156845
BND 1.504667
BOB 8.026122
BRL 6.222208
BSD 1.161484
BTN 103.079042
BWP 15.430468
BYN 3.948484
BYR 22674.166472
BZD 2.335962
CAD 1.621544
CDF 2767.752365
CHF 0.93236
CLF 0.028021
CLP 1099.257196
CNY 8.246569
CNH 8.247682
COP 4512.81853
CRC 584.492964
CUC 1.156845
CUP 30.656399
CVE 110.22548
CZK 24.366653
DJF 206.825845
DKK 7.466823
DOP 73.043811
DZD 150.587707
EGP 55.020834
ERN 17.352678
ETB 170.263954
FJD 2.622163
FKP 0.863941
GBP 0.869566
GEL 3.146878
GGP 0.863941
GHS 14.285878
GIP 0.863941
GMD 83.292673
GNF 10073.43184
GTQ 8.899809
GYD 242.992878
HKD 9.001343
HNL 30.481071
HRK 7.532452
HTG 151.976824
HUF 390.988814
IDR 19195.070133
ILS 3.770986
IMP 0.863941
INR 102.616915
IQD 1521.554466
IRR 48659.802176
ISK 141.609598
JEP 0.863941
JMD 186.95297
JOD 0.820223
JPY 176.867786
KES 150.297486
KGS 101.162758
KHR 4664.367971
KMF 490.502189
KPW 1041.1725
KRW 1643.952241
KWD 0.355117
KYD 0.967853
KZT 628.644608
LAK 25192.967389
LBP 104008.609066
LKR 351.573948
LRD 211.964003
LSL 19.861379
LTL 3.415864
LVL 0.699764
LYD 6.316735
MAD 10.604598
MDL 19.692939
MGA 5198.136276
MKD 61.585466
MMK 2428.754355
MNT 4160.92851
MOP 9.308063
MRU 46.21463
MUR 52.643659
MVR 17.703198
MWK 2013.777986
MXN 21.270271
MYR 4.885329
MZN 73.864752
NAD 19.861379
NGN 1709.46136
NIO 42.744859
NOK 11.653538
NPR 164.926868
NZD 2.0111
OMR 0.444812
PAB 1.161484
PEN 4.000866
PGK 4.876273
PHP 67.388569
PKR 328.983147
PLN 4.255557
PYG 8127.086139
QAR 4.245178
RON 5.095095
RSD 117.174593
RUB 93.902896
RWF 1685.295759
SAR 4.338944
SBD 9.569143
SCR 17.186112
SDG 695.842953
SEK 11.0268
SGD 1.502083
SHP 0.909099
SLE 26.856169
SLL 24258.470252
SOS 663.762017
SRD 44.39799
STD 23944.360562
STN 24.491325
SVC 10.162356
SYP 15041.388843
SZL 19.856881
THB 37.920812
TJS 10.819021
TMT 4.060527
TND 3.414776
TOP 2.709448
TRY 48.383484
TTD 7.881174
TWD 35.378414
TZS 2834.270545
UAH 48.22381
UGX 3989.569592
USD 1.156845
UYU 46.373373
UZS 14020.972962
VES 218.658585
VND 30482.871763
VUV 140.343424
WST 3.217049
XAF 655.721899
XAG 0.023229
XAU 0.000291
XCD 3.126432
XCG 2.093249
XDR 0.815508
XOF 655.721899
XPF 119.331742
YER 276.485624
ZAR 19.888471
ZMK 10412.99508
ZMW 26.568474
ZWL 372.503691
  • RBGPF

    -0.1800

    75.55

    -0.24%

  • RYCEF

    -0.0600

    15.35

    -0.39%

  • CMSC

    -0.0200

    23.69

    -0.08%

  • RELX

    -0.6900

    45.15

    -1.53%

  • BTI

    -0.2400

    51.36

    -0.47%

  • AZN

    -0.3400

    85.04

    -0.4%

  • GSK

    0.0900

    43.44

    +0.21%

  • NGG

    -0.2800

    73.33

    -0.38%

  • VOD

    0.0100

    11.28

    +0.09%

  • RIO

    -0.7000

    67

    -1.04%

  • SCS

    -0.2600

    16.53

    -1.57%

  • BCC

    -2.5300

    73.89

    -3.42%

  • CMSD

    -0.0600

    24.27

    -0.25%

  • JRI

    -0.1100

    14.01

    -0.79%

  • BP

    -0.2300

    34.29

    -0.67%

  • BCE

    0.2100

    23.44

    +0.9%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: Muhammad FAROOQ - AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

C.Zeman--TPP