Dubai Telegraph - Repeat hacks highlight Australia's cyber flaws

EUR -
AED 4.304793
AFN 75.018807
ALL 95.472997
AMD 434.616987
ANG 2.098046
AOA 1076.050478
ARS 1632.265422
AUD 1.628611
AWG 2.109903
AZN 1.989654
BAM 1.957166
BBD 2.36138
BDT 143.854547
BGN 1.955296
BHD 0.44267
BIF 3488.373035
BMD 1.172168
BND 1.495565
BOB 8.101243
BRL 5.827085
BSD 1.172434
BTN 111.217456
BWP 15.933279
BYN 3.308478
BYR 22974.499827
BZD 2.357968
CAD 1.594033
CDF 2719.430131
CHF 0.917081
CLF 0.026797
CLP 1054.658072
CNY 8.003859
CNH 7.995624
COP 4286.912729
CRC 533.026705
CUC 1.172168
CUP 31.062462
CVE 110.711345
CZK 24.379989
DJF 208.317171
DKK 7.472643
DOP 69.748105
DZD 155.099004
EGP 62.634792
ERN 17.582525
ETB 184.030546
FJD 2.570624
FKP 0.863441
GBP 0.86414
GEL 3.141364
GGP 0.863441
GHS 13.132293
GIP 0.863441
GMD 85.56768
GNF 10285.777375
GTQ 8.957132
GYD 245.27903
HKD 9.182474
HNL 31.202937
HRK 7.535405
HTG 153.582948
HUF 363.073257
IDR 20379.319081
ILS 3.459479
IMP 0.863441
INR 111.329738
IQD 1535.54055
IRR 1540229.223365
ISK 143.801703
JEP 0.863441
JMD 183.708257
JOD 0.831038
JPY 183.968891
KES 151.439949
KGS 102.471545
KHR 4703.327197
KMF 492.310913
KPW 1054.951494
KRW 1722.472039
KWD 0.361075
KYD 0.977053
KZT 543.05168
LAK 25764.260233
LBP 104967.676802
LKR 374.708368
LRD 215.532467
LSL 19.528583
LTL 3.461108
LVL 0.709033
LYD 7.443066
MAD 10.844023
MDL 20.200568
MGA 4864.499069
MKD 61.645695
MMK 2460.9559
MNT 4193.843189
MOP 9.460391
MRU 46.851964
MUR 54.810523
MVR 18.11585
MWK 2041.331642
MXN 20.472976
MYR 4.633535
MZN 74.895763
NAD 19.528485
NGN 1611.110648
NIO 43.030716
NOK 10.857362
NPR 177.939374
NZD 1.985729
OMR 0.450692
PAB 1.172404
PEN 4.11138
PGK 5.085746
PHP 72.253624
PKR 326.771221
PLN 4.253594
PYG 7210.741673
QAR 4.270792
RON 5.198806
RSD 117.417331
RUB 87.914502
RWF 1713.124056
SAR 4.395608
SBD 9.426707
SCR 16.243007
SDG 703.88472
SEK 10.830606
SGD 1.493759
SHP 0.875142
SLE 28.835408
SLL 24579.7799
SOS 669.30821
SRD 43.907102
STD 24261.518423
STN 24.861691
SVC 10.259169
SYP 129.553886
SZL 19.528294
THB 38.116579
TJS 10.997075
TMT 4.10845
TND 3.377896
TOP 2.8223
TRY 52.981658
TTD 7.958303
TWD 37.048703
TZS 3059.359673
UAH 51.51602
UGX 4408.51035
USD 1.172168
UYU 46.757231
UZS 14007.411865
VES 573.123227
VND 30873.156311
VUV 137.907235
WST 3.182659
XAF 656.462918
XAG 0.015743
XAU 0.000256
XCD 3.167843
XCG 2.11301
XDR 0.815395
XOF 656.414482
XPF 119.331742
YER 279.67633
ZAR 19.48935
ZMK 10550.925377
ZMW 21.894874
ZWL 377.437733
  • RBGPF

    0.5000

    63.1

    +0.79%

  • CMSC

    0.0600

    22.88

    +0.26%

  • JRI

    -0.0100

    12.98

    -0.08%

  • RIO

    0.1000

    100.58

    +0.1%

  • GSK

    -0.7000

    51.61

    -1.36%

  • BCE

    0.1800

    23.96

    +0.75%

  • NGG

    -1.0600

    88.48

    -1.2%

  • BCC

    -1.1400

    78.13

    -1.46%

  • BTI

    -0.0900

    58.71

    -0.15%

  • RYCEF

    0.5500

    16.35

    +3.36%

  • RELX

    -0.2400

    36.35

    -0.66%

  • CMSD

    0.1500

    23.28

    +0.64%

  • BP

    -0.9700

    46.41

    -2.09%

  • AZN

    -2.6300

    184.74

    -1.42%

  • VOD

    0.3500

    16.15

    +2.17%

Repeat hacks highlight Australia's cyber flaws
Repeat hacks highlight Australia's cyber flaws / Photo: Muhammad FAROOQ - AFP

Repeat hacks highlight Australia's cyber flaws

Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.

Text size:

Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.

Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.

Both incidents sit comfortably among the largest data breaches in Australian history.

Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.

"There was a famous line for a while: Data is the new oil," he told AFP.

"If data is the new oil, then we're living the era of the weekly oil spill."

Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.

"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.

"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."

Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.

- Hacking 'for profit' -

Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.

"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."

Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.

Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.

"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.

"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."

The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.

The Optus breach led to the theft of customers' names, birth dates, and passport numbers.

- Russia blamed -

Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.

"We believe those responsible for the breach are in Russia," he told reporters.

"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."

Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.

Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.

University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.

"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.

"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."

I.El-Hammady--DT