APRA’s BEAR Case Against Bendigo: An $8m Cyber Accountability Test
Bendigo and Adelaide Bank has admitted it breached its accountability obligations under the Banking Executive Accountability Regime (BEAR), and on 10 August 2026 the Australian Prudential Regulation Authority (APRA) filed civil penalty proceedings against it in the Federal Court. The parties have jointly proposed that the bank pay an $8 million pecuniary penalty, subject to the Court’s approval. All amounts here are in Australian dollars.
The trigger was a cyber attack on the bank’s Alliance Bank business between 3 and 7 March 2023. APRA states that an unidentified attacker reached about 257 customer accounts and made 286 unauthorised transactions worth roughly $490,000, affecting 87 Alliance Bank customers. The Statement of Agreed Facts separately itemises 66 unauthorised transfers and 154 payments, which does not arithmetically reconcile to the stated total of 286. Bendigo reimbursed every affected customer and could not recover about $140,000. APRA’s case turns on the controls and the accountability records behind the attack; penetration testing procured by Bendigo had identified some of the control weaknesses as far back as 2020.
For reporting and risk teams inside any authorised deposit-taking institution (ADI), the interest is in how APRA framed the failure. APRA pleaded two entity-level contraventions of the Banking Act 1959: a failure to run the business with due skill, care and diligence, and a gap in who was formally accountable for a live IT system.
Related reading: our guide to APRA and ASIC’s FAR rule changes
The timeline that frames the case
Enforcement actions read more clearly against a calendar. These dates come from APRA’s originating application and the Statement of Agreed Facts and Admissions, both dated 10 August 2026.
- 2 June 2020 to 1 July 2023: the relevant period covered by the admissions.
- On or about 2 June 2020: CQR provides Bendigo’s Information Security team with its report on penetration testing of the Service One Ultracs instance, identifying customer-authentication weaknesses; the findings are not adequately escalated and remain unremediated before the March 2023 attack.
- 30 September 2020: Bendigo’s CPS 234 Controls Testing Framework is in force for the group, including Alliance Bank.
- 3 to 7 March 2023: the cyber attack on Alliance Bank digital access; the unrecovered $140,110 was repaid by Bendigo on or about 11 March 2023.
- 29 August 2022 to 30 August 2023: the window in which no accountable person’s statement covered Alliance Bank IT operations.
- 10 August 2026: APRA commences Federal Court proceedings; $8 million penalty proposed for the Court’s decision.
What Bendigo admitted under BEAR
APRA brought the case under sections 37C(a) and 37D(1)(a)(i) of the Banking Act 1959, using its civil penalty power in section 37G and Schedule 2. Section 37C(a) requires an ADI to take reasonable steps to conduct its business with honesty and integrity and with due skill, care and diligence. Bendigo admitted it contravened that obligation between 2 June 2020 and June 2023 by not having adequate customer authentication controls for Alliance Bank, no systematic testing program for those controls once its CPS 234 framework was in force, and inadequate governance for the information security of the Ultracs core banking system and the hosting services behind it.
The second contravention warrants particular attention. At the time, section 37D(1)(a)(i) required Bendigo, subject to the statutory exceptions, to ensure that the responsibilities of the accountable persons of Bendigo and its subsidiaries covered all parts or aspects of the operations of the relevant group. From 29 August 2022, the Chief Transformation Officer’s accountability statement added a limitations-and-exclusions section that carved out IT operations for Alliance Bank. That responsibility was never reallocated to another accountable person. For roughly a year, no one held it on paper. Bendigo admitted that Alliance Bank IT operations were part of its operations within the meaning of the section, and that the coverage gap was itself the breach.
The proceedings run against the entity, not against named individuals. APRA is seeking declarations and a pecuniary penalty against Bendigo and Adelaide Bank Limited as the ADI, and the Court will decide whether the declarations and the proposed $8 million are appropriate.
CPS 234 and the testing that did not close the loop
The admitted failure in this case sits earlier than the breach, in the testing and escalation that should have removed the weakness before an attacker found it. Prudential Standard CPS 234 Information Security commenced on 1 July 2019, subject to its transitional rule for information assets managed by third parties. APRA also approved a Bendigo-specific adjustment extending the date by which CPS 234 applied to third-party-managed information assets to 1 January 2021. The standard requires an APRA-regulated entity to implement controls for its information assets and systematically test their effectiveness. Bendigo had a CPS 234 Controls Testing Framework. A June 2020 penetration test of the Service One Ultracs instance identified weak password controls and customer-number enumeration; the agreed facts separately record widespread use of identical simple passwords.
The agreed facts say the 2020 findings were not adequately escalated and remained unremediated before the March 2023 attack. Bendigo also admitted that, from 30 September 2020, while its CPS 234 Controls Testing Framework was in force, it did not have a systematic testing program for Alliance Bank customer-authentication controls; APRA pleaded that omission as part of the section 37C(a) due-skill-care-and-diligence contravention. CPS 234 also carried notification duties. The agreed facts state that Bendigo complied with paragraph 35 by notifying APRA of the attack on 8 March 2023; they also record that Bendigo notified APRA of a material control weakness under paragraph 36 on 24 March 2023. This is the same control-and-test spine European teams will recognise from DORA resilience testing, where Article 24 requires identified testing weaknesses, deficiencies and gaps to be addressed through remediation; DORA’s TLPT process also includes supervisory documentation and an authority-issued attestation.
A BEAR case resolved after FAR took over
FAR replaced BEAR as the ongoing accountability regime for ADIs on 15 March 2024, subject to statutory savings and transitional provisions. FAR commenced for insurance entities, their licensed NOHCs and superannuation trustees from 15 March 2025. FAR is jointly administered by APRA and the Australian Securities and Investments Commission, where BEAR sat with APRA alone.
The change of regime does not erase historical exposure. Bendigo’s admitted conduct happened while BEAR was the law, so APRA pleaded the BEAR provisions in force at the time. FAR retains corresponding accountability and key-personnel concepts, but APRA and ASIC expressly state that BEAR and FAR obligations are not identical; FAR also expands the regime, including through conduct-related responsibilities. Firms that treated the FAR commencement as a clean slate should read this case as a reminder that conduct is judged against the rules in force when it occurred. Comparable UK documentation requirements are not identical: firms within SUP 10C maintain current Statements of Responsibilities for their SMF managers, while the FCA’s management-responsibilities-map requirements under SYSC 25 apply to SMCR banking firms; SMCR insurance firms that are Solvency II firms, including large non-directive insurers, but excluding insurance special purpose vehicles and the firms in run-off specified in SYSC 23 Annex 1 5.2R; and enhanced-scope SMCR firms.
The accountability-map question for FAR entities
The operational lesson sits in the accountability map. The failure APRA singled out was administrative: an exclusion was written into one executive’s statement and never picked up by anyone else. Outsourcing the system or running it for authorised representatives did not move the accountability off the ADI. Ultracs was licensed from a vendor and hosted by a third party, and Alliance Bank was a network of five authorised representatives operating under Bendigo’s ADI licence. None of that removed Bendigo’s obligation to ensure that accountable-person responsibilities collectively covered Alliance Bank IT operations, while Bendigo remained responsible for the information security controls over its information assets.
My read is that the highest-value check is a responsibility-coverage reconciliation. For an enhanced FAR entity, reconcile material IT responsibilities against current accountability statements and the accountability map; for a core FAR entity, use its internal accountability documentation, because FAR does not require core entities to submit accountability statements or maps. Then read the limitations-and-exclusions sections specifically: an exclusion in one statement is only safe if the same responsibility is expressly picked up in another. A review that checks whether each statement looks complete on its own will miss this, because the gap lives between statements. Both APRA and AUSTRAC now pursue pecuniary penalties through the Federal Court, as AUSTRAC’s Federal Court penalties show on the AML side, so the record needs to stand up as evidence in court.
Frequently Asked Questions
Does the move to FAR mean BEAR breaches can no longer be pursued?
No. Schedule 2, item 18 of the Financial Accountability Regime (Consequential Amendments) Act 2023 preserves the former Banking Act provisions for a BEAR contravention or alleged contravention that occurred before the banking start time. APRA therefore pleaded this proceeding under the BEAR provisions applicable to Bendigo’s historical conduct.
Is the $8 million penalty final?
Not yet. The parties jointly proposed that figure, but the Federal Court decides whether to make the declarations and impose a penalty, and at what amount. Agreed penalties in Australian civil penalty proceedings are proposals the Court can accept, adjust or reject.
Were individual accountable persons named or penalised?
The proceedings are against Bendigo and Adelaide Bank Limited as the ADI, for entity-level contraventions of sections 37C(a) and 37D(1)(a)(i). The accountability-statement failure concerns whether responsibility was allocated at all, rather than an enforcement action against a specific individual in this proceeding.
Does CPS 234 reach a system run by a third-party provider?
Yes. CPS 234 applies to information assets managed by third parties, and the case concerned a core banking system licensed from a vendor and hosted by an external provider. Using a third party does not transfer the standard’s obligations away from the regulated entity.
Related Articles
- APRA and ASIC FAR Rule Changes: how the Financial Accountability Regime works and where the accountability and administrative obligations now sit.
- SM&CR Reforms 2026: the UK individual-accountability regime and how responsibility maps are used as supervisory evidence.
- DORA ICT Incident Reporting: the EU rules on classifying and reporting major ICT-related incidents for financial entities.
- DORA Resilience Testing for Smaller Firms: how the EU testing programme applies with proportionality across entity types.
- AUSTRAC Federal Court Penalties: the AML enforcement trend toward court-ordered pecuniary penalties in Australia.
Key Takeaways
- APRA pleaded two entity-level contraventions of the Banking Act 1959, sections 37C(a) and 37D(1)(a)(i), treating a controls-and-accountability failure as a breach in its own right; an $8 million penalty is proposed for the Court’s decision.
- The accountability failure was a coverage gap: Alliance Bank IT operations were excluded from the Chief Transformation Officer’s statement and were not allocated to any other accountable person’s statement from 29 August 2022 to 30 August 2023.
- Reconcile material IT responsibilities across the appropriate FAR accountability artefacts: accountability statements and the map for enhanced entities, or internal accountability documentation for core entities; check that exclusions do not create coverage gaps.
- CPS 234 requires systematic testing that feeds remediation; penetration-test findings from 2020 that were not escalated sit at the centre of the skill-care-diligence contravention.
- FAR replaced BEAR for ADIs on 15 March 2024 and reached insurance entities, their licensed NOHCs and superannuation trustees from 15 March 2025, but conduct is judged against the regime in force when it occurred.
- A third-party or hosted system does not move CPS 234 or accountability obligations off the regulated ADI.
Sources and References
- APRA media release: Bendigo and Adelaide Bank admits to breaching its BEAR obligations in relation to cyber incident (11 August 2026)
- APRA v Bendigo and Adelaide Bank Limited: Originating Application, Federal Court of Australia (10 August 2026)
- Statement of Agreed Facts and Admissions (10 August 2026)
- Banking Act 1959 (Cth), sections 37C, 37D, 37G and Schedule 2 (the BEAR provisions)
- Financial Accountability Regime (Consequential Amendments) Act 2023 (Cth), Schedule 2, item 18 (savings provision for BEAR contraventions)
- APRA Prudential Standard CPS 234 Information Security
- APRA: Financial Accountability Regime (FAR)
- APRA: Banking Executive Accountability Regime (BEAR)
What to check before the next penetration test lands
The Federal Court will decide whether the $8 million penalty stands, and the accountability-map and testing evidence a bank would need in that position is the evidence it should be able to produce today.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
