-
Yazidi woman tells French court of rape, slavery and escape from IS
-
New FIFA ruling boosts prospects for women coaches
-
Megan Jones to captain England in Women's Six Nations
-
Trump says told Netanyahu not to attack Iran gas fields
-
MLS reveals shortened 2027 campaign details
-
FIFA planning for World Cup to 'go ahead as scheduled' amid Iran uncertainty
-
Braves outfielder Profar's full MLB season ban upheld: report
-
Mideast war exposing Europe's reliance on Gulf flights, airlines warn
-
Ghalibaf: Iran's new strongman running war effort
-
UN shipping body urges 'safe maritime corridor' in Gulf
-
Venezuelan student freed after months in US immigration custody
-
Trump to Japan PM: 'Why didn't you tell me about Pearl Harbor?'
-
US mulls lifting sanctions on Iranian oil at sea despite war on Tehran
-
IMF raises concern over global inflation, output over Iran war
-
Middle East war weighs on global trade outlook: WTO
-
Cunningham out for NBA Pistons with collapsed lung
-
Belarus frees 250 political prisoners in US-brokered deal
-
Fernandez 'completely committed' to Chelsea insists Rosenior
-
Call to add Nazi camps to UNESCO list
-
England cricket chiefs to front up to media over Ashes flop
-
'Miracle': Europe reconnects with lost spacecraft
-
Nigeria 'challenged by terrorism', president says on UK state visit
-
Woltemade deployed too deep to be dangerous at Newcastle, says Nagelsmann
-
Wimbledon expansion plan gets legal boost
-
EU summit fails to rally Orban behind stalled Ukraine loan
-
New Morocco coach praises 'well-deserved' Cup of Nations decision
-
Senegal to appeal CAF Africa Cup of Nations decision
-
'Mixing things up': Nagelsmann goes for flexibility in new Germany squad
-
Record-setter Hodgkinson hopes 'fourth time lucky' at world indoors
-
European Central Bank warns of major hit from Mideast war
-
Atletico target Romero says his focus on Spurs' survival bid
-
Karalis hits prime form to threaten Duplantis surprise
-
Freshly returned Mbappe leads France squad for Brazil, Colombia friendlies
-
US earns its lowest-ever score on freedom index
-
Europe's super elite teach English clubs a Champions League lesson
-
What we know about the UK's deadly meningitis outbreak
-
Karl handed Germany debut as Musiala misses out with injury
-
What cargo ships are passing Hormuz strait?
-
Bank of England holds interest rate amid Middle East war
-
'Surreal' for F1 world champion Norris to have Tussauds waxwork
-
Iran hangs three men in first executions over January protests
-
North Korea, Philippines qualify for 2027 Women's World Cup
-
Man Utd boss Carrick expects hard test against resolute Bournemouth
-
Oil prices surge, stocks sink on energy shock fears
-
Alibaba pins hopes on AI as quarterly net profit drops
-
Oil soars 10% after Qatar energy sites hit in Mideast war
-
Iran 'boycotting' USA but not World Cup: football federation chief
-
Tokyo's dazzling cherry blossom season officially begins
-
Iran causes 'extensive' damage to Qatar gas hub, sparks Trump warning
-
Baby monkey Punch acclimatising, making new friends at Japan zoo
Repeat hacks highlight Australia's cyber flaws
Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.
Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.
Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.
Both incidents sit comfortably among the largest data breaches in Australian history.
Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.
"There was a famous line for a while: Data is the new oil," he told AFP.
"If data is the new oil, then we're living the era of the weekly oil spill."
Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.
"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.
"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."
Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.
- Hacking 'for profit' -
Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.
"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."
Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.
Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.
"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.
"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."
The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.
The Optus breach led to the theft of customers' names, birth dates, and passport numbers.
- Russia blamed -
Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.
"We believe those responsible for the breach are in Russia," he told reporters.
"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."
Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.
Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.
University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.
"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.
"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."
H.Seidel--BTB