-
Spain's exiled king recounts history, scandals in wistful memoir
-
Wall Street stocks steady after positive jobs data
-
Trump blasts Democrats as government shutdown becomes longest ever
-
Indian pilgrims find 'warm welcome' in Pakistan despite tensions
-
Inter and AC Milan complete purchase of San Siro
-
Swedish authorities inspect worksite conditions at steel startup Stegra
-
Keys withdraws from WTA Finals with illness
-
Prince Harry says proud to be British despite new life in US
-
EU strikes last-ditch deal on climate targets as COP30 looms
-
Stocks retreat as tech bubble fears grow
-
Shein opens first permanent store amid heavy police presence
-
West Indies edge New Zealand despite Santner brilliance
-
French pair released by Iran await return home
-
German factory orders up but outlook still muted
-
Death toll tops 100 as Philippines digs out after typhoon
-
Attack on key city in Sudan's Kordofan region kills 40: UN
-
'No one could stop it': Sudanese describe mass rapes while fleeing El-Fasher
-
Champagne and cheers across New York as Mamdani soars to victory
-
Medieval tower collapse adds to Italy's workplace toll
-
BMW boosts profitability despite China, tariff woes
-
South Africa's Wiese wary of 'hurt' France before re-match
-
Beyond limits: Croatian freediver's breathtaking record
-
Tottenham supporting Udogie after alleged gun threat in London
-
Thunder roll Clippers to stay unbeaten as SGA keeps streak alive
-
In appeal, Australian mushroom murderer alleges 'miscarriage of justice'
-
Toyota hikes profit forecasts 'despite US tariffs'
-
Ex-France lock Willemse challenges Meafou to become 'the bully'
-
Ukrainians to honour sporting dead by building country they 'died for': minister
-
At least 7 dead after UPS cargo plane crashes near Louisville airport
-
US Supreme Court hears challenge to Trump tariff powers
-
US government shutdown becomes longest in history
-
India's Modi readies bellwether poll in poorest state
-
Green goals versus growth needs: India's climate scorecard
-
Where things stand on China-US trade after Trump and Xi talk
-
Sri Lanka targets big fish in anti-corruption push
-
NY elects leftist mayor on big election night for Democrats
-
Injured Jordie Barrett to miss rest of All Blacks tour
-
Asian markets tumble as tech bubble fears grow
-
Pay to protect: Brazil pitches new forest fund at COP30
-
Iraq's social media mercenaries dying for Russia
-
Young leftist Trump foe elected New York mayor
-
Concerns at ILO over expected appointment of close Trump advisor
-
Venus Williams to return to Auckland Classic at the age of 45
-
No deal yet on EU climate targets as COP30 looms
-
Typhoon death toll climbs to 66 in the Philippines
-
NATO tests war preparedness on eastern flank facing Russia
-
Uncapped opener Weatherald in Australia squad for first Ashes Test
-
Liverpool down Real Madrid in Champions League, Bayern edge PSG
-
Van Dijk tells Liverpool to keep calm and follow Arsenal's lead
-
PSG left to sweat on injuries to Dembele and Hakimi
Repeat hacks highlight Australia's cyber flaws
Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.
Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.
Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.
Both incidents sit comfortably among the largest data breaches in Australian history.
Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.
"There was a famous line for a while: Data is the new oil," he told AFP.
"If data is the new oil, then we're living the era of the weekly oil spill."
Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.
"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.
"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."
Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.
- Hacking 'for profit' -
Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.
"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."
Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.
Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.
"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.
"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."
The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.
The Optus breach led to the theft of customers' names, birth dates, and passport numbers.
- Russia blamed -
Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.
"We believe those responsible for the breach are in Russia," he told reporters.
"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."
Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.
Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.
University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.
"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.
"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."
H.Seidel--BTB