-
'Don't have to hide': Thai IDs, legal work give hope to Myanmar refugees
-
Siemens shares plunge on disappointing guidance raise
-
Stocks mixed with tech firms back under pressure
-
New Australia coach Kiss gives Japan starts to Ross, Amatosero
-
How Blundell's old school tactic ended England's 'Bazball' era
-
'Stretch our money': Romanians face highest EU inflation
-
Israel reports troop deaths as Lebanon talks underway in Rome
-
Iran says close to Hormuz plan with Oman, but reopening depends on US
-
Seeds Rybakina, Pegula, Gauff reach third round at WTA Toronto
-
Messi scores twice to set Leagues Cup record in Miami victory
-
Police raid South Korea FA in probe into World Cup coach appointment
-
Asian stocks mostly down with tech firms back under pressure
-
Low water on Germany's Rhine river threatens new blow to economy
-
Back to the future as world champion Springboks host All Blacks
-
Ex-Wallabies Foley, Phipps rejoin Waratahs ahead of home World Cup
-
India youth protests highlight mistrust in 'lapdog' media
-
Rising Kenyan lakes push crocodiles closer to homes
-
Pacific islands alarmed by Trump-backed push for deep-sea mining
-
Istanbul cymbals: From Ottoman war tool to pulse of global music
-
Erratic rains dictate menu at three-star Michelin restaurant in Brazil
-
Myanmar ex-junta chief on first Thailand trip as civilian leader
-
Zverev, Auger-Aliassime and Medvedev exit Montreal Masters
-
Environmental disaster looms as tanker leaks off Oman
-
Google-parent Alphabet shakes up AI division
-
Embattled Infantino sees minnows Malawi reach WAFCON quarter-finals
-
FIFA back Infantino, apologise for World Cup privatisation plan
-
Seeds Rybakina, Pegula and Gauff advance at WTA Toronto event
-
Auger-Aliassime out of Montreal ATP event with injury
-
Zverev, Auger-Aliassime exit star-short Montreal Masters
-
Colombian baby hippo of Escobar stock dies after rescue
-
Embattled FIFA chief Infantino in emergency talks in Morocco
-
Preakness shifts 2027 dates to entice more Derby horses
-
Castaway SpaceX rocket stage crashed into Moon, scientists say
-
Guatemalan volcano eruption ends, locals return home
-
Dow edges to record as markets parse prospects for Hormuz deal
-
WHO chief urges stronger Ebola response in DR Congo visit
-
Salah arrives in Turkey to complete Trabzonspor move
-
Newcastle appoint Jaissle as new head coach after Howe exit
-
AFP journalist to be honored at International Press Freedom Awards
-
Swiss ski star Lara Gut-Behrami calls time on 18-year career
-
Turkish MPs back limited amnesty for Kurdish militants
-
US indicts leaders of Mexico's CJNG cartel, ups reward money
-
Noosha Aubel: Czy poradzi sobie z problemami Poczdamu?
-
Noosha Aubel: Είναι σε θέση να αντιμετωπίσει τα προβλήματα του Πότσδαμ;
-
Noosha Aubel: Klarar hon av Potsdams problem?
-
نوشا أوبيل: هل هي على مستوى التحديات التي تواجهها بوتسدام؟
-
Noosha Aubel: Zvládne problémy Postupimi?
-
Former England fly-half Burns retires from rugby union
-
Brazil hits new diplomatic lows with US and Argentina
-
Pakistan beat West Indies by eight wickets to level series
Repeat hacks highlight Australia's cyber flaws
Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.
Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.
Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.
Both incidents sit comfortably among the largest data breaches in Australian history.
Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.
"There was a famous line for a while: Data is the new oil," he told AFP.
"If data is the new oil, then we're living the era of the weekly oil spill."
Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.
"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.
"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."
Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.
- Hacking 'for profit' -
Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.
"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."
Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.
Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.
"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.
"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."
The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.
The Optus breach led to the theft of customers' names, birth dates, and passport numbers.
- Russia blamed -
Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.
"We believe those responsible for the breach are in Russia," he told reporters.
"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."
Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.
Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.
University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.
"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.
"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."
X.M.Francisco--PC