CBA defends its silence on losing the data of almost 20 million accounts

CBA lost the data of almost 20 million accounts without notifying customers

After an exposé from BuzzFeed News revealed that the Commonwealth Bank had lost the data of some 12 million customers (across almost 20 million accounts) in May 2016, the Australian financial giant has released a statement in its defence.

The data took the form of bank statements spanning the years 2000-2016 and was stored on two magnetic tapes that were due to be destroyed by a third-party contractor, Fuji-Xerox. 

No official documentation on the destruction of these tapes was ever produced and, as such, their whereabouts are still unaccounted for.

While the Commonwealth Bank claims these bank statements didn’t contain any information on customers’ passwords and PIN numbers, they did contain their names, addresses, account numbers and transaction details.

It's fine, though...

CBA has now released a statement to its customers via email addressing the situation and assuring them that there’s “no evidence of customer information being compromised” and that “customers do not need to take any action”.

An independent forensic investigation was immediately launched after the incident in 2016 and found that the tapes had “most likely” been disposed of. 

The affected accounts were also subject to elevated monitoring, which allegedly returned no signs of malicious activity over the last two years.

CBA notified the appropriate regulators of the potential breach and kept them up to speed with the ongoing investigation but chose not to inform customers “in light of the investigations findings and the account monitoring in place”.

...isn't it?

In a conversation with ABC News’ AM radio program, CBA’s head of retail banking, Angus Sullivan, said that “when incidents like these are shared more broadly, they create risks in and of themselves”.

While there may be truth to this, recent legislation means that Australian businesses must report if they’ve suffered a data breach to both the regulators and the affected individuals if they were deemed at risk.

While CBA did notify the regulators (in this case, the Office of the Australian Information Commission and the Australian Prudential Regulation Authority), they chose not to disclose the breach to customers as they were deemed ‘protected’.

Although ongoing monitoring may protect from any fraud or theft targeted at CBA accounts, do customers have a right to know when the names, addresses, and detailed finances of 12 million customers are misplaced?

Harry Domanski
Harry is an Australian Journalist for TechRadar with an ear to the ground for future tech, and the other in front of a vintage amplifier. He likes stories told in charming ways, and content consumed through massive screens. He also likes to get his hands dirty with the ethics of the tech.
Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
An Nvidia GeForce RTX 5080 resting on an RTX 5090 on a gray crafting mat.
Corsair tells us only one of its prebuilt PCs with an RTX 5000 GPU has suffered from chip-level fault, suggesting it’s as rare as Nvidia claimed
ChatGPT WhatsApp
New survey suggests the vast majority of iPhone and Samsung Galaxy users find AI useless – and to be honest, I’m not surprised
A hunter holds up a Grav Bowfin and smiles
How to catch a Gravid Bowfin in Monster Hunter Wilds
Quordle on a smartphone held in a hand
Quordle hints and answers for Friday, March 7 (game #1138)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Friday, March 7 (game #369)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Friday, March 7 (game #635)