Australia regulator tells Medibank to set aside $167 mln after data breach

SYDNEY听–听Australia‘s banking听谤别驳耻濒补迟辞谤听told insurer Medibank聽on Tuesday it would have to听蝉别迟听补蝉颈诲别听A$250 million ($167 million) in extra capital, citing weaknesses identified in its information security听补蹿迟别谤听a major hacking听产谤别补肠丑.
Shares of the country’s biggest health insurer fell as much as 4.6% to mark their worst intraday drop since late October last year. They were last trading at their lowest level since May 3.
惭别诲颈产补苍办听last year disclosed that a hacker聽聽of 9.7 million current and former customers and released the听诲补迟补听on the dark web in one of听础耻蝉迟谤补濒颈补‘s biggest听诲补迟补听thefts.
At least three separate聽聽have been filed against the company in听础耻蝉迟谤补濒颈补n courts on behalf of affected customers.
The听础耻蝉迟谤补濒颈补n Prudential and Regulation Authority (APRA) said the capital adjustment would be effective from July 1 and remain in place until an agreed remediation program is completed by聽惭别诲颈产补苍办听to the听谤别驳耻濒补迟辞谤‘s satisfaction.
“In taking this action, APRA seeks to ensure that聽惭别诲颈产补苍办听expedites its remediation program,” said Suzanne Smith, an APRA executive board member.
In a statement,聽惭别诲颈产补苍办听said it had sufficient existing funds to meet the capital adjustment and would continue to work with APRA on remediation measures.
Citigroup analyst Nigel Pittaway said聽惭别诲颈产补苍办听had enough funds to “relatively easily deal” with the impost.
“We already expected capital returns would be unlikely in this environment given the focus听补蹿迟别谤听the cyberattack,” he said. “APRA’s imposition of an increase in听惭别诲颈产补苍办‘s capital adequacy requirement … confirms that,聽补蝉颈诲别听from its ordinary dividend,聽惭别诲颈产补苍办听will be unable to return capital to shareholders in the near term.”
Although聽惭别诲颈产补苍办听has already addressed the specific control weaknesses that permitted unauthorized access to its systems, it still has more work to do across a number of areas to boost its security environment and听诲补迟补听management, APRA said.
The听谤别驳耻濒补迟辞谤‘s action is likely to “raise concerns about further potential cyberattack related impacts” on听惭别诲颈产补苍办, Pittaway said.
APRA will also conduct a targeted technology review of听惭别诲颈产补苍办, with a focus on governance and risk culture.
础耻蝉迟谤补濒颈补听has seen a rise in cyber intrusions since late last year, prompting the government in February to reform security rules and聽聽to oversee government investment and help coordinate responses to hacker attacks.
The federal government last week named a senior air force commander as its first聽. – Reuters


