- Johnson bags five as Australia beat Pakistan to seal T20 series
- Zelensky says wants to end war by diplomacy next year
- Rugby Union: Wales v Australia - three talking points
- 10 newborns killed in India hospital fire
- Veteran Le Cam leads Vendee Globe as Sorel is first to quit
- Bagnaia on pole for Barcelona MotoGP, Martin fourth
- UN climate chief urges G20 to spur tense COP29 negotiations
- Rauf takes four as Pakistan hold Australia to 147-9 in 2nd T20
- World not listening to us, laments Kenyan climate scientist at COP29
- Philippines warns of 'potentially catastrophic' Super Typhoon Man-yi
- Wales take on Australia desperate for victory to avoid unwanted record
- Tyson beaten by Youtuber Paul in heavyweight return
- Taylor holds off bloodied Serrano to retain undisputed crown
- Japan PM expresses concern to Xi over South China Sea situation
- Tens of thousands flee as Super Typhoon Man-yi nears Philippines
- Hoilett gives Canada win in Suriname as Mexico lose to Honduras
- Davis, James spark Lakers over Spurs while Cavs stay perfect
- Mushroom houses for Gaza? Arab designers offer home-grown innovations
- Gabon votes on new constitution hailed by junta as 'turning point'
- Young Libyans gear up for their first ever election
- Vice tightens around remaining civilians in eastern Ukraine
- Dutch coalition survives political turmoil after minister's resignation
- Uruguay end winless run with dramatic late win over Colombia
- Max potential: 10 years since a teenage Verstappen wowed in Macau
- Tens of thousands flee as Typhoon Man-yi nears Philippines
- Is Argentina's Milei on brink of leaving Paris climate accord?
- Big Bang: Trump and Musk could redefine US space strategy
- Revolution over but more protests than ever in Bangladesh
- Minister resigns but Dutch coalition remains in place
- Ireland won 'ugly', says relieved Farrell
- Stirring 'haka' dance disrupts New Zealand's parliament
- England's Hull grabs lead over No.1 Korda at LPGA Annika
- Kosovo players walk off in Romania after 'Serbia' chants, game abandoned
- Kosovo players walk off in Romania game after 'Serbia' chants
- Lame-duck Biden tries to reassure allies as Trump looms
- Nervy Irish edge Argentina in Test nailbiter
- Ronaldo at double as Portugal reach Nations League quarters, Spain win
- Fitch upgrades Argentina debt rating amid economic pain
- Trump picks Doug Burgum as energy czar in new administration
- Phone documentary details struggles of Afghan women under Taliban
- Ronaldo shines as Portugal rout Poland to reach Nations League last-eight
- Spain beat Denmark to seal Nations League group win
- Former AFCON champions Ghana bow out as minnows Comoros qualify
- Poland, Britain reach BJK Cup quarter-finals
- At summit under Trump shadow, Xi and Biden signal turbulence ahead
- Lebanon said studying US truce plan for Israel-Hezbollah war
- Xi warns against 'protectionism' at APEC summit under Trump cloud
- Nigerian UN nurse escapes jihadist kidnappers after six years
- India in record six-hitting spree to rout South Africa
- George tells England to prepare for rugby 'war' against Springboks
Repeat hacks highlight Australia's cyber flaws
Inadequate privacy safeguards and the stockpiling of sensitive customer information have made Australia a lucrative target in the eyes of foreign hackers, cybersecurity experts told AFP following a series of major data breaches.
Medibank, Australia's largest private health insurer, recently confirmed that hackers had accessed the data of 9.7 million current and former customers, including medical records related to drug abuse and pregnancy terminations.
Telecom company Optus fell prey to a data breach of similar scale in late September, during which the personal details of up to 9.8 million people were accessed.
Both incidents sit comfortably among the largest data breaches in Australian history.
Australian National University cybersecurity expert Thomas Haines said many companies had been hoarding personal data that they should not have been hanging on to.
"There was a famous line for a while: Data is the new oil," he told AFP.
"If data is the new oil, then we're living the era of the weekly oil spill."
Haines contrasted Australia's approach with that of the European Union, which in 2018 adopted sweeping privacy reforms limiting how organisations collect, use and store personal data.
"There have got to be incentives in place to stop companies hoarding data they don't need, or to penalise those companies for big leaks. Europe has done this," he said.
"At the moment the business incentives are basically along the lines of: Let's just keep a whole bunch of data."
Haines said Medibank appeared to be an exception, in that most of the sensitive information within its databases had been stored for good reason.
- Hacking 'for profit' -
Australia's comparatively weak safeguards against identity theft meant it was also easier to exploit stolen personal information, Haines said.
"All they need to know is your passport, your driver's licence and some other things -- and then I can start taking out loans in your name."
Haines said European countries such as Norway had much more stringent requirements involving face-to-face contact.
Dennis Desmond, a former FBI agent and US Defense Intelligence Agency officer, said most hackers were searching for particular types of data.
"For-profit hackers are going after healthcare data, they're going after identity data and credentials to access systems," he told AFP.
"There is a profit motivation there, otherwise they wouldn't be risking jail and prosecution."
The Medibank hackers this week started leaking stolen data to a dark web forum, after the company refused to pay a US$9.7 million (Aus$15 million) ransom.
The Optus breach led to the theft of customers' names, birth dates, and passport numbers.
- Russia blamed -
Australian Federal Police Commissioner Reece Kershaw on Friday blamed the Medibank cyberattack on a team of hackers based in Russia.
"We believe those responsible for the breach are in Russia," he told reporters.
"Our intelligence points to a group of loosely affiliated cyber criminals who are likely responsible for past significant breaches in countries across the world."
Medibank data leaked to the dark web so far has included hundreds of potentially-compromising medical records related to drug addiction, alcohol abuse and sexually-transmitted infections.
Home Affairs Minister Clare O'Neil conceded on Friday the country's cyber defences had not always been up to scratch.
University of Sydney data researcher Jane Andrew said one major flaw was that Australian companies were not always obliged to report data breaches.
"There are heaps of data breaches happening all the time that we don't hear anything about," she told AFP.
"Companies have been gathering data because it's seen to be valuable, without fully understanding the potential risks."
H.Thompson--AT