Skip to main content

Banks get temporary access to Optus customer data to watch for fraud

6 October 2022

AFR

Banks will have to comply with strict requirements to receive customer identification details from Optus to guard against fraud, including making written assurances to regulators, proving they can securely store information and pledging to destroy it when it is no longer required.

New regulations unveiled by the Albanese government in response to the Optus cyberattack will allow telecommunications companies to temporarily share customers’ government identification details including driver’s licence, Medicare and passport numbers with banks.

Optus would also be able to share information with Commonwealth and state agencies, such as Services Australia, to detect and assist in preventing fraud, Treasurer Jim Chalmers and Communications Minister Michelle Rowland said on Thursday.

The new regulations come as Attorney-General Mark Dreyfus establishes a whole-of-government working group with Optus to coordinate the federal response to the attack, which involved the theft of information relating to nearly 10 million customers.

Mr Dreyfus has already flagged changes to privacy laws which would limit the volume of data that businesses can collect and store.

The government has also been critical of Optus, rejecting the company’s claim it was a victim of a sophisticated attack and blasting it for not sharing information quickly enough.

The regulations will apply to all telecommunications companies and all financial institutions regulated by the Australian Prudential Regulation Authority, with the exception of foreign bank branches.

The amended regulations are intended to help banks put in enhanced monitoring of customers’ accounts for fraudulent transactions. They will be reviewed after 12 months.

Ms Rowland revealed the amended regulation had been made after Optus claimed it was unable to pass on information to government agencies and banks because it was not covered by a specific exemption in the Telecommunications or Privacy acts. After receiving its own legal advice, the government considered it prudent to change the regulations.

“I think we need to be clear: these regulations are specifically in response to these cyber threats and we know that this is on a scale and scope that hasn’t happened in Australia before,” Ms Rowland said.

Under the new regulations, banks will be able to opt in to receive data from Optus after jumping through several hoops.

Banks will need to provide a written attestation that they comply with APRA’s prudential standard for information security, and provide a written commitment to the competition watchdog that they will comply with their Privacy Act obligations.

They must also confirm in writing that the information they are seeking is necessary and proportionate to safeguard customers.

Security protocols

Recipients must satisfy “robust” information security requirements and protocols for any transfer and storage of data, and must use the data solely for preventing or responding to cybersecurity incidents, fraud, scam activity or identify theft.

Banks will be required to review every 12 months whether they still need the customer information. If not, they must destroy it.

While Optus revealed 9.8 million account holders had their personal information stolen in the cyberattack, the focus of the data-sharing exercise is expected to focus on the 1.2 million people who had a current and valid form of identification compromised.

The Australian Banking Association said the whole industry had worked closely with the government on the new measures.

“The data-sharing will help us to combat fraud and scams, keep customers safe, and limit the long-term risks presented by the Optus data breach,” ABA chairman and Westpac chief Peter King said.

Optus regulatory affairs boss Andrew Sheridan welcomed the government’s tweaks.

“This proposal is about protecting Australians,” he said.

“Optus is also pleased the federal government has taken the initiative to form a joint working group with Optus to enhance the coordinated response to the cyberattack.”

Latest news

1 / 3
Newsletters
Weekly Update: 4 September 2026
4 September 2026

Key News: “The Cash Distribution Framework is an important piece of regulatory reform to ensure the continued availability of cash given the decline in its usage and recent uncertainties across the sector.” ABA CEO Simon Birmingham. Media release, 3 September 2026. Media & Communications Update: Political Update: Economic Update: Regulatory Update Upcoming Submissions Selected Media… Read more »

Read more
Newsletters
Weekly Update: 24 July 2026
24 July 2026

Key News: “You might just think it’s harmless letting somebody access your bank account and getting a few hundred bucks in return, but these are crime syndicates, these are money launderers. You may well be helping to scam a vulnerable Australian out of their life savings.” ABA CEO Simon Birmingham. Interview with 2SM’s Tim Webster,… Read more »

Read more
Newsletters
Weekly Update: 26 June 2026 
26 June 2026

Key News: “Every dollar of bank profits that gets reinvested into bank capital, generates on the analysis we showed this week, $4.70 of economic activity across the Australian economy.” ABA CEO Simon Birmingham. Interview with Ross Greenwood, 21 June. Media & Communications Update: Political Update: Economic Update: Regulatory Update Upcoming Submissions Selected Media Warm regards,The… Read more »

Read more