• Contact
  • Feedback
Banking Day
  • News
  • Topics
    • All Topics
    • Briefs
    • Major Banks
    • Authorised deposit-taking institutions
    • Insurance, funds and super
    • Payments, mobile & wallets
    • Consumer lending
    • Mortgages
    • Business lending
    • Finance regulation
    • Debt capital markets
    • Ratings agencies
    • Equity capital markets
    • Professional services
    • Work & career
    • Foreign news
    • Other topics
  • Free Trial
  • Subscribe
  • Resources
    • Industry events
  • About us
    • About Banking Day
    • Advertise
    • Feedback
    • Contact Banking Day
  • Search
  • Login
  • My account
    • Account settings
    • User Admin
    • Logout

Login or request a free trial

Data breach at CBA's Beem compromises customer privacy

03 May 2018 4:53PM
A Commonwealth Bank payments arm last night swung into damage control after confirming that a data breach compromised the personal email addresses of its customers, which included staff employed at the Reserve Bank.The bungle is set to be the first privacy breach in the banking industry to be reported to the Office of the Information and Privacy Commissioner under a mandatory disclosure regime introduced in February.The Beem instant payments platform inadvertently revealed the email addresses of thousands of customers on Tuesday at the same time as the Australian Prudential Regulation Authority released damaging findings from an independent inquiry into operational risk failures across the CBA's operations.Beem sent customers an email to announce that its mobile app was now downloadable from Apple's app store.However, the message opened a window into the company's customer base because the email addresses of all subscribers to the service were viewable to all recipients.Beem's chief executive, Mark Wood, issued an apology to customers for the stuff-up on Tuesday and promised that it would not happen again.Here's what Wood told customers in his email:Hi There, I am writing to apologise to you.You have received an email from us earlier today that included email addresses of others.We know this is unacceptable and we do apologise for the email being sent with this information.We ask that you please delete the email and we are asking the other recipients to do the same.This has occurred due to a manual error and we are automating the process to avoid this from happening in the future.We do take your privacy seriously and no other details have been disclosed.We hope you will continue to trust us.Sincerely, Mark WoodBanking Day was alerted to the bungle by Beem customers, who reported they saw email addresses belonging to the following email domains in the message: rba.gov.au; nab.com.au; westpac.com.au; and ing.com.au.The timing of the data breach is embarrassing for the Beem subsidiary and the CBA group, given that the bank and its prudential regulator are now trying to paint an image of a company mending its errant ways. CBA is a part-owner of Beem, along with NAB and Westpac, through a company known as Digital Wallet Pty Ltd.The CBA associate last night declined to respond to a written request from Banking Day for its views on what the regulatory fallout might be.A spokesperson did not comment on whether the data breach was reportable to the banking regulator and the federal privacy commissioner."We take our responsibility to keep customer information secure very seriously and we are disappointed this has occurred," the spokesperson said. "We have contacted all customers and are working to ensure controls are in place so that this doesn't happen in the future."Earlier this week CBA entered into an enforceable undertaking to APRA, which included the adoption of special measures to improve its operational risk record.

I'm a returning subscriber

*
Password reset *
Login

Request a free trial

  • Emailing you the news at 7am.
  • Covering core lending and funding issues, strategy, payments, regulation, risk management, IT, marketing and more.
  • Original news and summaries of major stories from other media – ditch your newspaper subscriptions.
  • Focused on banking and finance, saving you the time spent wading through newspapers and other services.
  • With reporting from former editors and senior writers from the AFR and The Australian.
  • Configured for your phone, laptop and PC.
Free trial Banking Day
Stay Ahead. Stay Informed.
Concise. Candid. Provocative.
Get the daily banking news that matters
Banking Day – Your trusted source for independent financial insights.
Subscribe Now

Consumer lending

  • Latitude, Harvey Norman liable for interest free GO card con

Copyright © WorkDay Media 2003-2025.

Banking Day is a WorkDay Media publication

WorkDay Media Unit Trust

  • Privacy policy
  • Terms of access and use