Ernst & Young has terminated two employees stationed at Commonwealth Bank of Australia after they allegedly accessed Prime Minister Anthony Albanese’s personal bank account information without authorization. One of the fired staffers now faces criminal charges in connection with the breach. The incident occurred during their consulting assignment at CBA, one of Australia’s largest financial institutions.

The unauthorized access raises serious questions about internal security controls at major financial institutions and the oversight of third-party consultants with privileged system access. CBA has not disclosed when the breach occurred or how it was detected, though the swift termination and criminal referral suggest the bank is treating this as a severe security violation.

This incident comes at a time when Australian regulators are already scrutinizing data protection practices across the financial sector following several high-profile breaches in recent years.

FXnCO Insight

Financial institutions using external consultants should immediately audit access privileges and monitoring systems, as regulatory scrutiny on data governance will likely intensify following this high-profile breach involving a sitting head of government.

Source: Finextra