A recent audit has revealed that banking cybercrime is on the rise in Australia, with thousands of Australian banking passwords stolen and traded online, the ABC reports.
Cyber intelligence research has revealed that more than 31,000 credentials belonging to customers of Australia's Big Four banks – Commonwealth Bank, ANZ, NAB and Westpac – are circulating on the dark web and messaging platform Telegram.
Infostealer malware on devices
The audit found that at least 14,000 passwords linked to Commonwealth Bank, 7,000 to ANZ, 5,000 to NAB, and 4,000 to Westpac customers have been exposed.
The breach has been attributed to "infostealer" malware, a type of malicious software that infects devices to harvest sensitive data such as banking credentials, credit card details, cryptocurrency wallets, and browser histories.
The malware primarily targets Windows systems but has increasingly been found on mobile devices.
Exposed passwords create a genuine risk of theft and financial loss.
In addition to banking information, compromised data often includes access to online payment platforms, e-commerce accounts and personal financial information stored within browsers.
Some of the affected devices were compromised as early as 2021, but the credentials remain valuable to cybercriminals.
Even outdated passwords can provide access to accounts, particularly where authentication methods can be bypassed using stolen browser cookies or access tokens.
The cybercrime ecosystem facilitating this trade is expanding rapidly.
Stolen credentials are sold or distributed freely via online forums and encrypted messaging platforms.
Subscriptions to new stolen data can cost as little as US$400 (around A$626), providing access to tens of thousands of stolen logs monthly.
Lifetime access packages are also being marketed for thousands of dollars.
Globally, infostealer malware infections have surged, with over 58,000 devices compromised in Australia alone and more than 31 million worldwide.
Silent heist
The scale of theft has been described as a "silent heist", with an estimated 3.9 billion passwords stolen globally through these methods.
Traditional cybersecurity measures such as changing passwords and enabling multi-factor authentication offer limited protection if devices remain infected.
Cybersecurity specialists advise that keeping operating systems and antivirus software updated is crucial, alongside avoiding downloads of pirated software, gaming modifications, and other unofficial applications that are common infection vectors.
Individuals are encouraged to conduct sensitive activities such as banking on separate, secure devices to reduce exposure.
Authorities continue to monitor the situation closely as cybercriminals capitalise on widespread malware infections to access and exploit personal financial data.