#NSBCS.135 - AML/CTF Compliance and Cybersecurity: The Hidden Risk of Customer Due Diligence Data
On 1 July 2026, Australia’s expanded anti-money laundering and counter-terrorism financing regime came into effect, extending the regime to certain services typically provided by lawyers, accountants, conveyancers, real estate professionals and a few others.
Reporting entities must now maintain an AML/CTF program, conduct customer due diligence, report suspicious matters where required and retain relevant records.
It is an important step in strengthening Australia’s response to financial crime. But it raises an obvious question: in building processes to protect the financial system from criminals, are we creating more valuable information for threat actors?
Coming at this from a finance and operations background, what stands out to me is the cyber risk being created alongside the compliance obligation.
AML/CTF requires firms to know more about their customers (which is a good thing). Identity details, ownership structures, transactions and risk assessments can also be extremely valuable to criminals. The more information collected and distributed across systems, the larger the potential attack surface.
The first, and perhaps most important, decision is what not to collect.
The AML/CTF Act does not generally require businesses to retain copies of identity documents. Instead, businesses need to keep sufficient records of the information used, how the customer was identified and the outcome of the verification and risk assessment.
It’s a pretty important distinction.
The instinct when a new obligation arrives is to collect and retain everything, just in case. While it probably feels safer, every unnecessary copy is information that must be protected, and information you do not retain cannot be exposed in the event of breach of your systems.
A passport or drivers licence sitting unnecessarily in an inbox, shared drive or client file is not providing additional compliance protection, but it’s definitely creating additional exposure.
This is particularly relevant for smaller practices. Even where annual turnover is below $3 million, the Privacy Act applies to personal information handled in connection with AML/CTF obligations. For some firms, this may be their first direct encounter with formal privacy compliance, at exactly the time they begin collecting some of the highest-risk personal information they have ever held.
Required customer due-diligence records generally need to be kept for seven years after the business relationship ends or an occasional transaction is completed. That makes every record retained a long-term security commitment. Businesses need to know where that information is held, who can access it, which third parties have copies and how it will be destroyed or de-identified once it is no longer lawfully required.
The connection becomes even clearer if a breach occurs. Stolen identity information can be used to make suspicious activity appear credible. A breach is therefore not only an IT or privacy event; it may also require a reporting entity to reassess its financial-crime risk and consider whether existing customer information remains reliable.
Three questions are worth answering:
What are we required to collect, and what are we retaining out of habit?
Where does that information end up, and who genuinely needs access?
How will we know when it is no longer needed, and who is responsible for destroying or de-identifying it?
AML/CTF is trying to stop criminals misusing your services. Cybersecurity is trying to stop them misusing your systems, information and people.
Know your customer. But protect what you learn about them.
What we read this week
Origin Energy Confirms Data Breach Affecting Nearly 900,000 Customers - Australian energy and internet provider Origin Energy has completed the initial phase of its investigation into a cybersecurity incident and confirmed that personal data belonging to approximately 900,000 current and former customers was compromised. The company stated that credit card and bank details were not included in the accessed information. Origin is notifying affected individuals, working with the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and law enforcement, and has extended customer support. Organisations handling large volumes of customer data should prioritise access reviews, rapid notification processes and close coordination with regulators.
Russian Actors Exploit Microsoft OWA Flaw for Persistent Mailbox Access - Russian-linked threat actors (tracked as Laundry Bear / Void Blizzard / TA488) have been observed exploiting a vulnerability in Microsoft Outlook Web Access to maintain long-term access to mailboxes even after credential rotation. The campaign targets government, telecommunications, financial and other sectors in the US and Europe, delivering a sophisticated backdoor known as OWAReaper. Defenders should apply available mitigations, monitor for anomalous OWA activity, enforce strong authentication and review email access logs for indicators of compromise.
Cisco Warns of Actively Exploited FMC Static Credential Flaw - Cisco has disclosed that a high-severity static credential vulnerability in Secure Firewall Management Center (FMC) software (CVE-2026-20316) has been exploited as a zero-day. CISA has added the flaw to its Known Exploited Vulnerabilities catalogue. Successful exploitation allows unauthorised access to vulnerable management devices. Organisations using Cisco FMC should apply patches immediately, rotate credentials, restrict management interface exposure and hunt for signs of prior compromise.
ShinyHunters Claims Ernst & Young Breach via Third-Party Platform - The ShinyHunters extortion group has claimed responsibility for a data breach at Ernst & Young, asserting it obtained access through a supply-chain or third-party platform compromise and threatening to release stolen data. EY has been notifying affected parties after detecting unauthorised access earlier in the year. The incident highlights ongoing risks in professional services supply chains. Firms should intensify third-party risk management, monitor for credential abuse and prepare for potential secondary extortion attempts.
Coordinated Cyberattack Hits More Than 30 Minnesota Water Systems - A coordinated cyberattack targeted operational technology at over 30 community water systems in Minnesota on 26–27 July 2026, prompting a statewide cybersecurity response. One plant reportedly went offline as a result. The incident underscores the growing threat to critical infrastructure and water utilities. Operators should strengthen OT segmentation, implement isolation points for containment, maintain offline backups and follow guidance on securing industrial control systems

