The Commonwealth Bank has admitted it lost 20 million customer statements after a sub-contractor failed to confirm it had destroyed the data.
CBA has defended the decision not to tell 12 million customers about a the loss of their transaction records in 2016.
The incident, which occurred in 2016 and first reported in Buzzfeed News yesterday, concerns 20 million customer statements from between 2000 and 2016.
According to CBA, the bank was "unable to confirm" the destruction by a supplier (Fuji Xerox) of two magnetic tapes which contained historical customer statements.
CBA said the tapes did not contain passwords, PINs or other data "which could be used to enable account fraud". However, they did include names, addresses, account numbers and transaction records.
"An independent forensic investigation ordered by CBA in 2016 and conducted by KPMG determined the most likely scenario was the tapes had been disposed of," said CBA.
CBA notified the Office of the Australian Information Commissioner and APRA at the time, but failed to tell affected customers.
"The decision not to notify customers was made in light of the investigations findings and the account monitoring in place," said CBA.
The bank's acting group executive for retail banking services, Angus Sullivan, said: "We take the protection of customer data very seriously and incidents like this are not acceptable."
"I want to assure our customers that we have taken the steps necessary to protect their information and we apologise for any concern this incident may cause," Mr Sullivan said.
Investors should be looking to increase allocations to defensive assets this year, with relations between the US and China contributing to m...
Rapid changes in the financial sector are opening opportunities for investors, with the introduction of open banking and digitization to acc...
Australia’s competition watchdog is proposing to accept an application for a certification trademark that signals to potential investors t...