
"The insider who watched: what the American Express determination says about who can read your data — and who gets to talk about it"
The insider who watched
The breach that hit "BAM" — the complainant's anonymised initials — didn't come from a ransomware crew or a leaked database dump. It came from an employee at American Express Australia with whom he had briefly been in a relationship, who used legitimate work access to look at his accounts and transactions repeatedly. No malware, no phishing: just a person with a lawful login and an unlawful reason to use it.
That is the most uncomfortable part of this case, and it's why it deserves more attention than it got. Every control the average customer imagines protecting them — encryption, fraud scoring, two-factor login — does nothing against an employee who is supposed to have access to the account screen. Insider misuse isn't an edge case in banking. The 2019 report of the Royal Commission into banking recorded employees rifling through customers' accounts, and the 2022 Optus and Medibank breaches gave Australia its fixation on external attackers. But the pattern that keeps recurring, year after year, is a person inside the perimeter acting on a personal motive.
What the determination found
The Privacy Commissioner's investigation, sparked in 2023 and summarised in the OAIC's published report, concluded Amex breached Australian Privacy Principle 11.1 by failing to take reasonable steps to protect personal information from unauthorised access — specifically insider access. The findings were stark:
- More than three-quarters of Amex's systems did not track employee access to customer accounts at all, so much insider misuse would be undetectable.
- Amex's anomaly-detection program, which might have caught out-of-pattern access, did not cover the employee's team during the relevant period — despite the company having experienced a previous insider incident in 2019 and being on notice.
- The Commissioner identified specific reasonable steps Amex should have taken: uniform account-level access logging, restricted access to certain customer records, just-in-time access, and prohibiting employees from accessing accounts of friends and family.
APP 11.1 is deliberately written to scale with risk. The OAIC's guidance on the Australian Privacy Principles describes security measures as a question of what is "reasonable in the circumstances" — and a bank holding transaction data, balances and identity documents sits near the top of that scale. The Commissioner's reasoning here is worth reading for that reason: she didn't accept "we have logging in most systems" as reasonable. Where the employee could get in, the standard followed.
Amex was ordered to apologise in writing, pay the complainant compensation of more than $23,000, and implement account-level logging and access restrictions within six months. As the ABC reported, the interim decision had found the company's technology needed an overhaul because the majority of its customers' data was exposed to rogue-employee access.
One more detail that reads oddly: the determination process itself dragged on for years. BAM first complained in 2023; the investigation and the interim decision both surfaced in 2026. The OAIC's case backlog has been a running scandal since before the review of the Privacy Act began, and a three-and-a-half-year wait between harm and remedy is its own kind of failure. If you're considering a complaint of your own, the NDB scheme's pages are the practical starting point, but go in with patience as an assumption.
Then came the gag order
The twist that turned a routine enforcement story into a national controversy: the complainant won, and was then legally threatened into silence. Privacy Commissioner Carly Kind provided the full determination to BAM on a "strictly confidential basis", warning that unauthorised disclosure could trigger urgent injunctive proceedings — after Amex made submissions about what should be restricted, citing "the creation of risks to Amex's cybersecurity". The Sydney Morning Herald's reporting noted the Commissioner had three weeks earlier signalled an intention to publish, before reversing course.
Think about what that argument actually means. The section 100 confidentiality regime exists to let regulators share commercially sensitive material during an investigation without it becoming a gossip feed. Applied this way, it becomes a liability shield: the worse the security finding, the stronger the incentive to bury it. The cybersecurity-risk justification is especially thin — the "risks" cited came from the findings describing logging gaps, not from any exploit methodology a determination would reveal. Nobody attacks a bank with an OAIC PDF.
The Senate wasn't satisfied. On 1 July 2026 it passed a motion compelling the OAIC to hand over the full report, passing 33–21 with a deadline of 28 July — an unusual use of parliamentary order-making power against a regulator, and a signal of how far the transparency argument cut across party lines. Section 49 of the Parliamentary Privileges Act means a compliant response has to follow; what the OAIC chooses to redact, if anything, is the fight still running as I write this.
The previous incident, and what "on notice" means
It's worth dwelling on the 2019 precedent, because the Commissioner treated it as a turning point. A first insider incident at a major bank is a warning shot every security team should treat as a design brief. After it, Amex knew three things: employees could reach customer records, an employee had in fact done so, and detection had depended on chance rather than instrumentation. The reasonable-response bar shifted at that moment — and the determination records that the anomaly-detection program still hadn't reached the relevant team years later. Deployment rollouts of security tooling are always partial; the finding says partial coverage of insider detection, at a bank already burned once, isn't "reasonable steps". That reasoning generalises far past banks: any organisation that has had one insider incident has effectively told its regulator it knows the threat is real.
Why this matters to you
Insider access is the threat model people forget. After any relationship breakdown or dispute with an organisation, it's worth assuming someone inside may look. Bank customers can request access logs and file complaints with the OAIC — BAM's case proves the pathway works, even if it took three and a half years. A written request for the bank's records of who viewed your profile is free, and the Consumer Data Right rules give some account holders a second, independent lever for seeing what data is held.
Logging is the tell. The single most damning finding wasn't the employee's conduct — it was that most systems couldn't even record it. That applies at any scale: if your own services don't log who accessed what and when, monitoring and audit can't catch misuse either. There's a small irony in a payments giant learning that lesson from the same playbooks a two-person SaaS company uses. Access logging costs almost nothing to build in from the start and is painful to retrofit — which is exactly why most organisations don't, and why the finding deserves quoting at whoever sets your own engineering priorities.
Transparency is part of the remedy. A determination nobody can read deters nobody. The OAIC's enforcement credibility already took damage from the backlog; a precedent that bad findings can be sealed indefinitely would compound it. Whatever the Senate order produces, the principle stands: privacy findings against large institutions only protect the rest of us if they're public.
This article is general information, not legal advice. Determination status and Senate order details checked on 7 October 2026.