Help & support
At CommBank, we are committed to ensuring the security of our information, systems and services and value the role of security researchers in helping us mitigate cyber security risk.
If you believe you have discovered a suspected cyber threat or security issue that affects the confidentiality, integrity or availability of the Bank’s information, systems or services (“vulnerability”), please submit a report to our security team via one of the methods below.
For the protection of our customers, we treat all information regarding a vulnerability as confidential and ask that you do not publicly disclose, discuss or confirm the details of any suspected security issues.
Please do not use this disclosure program to report phishing or scam attempts. If you have received a hoax or phishing email or SMS please send it to hoax@cba.com.au. You can also access our list of recently reported scam emails impersonating CommBank.
While we encourage security research on our products and services, the following types of research are strictly prohibited:
CommBank does not waive any rights or claims with respect to such activities.
You can responsibly disclose suspected vulnerabilities to the CommBank Cyber Security Team by emailing vulnerability@cba.com.au.
If you feel the email should be encrypted, our PGP key can be found below.
To assist us in investigating your report, we recommend you follow the structure:
Upon submitting your disclosure, you will receive confirmation that we’ve received it by way of an automated reply.
We will use the disclosure information you provide to enhance the security of our systems. We may also use the information in notifications to regulatory bodies, to comply with laws, and assist government or law enforcement agencies.
If you have provided your personal information, we may contact you for more information to assist us with investigating your disclosure.
For more information about how we handle your personal information, you can refer to our CommBank Privacy policy.
CommBank does not compensate individuals or organisations for identifying potential or confirmed security vulnerabilities. We sincerely thank the researchers who have helped keep our customers and communities safe by reporting security vulnerabilities.
Ceba can help you lock your card or securely connect you to a specialist in the CommBank app.
Fast-track your call, see expected wait times and connect with a specialist in the CommBank app.
Send us a copy or screenshot if you receive a hoax email or SMS.