2018 Commonwealth Bank Australia — staff emails mis-addressed to cba.com vs cba.com.au; ~10k customers referenced (2016–17 pattern)
Data compromised
Customer-identifying content in misrouted administrative email per CBA investigation narratives—full field-level exposure debated by recipients
Technical writeup
Commonwealth Bank of Australia (CBA) publicly explained that staff had sent hundreds of internal emails to `@cba.com` instead of `@cba.com.au`, a path that misrouted messages containing metadata on roughly 10,000 customers across 2016–2017 correspondence. iTnews, SMH, and the bank’s newsroom stated the external domain operator auto-purged body content, leaving only sender/recipient/subject traces in many cases, and that CBA ultimately acquired the confusing domain; the episode was regulated as a serious operational-data-control failure though not a classic external intrusion.
Root cause
Human mis-addressing / mail-routing hygiene failure on high-volume internal email