Security centre

How your money stays yours

CommBank wraps every account in layered defence: encryption, multi-factor authentication, device recognition and 24/7 fraud monitoring. Here is exactly how each layer works — and what your part is.

Shield with padlock surrounded by 2FA, encryption and verification badges
AES-256Data at rest
2FAEvery new device
Defence in depth

Five layers between attackers and your account

No single control is trusted alone. Each layer assumes the previous one might fail.

1. Encryption

TLS secures every session in transit; AES-256 class encryption protects stored data with separately managed keys.

2. Multi-factor authentication

Passwords alone are never enough. One-time codes or biometrics confirm identity on every new device and sensitive action.

3. Device recognition

Each device earns a fingerprint over time. Unknown devices get restricted access and an extra verification step.

4. Behaviour analytics

Models learn your normal patterns. Unusual amounts, locations or hours trigger step-up checks before money moves.

5. 24/7 fraud team

Automated alerts route to human analysts around the clock. Suspicious activity can freeze transactions in seconds.

+ You, informed

Real-time alerts for logins, payments and card charges make you the fastest sensor in the system.

Padlock surrounded by binary streams and AES-256 badge
Layer one, in plain words

Encryption: unreadable to everyone but you

Encryption scrambles data so that only the intended recipient can decode it. CommBank applies it twice: once while data travels between your device and the bank, and again while it sits in storage.

  • In transit: TLS protects every page of NetBank — look for the lock in your browser.
  • At rest: AES-256 class encryption with keys stored apart from the data itself.
  • In code: security reviews run on every release before it can reach production.
Layer two

Two factors are worth a hundred passwords

Multi-factor authentication combines something you know (your password) with something you have (your phone) — or something you are (your fingerprint). An attacker who steals one factor still gets stopped by the other.

Recommendation: enable both a one-time code and biometric unlock. Enabling MFA blocks the overwhelming majority of account-takeover attempts before they start.

Phone entering a six-digit verification code between something-you-have and something-you-know icons
Fake urgent bank email flagged as phishing next to a genuine HTTPS padlock
Urgency is a red flag
Your turn

Spot phishing in five seconds

Attackers rarely break encryption — they ask you to hand over the key. Almost every phishing message has the same three fingerprints:

  1. Fake urgency

    "Your account will be locked in 24 hours." Real banks give you time; scammers manufacture panic.

  2. Look-alike address

    bank-secure-login.xyz instead of the official domain. Check the full address, not the display name.

  3. A link that does the work

    Never click. Type the bank's address yourself or open the official app — if the message was real, the alert will be waiting there.

Emergency playbook

If you suspect fraud: four moves, in order

  1. Freeze the card

    One tap in NetBank stops further charges instantly. You can unfreeze later if it was a false alarm.

  2. Change your password

    Use a new, unique password. If you reuse the old one elsewhere, change it there too.

  3. Review the last 30 days

    Check transactions, payees and scheduled payments. Fraudsters often plant small test charges first.

  4. Contact support

    Report through the official channels listed in the Support guide. The fraud team can reverse eligible transactions and secure the profile.

FAQ

Security questions, answered

What encryption does NetBank use?

Connections are protected with TLS transport encryption, and sensitive data at rest is stored using AES-256 class encryption with keys managed separately from the data.

Should I enable biometric login?

Yes. Fingerprint and face recognition on your own device combine convenience with security: the biometric template never leaves the device, and sensitive changes still require a password or code.

How do I spot a phishing message?

Check the sender address character by character, ignore urgency or threats, and never click links — type the bank's address manually. Real banks never ask for your full password by message.

What should I do if I suspect fraud?

Freeze the affected card in NetBank, change your password, review recent transactions and contact support. Acting within minutes limits most losses.

Something looks wrong right now?

The support guide lists the official channels and the fastest route to a specialist.

Get support Back to NetBank