1. Encryption
TLS secures every session in transit; AES-256 class encryption protects stored data with separately managed keys.
CommBank wraps every account in layered defence: encryption, multi-factor authentication, device recognition and 24/7 fraud monitoring. Here is exactly how each layer works — and what your part is.
No single control is trusted alone. Each layer assumes the previous one might fail.
TLS secures every session in transit; AES-256 class encryption protects stored data with separately managed keys.
Passwords alone are never enough. One-time codes or biometrics confirm identity on every new device and sensitive action.
Each device earns a fingerprint over time. Unknown devices get restricted access and an extra verification step.
Models learn your normal patterns. Unusual amounts, locations or hours trigger step-up checks before money moves.
Automated alerts route to human analysts around the clock. Suspicious activity can freeze transactions in seconds.
Real-time alerts for logins, payments and card charges make you the fastest sensor in the system.
Encryption scrambles data so that only the intended recipient can decode it. CommBank applies it twice: once while data travels between your device and the bank, and again while it sits in storage.
Multi-factor authentication combines something you know (your password) with something you have (your phone) — or something you are (your fingerprint). An attacker who steals one factor still gets stopped by the other.
Recommendation: enable both a one-time code and biometric unlock. Enabling MFA blocks the overwhelming majority of account-takeover attempts before they start.
Attackers rarely break encryption — they ask you to hand over the key. Almost every phishing message has the same three fingerprints:
"Your account will be locked in 24 hours." Real banks give you time; scammers manufacture panic.
bank-secure-login.xyz instead of the official domain. Check the full address, not the display name.
Never click. Type the bank's address yourself or open the official app — if the message was real, the alert will be waiting there.
One tap in NetBank stops further charges instantly. You can unfreeze later if it was a false alarm.
Use a new, unique password. If you reuse the old one elsewhere, change it there too.
Check transactions, payees and scheduled payments. Fraudsters often plant small test charges first.
Report through the official channels listed in the Support guide. The fraud team can reverse eligible transactions and secure the profile.
Connections are protected with TLS transport encryption, and sensitive data at rest is stored using AES-256 class encryption with keys managed separately from the data.
Yes. Fingerprint and face recognition on your own device combine convenience with security: the biometric template never leaves the device, and sensitive changes still require a password or code.
Check the sender address character by character, ignore urgency or threats, and never click links — type the bank's address manually. Real banks never ask for your full password by message.
Freeze the affected card in NetBank, change your password, review recent transactions and contact support. Acting within minutes limits most losses.
The support guide lists the official channels and the fastest route to a specialist.