Hackers Target Australian Pension Funds in Coordinated Cyberattacks
In a concerning development, hackers have launched coordinated cyberattacks on some of Australia’s largest pension funds, exposing vulnerabilities in the nation’s superannuation system.
These attacks have compromised thousands of accounts, stolen personal data, and resulted in financial losses amounting to approximately $500,000.
The Targets
The cybercriminals targeted major superannuation funds, including Australian Super, Hostplus, Rest Super, Insignia Financial, and Australian Retirement Trust.
Australian Super, the country’s largest fund managing $365 billion for 3.5 million members, reported suspicious activity affecting around 600 accounts.
Rest Super revealed that up to 8,000 accounts may have had personal information accessed.
The Method
The attacks involved credential stuffing, a technique where hackers use stolen passwords to gain unauthorized access to accounts. This method exploits the common practice of password reuse, highlighting the importance of unique and secure login credentials.
The Impact
While most attempts were repelled, some members experienced financial losses and disruptions. AustralianSuper assured members that their accounts are secure despite temporary glitches showing zero balances. Rest Super and Insignia Financial confirmed that no funds were stolen from their accounts, but personal information may have been accessed.
The Response
Authorities, including the Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC), are working closely with financial institutions to address the breaches. Superannuation funds have implemented heightened security measures, such as multi-factor authentication, to mitigate risks.
Lessons Learned
These attacks underscore the growing threat of cybercrime in the financial sector. Members are urged to protect themselves by using strong, unique passwords and enabling multi-factor authentication. The incident serves as a wake-up call for both individuals and institutions to prioritize cybersecurity.
As the investigation continues, the focus remains on safeguarding the life savings of millions of Australians and preventing future breaches. This incident highlights the need for robust cybersecurity measures in an increasingly digital world.
Protecting Your Super Fund Account
Important steps to protect your super fund account:
- Change & Check Password – If you super fund is one of the hacked companies, change your password straight away! Also, it’s important that you make sure your Super fund account is secure by not using a compromised password, ideally storing your account login in a trusted password manager like Keeper.
- Secondary Authentication – Make sure that secondary authentication is enabled using an authenticator app like Google Authenticator, Microsoft Authenticator or Keeper, otherwise, a less secure method is via your phone number.





