News | International
12 Apr 2025 18:30
NZCity News
NZCity CalculatorReturn to NZCity

  • Start Page
  • Personalise
  • Sport
  • Weather
  • Finance
  • Shopping
  • Jobs
  • Horoscopes
  • Lotto Results
  • Photo Gallery
  • Site Gallery
  • TVNow
  • Dating
  • SearchNZ
  • NZSearch
  • Crime.co.nz
  • RugbyLeague
  • Make Home
  • About NZCity
  • Contact NZCity
  • Your Privacy
  • Advertising
  • Login
  • Join for Free

  •   Home > News > International

    What we know so far about the Australian superannuation fund cyber attacks

    Last weekend hundreds of thousands of dollars quietly disappeared from Australians' super funds. Here's how the experts think it happened.


    Multiple large superannuation funds have been targeted in suspected cyber attacks that led to some members losing several thousand dollars in retirements savings.

    Hostplus, Rest, AustralianSuper and Australian Retirement Trust are among the providers targeted.

    The attacks were discovered over the weekend, and follow rising reports of online security threats in Australia with a cyber crime reported every 6 minutes.

    Cyber experts say there were "major security weaknesses" in the superannuation sector that had been flagged, and the breach should be a wake-up call for the industry.

    What happened?

    AustralianSuper, the nation's biggest retirement fund, said cyber criminals may have used up to 600 members' stolen passwords to log into their accounts.

    The hackers allegedly sought lump sum withdrawals.

    The attack followed a spike in "suspicious activity" on AustralianSuper's website and app, chief member officer Rose Kerlin said.

    The company identified that members' stolen passwords were used to log into their accounts "in attempts to commit fraud".

    "We took immediate action to lock these accounts and let those members know," Ms Rose said.

    The superannuation industry association also confirmed members' funds had been impacted.

    "While the majority of attempts were repelled, unfortunately a number of members were affected," the group said in a statement.

    The ABC understands that no members from Rest, Host Plus, Insignia and Australian Retirement lost retirement savings.

    Host Plus said it was still investigating.

    AustralianSuper confirmed that members were still struggling to access their accounts, and that some were showing zero funds.

    "Even though you may not be able to see your account, or you are seeing a $0 balance, your account is secure," the financial company said.

    Rest customers were also experiencing outages and struggling to access accounts.

    How could accounts be accessed?

    Matt Warren, director of the RMIT Centre for Cyber Security Research and Innovation, said the breach appeared to involve large amounts of stolen data that was sold on the dark web.

    The data would have included people's usernames and passwords.

    "Someone would have bought that and then started to research how to undertake the attack," he told the ABC.

    He said the superannuation sector was an easy target, because some accounts do not require multi-factor authentication.

    Multi-factor authentication is a process where a security code is either sent to an app on your phone or via SMS after you enter your password.

    It provides an additional layer of security.

    "It means if someone had your username or password and they didn't have that code, they can't log into your account," Professor Warren said.

    Alastair MacGibbon, chief strategy officer at CyberCX, referred to the attacks as "coordinated attempted fraud".

    He said it did not appear that there was any evidence of hacking, or criminals compromising any software systems.

    Instead, it was a case of so-called "credential stuffing".

    He described credential stuffing as a type of attack where criminals use stolen credentials from one platform to gain unauthorised access to multiple user accounts.

    "They're taking usernames and passwords that have been stolen in other data breaches," he said.

    "In effect, if people use the same passwords for multiple accounts, it only takes one data breach for persistent and savvy criminals to gain unauthorised access to their other accounts."

    He added that CyberCX was tracking an increase in these attacks, and credential stuffing was a growing threat to businesses and individuals.

    How can accounts be kept secure?

    In 2024, the Financial Services Council released a standard for its superannuation members to make multi-factor authentication systems compulsory.

    The requirement recommended the security measures be implemented by July 2026.

    Not all superannuation funds targeted in the attacks are Financial Services Council members.

    But Professor Warren said that given the need to better secure accounts had been flagged, the superannuation funds should be held accountable.

    "It's been known for a long while that there's a major security weakness with superannuation," he said.

    "It's a real wake-up call … the people behind these sorts of attacks would have been aware that in Australia many superannuation fund companies didn't have compulsory multi factor authentication."

    University of Melbourne Academic Centre of Cyber Security Excellence professor Toby Murray said the attacks did not appear to be very sophisticated.

    He said the superannuation companies may not have had adequate automated fraud detection.

    Professor Murray said there would have been irregular transactions occurring at unusual hours which should have been flagged as suspicious.

    "It doesn't pass the pub test," he said.

    Mr MacGibbon agreed that the attack was not very sophisticated, and most customers should not be concerned about their funds.

    But it was clear the superannuation industry needed strong security measures.

    He also called on people to ensure they regularly update passwords so they are "unique and hard to guess", and are not repeated across multiple accounts.

    "We've all seen the banks really radically improve security … We need to do the same thing for super accounts," Mr MacGibbon said.

    "There needs to be proper anti-fraud technologies used by these super funds, and that's the wake-up call that I think Australians should have today."

    Will victims get money back?

    Superannuation funds are urging their members to check accounts for signs of fraud, ensure their banking and contact details are correct, and change their password if it is not unique to their account.

    Australia's National Cyber Security Coordinator Lieutenant General Michelle McGuinness said superannuation and banking firms were working with government agencies to respond to the attack.

    "I am coordinating engagement across the Australian government, including with the financial system regulators, and with industry stakeholders to provide cyber security advice," she said.

    Mr MacGibbon believed that customers impacted would be protected by insurance.

    "Those funds are obviously going to be returned by the superannuation companies," he said.

    Professor Warren said he would expect superannuation companies to "do the right thing" and ensure members received their money back.

    © 2025 ABC Australian Broadcasting Corporation. All rights reserved

     Other International News
     12 Apr: Queensland health officials monitoring Monash IVF after embryo transfer bungle
     12 Apr: Market turbulence continues amid fresh escalation in US-China trade war
     12 Apr: US and Pakistan threaten Afghan migrants with deportation
     12 Apr: Grey's Anatomy star Eric Dane has been diagnosed with ALS. Here's what it means
     12 Apr: US judge demands White House reveal plans to return man wrongly deported to El Salvador prison
     12 Apr: Australian judge Robert French becomes latest foreign judge to quit Hong Kong's Court of Appeal
     12 Apr: Donald Trump's trade war takes toll on Americans as US tariffs begin to bite
     Top Stories

    RUGBY RUGBY
    Highlanders coach Jamie Joseph is refusing to give up on his young squad ahead of tonight's Super Rugby Pacific meeting with the Fijian Drua in Dunedin More...


    BUSINESS BUSINESS
    A judge has dismissed an injunction, halting the controversial sale of Tauranga's Marine Precinct More...



     Today's News

    Politics:
    Queensland health officials monitoring Monash IVF after embryo transfer bungle 18:17

    Rugby:
    Highlanders coach Jamie Joseph is refusing to give up on his young squad ahead of tonight's Super Rugby Pacific meeting with the Fijian Drua in Dunedin 18:07

    Rugby:
    Matatu coach Whitney Hansen has acknowledged the blow of losing loose forward Lucy Jenkins and prop Marcelle Parkes ahead of tonight's Super Rugby Aupiki final against the Blues at Eden Park 17:27

    International:
    Market turbulence continues amid fresh escalation in US-China trade war 17:27

    Law and Order:
    A homicide investigation's underway following the discovery of a woman's body in Waiuku, near Auckland, yesterday evening 17:27

    Netball:
    Former Australia Diamonds captain turned Central Pulse shooting coach Vicki Wilson believes it'll take some time for ANZ Premiership netball teams to fully embrace the new two-point shot 16:17

    International:
    US and Pakistan threaten Afghan migrants with deportation 16:07

    Motorsports:
    New Zealand Supercars driver Ryan Wood is stoked to have earned his first podium finish on home tarmac 15:57

    Soccer:
    Wellington Phoenix men's coach Giancarlo Italiano is avoiding any discussions about the past, with the Melbourne Victory back in the capital for this afternoon's A-League contest 15:27

    Auckland:
    A person has been rescued from an apartment fire in Auckland 14:57


     News Search






    Power Search


    © 2025 New Zealand City Ltd