By Jason Symons, Partner, Cyber Risk and Insurance, Mitchell Riley-Meijer, Incident Response Manager, Cyber Risk and Insurance and Mark Bland, Partner, Financial Services
Updated as at: Saturday, 3pm, 05 April 2025
On Friday, 04 April 2025, several media outlets reported that Australian Superannuation funds had been targeted by a coordinated cyber security attack.
These outlets reported that super funds Australian Retirement Trust, AustralianSuper, Hostplus, Rest and Insignia had been targeted.
The information sourced by the media outlets was from several anonymous sources familiar with an investigation into the attack.
AustralianSuper, Rest and Insignia have confirmed that there has been unauthorised activity on some members accounts:
The impacted funds are working with the National Cyber Security Coordinator to assess the incident.
Media outlets are reporting that it is suspected that the Threat Actors may be exploiting compromised credentials from dark web data in order to gain unlawful access to Fund member user accounts.
Should the claims that the Threat Actors are using historically compromised credentials to conduct this attack prove to be legitimate, the following general cyber security risks arise:
Breach of other services using same or similar credentials.
The Superannuation funds are urging members to:
Should the claims that the Threat Actors are using historically compromised credentials to conduct this attack prove to be legitimate, the information alleged to be used could result in an increased cyber risk to individuals due to the prevalence of credential re-use.
Funds who suspect their member’s data may be impacted by this attack should assess their IT environment to determine if there is a risk.
Funds who believe they are at risk due to this attack should engage with specialist technical and legal advice, and review advisories from government authorities to minimise technical and cyber security risk to their IT environments.
Additionally, funds who believe they are at risk should be prepared to meet relevant data breach notification and cyber security response requirements.
Funds who believe they are at risk due to this attack should also review their cyber security insurance policies to determine if they are covered for relevant response costs.
Finally, funds who believe they are at risk due to this attack should review their internal Cyber Incident Response Plans and supporting procedures should they be required to activate them.
Details regarding this coordinated cyber security attack are still coming to light. Impacted funds are working with the National Cyber Security Coordinator to assess this incident.
In the interim, the Australian Government, via the National Cyber Security Coordinator, recommends[1] individuals who are concerned about the impacts of this incident to engage with cyber.gov.au for more information on simple steps you can take to protect yourself online.
The Mills Oakley Cyber Risk & Insurance and Financial Services teams are monitoring this situation closely and are engaging with impacted funds to provide support.
This alert will be updated as more information comes to light regarding this situation. In the meantime, if you would like to discuss this incident with us, please get in contact with our team here.
—
If you would like further information or have any queries regarding other matters, please do not hesitate to contact: