Cyber Alert: Super Funds Coordinated Attack

Multiple Australian superannuation funds have recently experienced a coordinated and targeted cyber incident.
April 5 2025

By Jason Symons, Partner, Cyber Risk and Insurance, Mitchell Riley-Meijer, Incident Response Manager, Cyber Risk and Insurance and Mark Bland, Partner, Financial Services

Updated as at: Saturday, 3pm, 05 April 2025

Summary

  1. Several Australian Superannuation funds have been targeted by a coordinated cyber security attack, over the late March and early April period.
  2. The coordinated attack has targeted super funds Australian Retirement Trust, AustralianSuper, Hostplus, Rest, and Insignia.
  3. It is reported that some members of these funds have suffered financial losses as a result of the attack.
  4. The Threat Actor has not yet been identified.
  5. The impacted funds are urging customers to check their superannuation accounts and to contact their fund if account passwords have been changed without member knowledge.

Incident Overview

On Friday, 04 April 2025, several media outlets reported that Australian Superannuation funds had been targeted by a coordinated cyber security attack.

These outlets reported that super funds Australian Retirement Trust, AustralianSuper, Hostplus, Rest and Insignia had been targeted.

The information sourced by the media outlets was from several anonymous sources familiar with an investigation into the attack.

AustralianSuper, Rest and Insignia have confirmed that there has been unauthorised activity on some members accounts:

  1. AustralianSuper has stated that it has identified that cyber criminals may have used up to 600 members’ passwords to log into their accounts in attempts to commit fraud.
  2. Rest has stated that it has become aware of some unauthorised activity on its online Member Access portal.
  3. Insignia has confirmed that there has been no financial impact on its members, and that it has taken action to restrict some activities on its platforms to protect customer accounts.

The impacted funds are working with the National Cyber Security Coordinator to assess the incident.

Media outlets are reporting that it is suspected that the Threat Actors may be exploiting compromised credentials from dark web data in order to gain unlawful access to Fund member user accounts.

Cyber Security Risks

Should the claims that the Threat Actors are using historically compromised credentials to conduct this attack prove to be legitimate, the following general cyber security risks arise:

  1. Financial cyber-enabled crime potentially resulting in monetary loss.
  2. Identity theft potentially resulting in fraud or monetary loss.

Breach of other services using same or similar credentials.

Issues to Highlight

The Superannuation funds are urging members to:

  1. Check their user accounts.
  2. Contact their fund if they notice password changes.

Should the claims that the Threat Actors are using historically compromised credentials to conduct this attack prove to be legitimate, the information alleged to be used could result in an increased cyber risk to individuals due to the prevalence of credential re-use.

Funds who suspect their member’s data may be impacted by this attack should assess their IT environment to determine if there is a risk.

Funds who believe they are at risk due to this attack should engage with specialist technical and legal advice, and review advisories from government authorities to minimise technical and cyber security risk to their IT environments.

Additionally, funds who believe they are at risk should be prepared to meet relevant data breach notification and cyber security response requirements.

Funds who believe they are at risk due to this attack should also review their cyber security insurance policies to determine if they are covered for relevant response costs.

Finally, funds who believe they are at risk due to this attack should review their internal Cyber Incident Response Plans and supporting procedures should they be required to activate them.

Remaining Vigilant

Details regarding this coordinated cyber security attack are still coming to light. Impacted funds are working with the National Cyber Security Coordinator to assess this incident.

In the interim, the Australian Government, via the National Cyber Security Coordinator, recommends[1] individuals who are concerned about the impacts of this incident to engage with cyber.gov.au for more information on simple steps you can take to protect yourself online.

Staying Up-to-Date

The Mills Oakley Cyber Risk & Insurance and Financial Services teams are monitoring this situation closely and are engaging with impacted funds to provide support.

This alert will be updated as more information comes to light regarding this situation. In the meantime, if you would like to discuss this incident with us, please get in contact with our team here.

[1] See LinkedIn post here.