Modern Australian
Times Advertising

Hackers have hit major super funds. A cyber expert explains how to stop it happening again

  • Written by Toby Murray, Professor of Cybersecurity, School of Computing and Information Systems, The University of Melbourne

Several of Australia’s biggest superannuation funds have suffered a suspected coordinated cyberattack, with scammers stealing hundreds of thousands of dollars of members’ retirement savings.

Superannuation funds including Rest, HostPlus, Insignia, Australian Retirement and AustralianSuper have all reportedly been targeted. However, so far AustralianSuper appears to be the worst affected.

It is Australia’s largest superannuation fund. It has roughly 3.5 million members and manages more than $365 billion in retirement savings. In this cyberattack, a handful of its members have lost about A$500,000 in combined savings.

AustralianSuper is reportedly assisting authorities recover the money. It has not yet confirmed if any remediation will occur.

It’s not yet clear whether the affected accounts had mandatory multi-factor authentication for login or money transfers. But this is a crucial measure to reduce the risk of a similar cyberattack happening in the future.

Strategic timing, stolen passwords

Details of the cyberattack are still sparse. But we do know that it began in the early hours of last weekend. This timing was likely strategic: account holders wouldn’t have noticed anything suspicious as they would have most likely been sleeping.

Photo of a man in a suit holding his hands up in front of him.
AustralianSuper CEO Paul Schroder. Bianca Di Marchi / AAP

Cyber criminals are believed to have obtained stolen passwords – either from the dark web or other hacked websites. They then used these passwords to try to access people’s superannuation accounts.

In a statement, AustralianSuper’s Chief Member Officer Rose Kerlin said scammers had accessed up to 600 customer passwords to log into accounts.

So far only four accounts have actually been breached. In those cases, the scammers changed login details and transferred out lump sums of money.

Although members of other superannuation funds do not seem to have lost any money, their personal information may have been compromised.

Different to other attacks

There have been cases in the past of people being scammed out of their retirement savings.

For example, in 2020, Australian man Lee Braz lost all of his retirement savings, worth $180,000, to scammers. The scammers used fraudulent documents to trick his fund, Intrust Super (now owned by HostPlus), into authorising the transfer.

After a four-year legal battle with the fund, Braz retrieved one-third of the money he had lost. However, this amount didn’t cover his legal fees.

But this recent scam seems very different in nature. It didn’t involve scammers using any fraudulent documents or elaborate trickery. Instead, the perpetrators appear to have pulled it off simply by using stolen passwords to access accounts.

Tighter security is crucial

Australian Taxation Office data indicates the average super balance for men is roughly A$180,000, while for women it is roughly A$146,000.

To ensure all of this money is properly protected, financial organisations should implement mandatory multi-factor authentication for user accounts. This would require people to prove who they are with something in addition to a password.

This could include, for example, using a one-time code or an authenticator app on their smartphone. This makes it much harder for criminals who obtain user passwords to take over their accounts.

Other financial organisations, including banks and some superannuation funds, already use multi-factor authentication. But it’s especially important for all superannuation funds to implement it, given many people don’t check their retirement savings for months at a time and are less likely to notice straight away if they’ve been hacked.

In the wake of this cyberattack, the Association of Superannuations Funds of Australia says it is working to improve security across the industry, but it is unclear exactly what this will involve.

Consumers also need to do their part by making sure they do not reuse passwords between websites. This is especially important for passwords used to protect accounts on financial organisations such as their super fund or online banking.

Using a password manager is a great way to make it easy to have unique passwords for each website you visit.

Finally, customers should be on the lookout for potential scams that may target them in the coming days. Scammers have been known to exploit fear and confusion in the wake of data breaches to try to lure victims into giving away personal information or money.

Anyone receiving messages purporting to be from their super fund and who wants to respond to them should call up their super provider directly, using a phone number from their website. Avoid clicking links or phoning numbers listed in messages that purport to be from your super fund.

Anyone receiving messages they suspect are scams can report them to Scamwatch.

Authors: Toby Murray, Professor of Cybersecurity, School of Computing and Information Systems, The University of Melbourne

Read more https://theconversation.com/hackers-have-hit-major-super-funds-a-cyber-expert-explains-how-to-stop-it-happening-again-253835

What Actually Adds Value to Properties in Newcastle

Newcastle has seen steady growth over the past few years, with more buyers looking beyond Sydney for lifestyle, space, and long-term value. As dema...

What is Design and Build in Construction?

Imagine you’re about to start a new construction project, maybe it’s a custom home or a commercial building. You’ve got the idea, the land, an...

Commercial roof leak detection: why early action protects your building

Water ingress is one of the most disruptive and costly issues facing commercial properties. For property managers and facilities teams, even a minor...

Custom Photo Frames: Turning Everyday Moments into Lasting Displays

Photos capture moments, but how you display them determines how they’re experienced every day. A meaningful photograph deserves more than a generi...

Managed IT Services: A Smarter, More Predictable Way to Run Your Business Technology

If you’ve ever had your systems go down in the middle of a busy day, you’ll know how quickly things can unravel. Phones stop ringing, emails sto...

Landscaping Geelong — Coastal Elegance Meets Practical Design

A Landscape Shaped by Location Geelong occupies a unique position within Victoria’s broader landscape. It carries the energy of a growing city, y...

Electric Adjustable Beds: A Simpler Way To Sleep Better

Sleep should feel natural. It should come easily, without discomfort, without constant repositioning, and without waking up feeling sore. But for ma...

Healthy Snacking Sorted: Premium Beef Jerky

In today's fast-paced world, finding a snack that's both satisfying and genuinely good for you can feel like a mission. Many readily available optio...

What to Know Before Getting Dental Implants: A Guide for First-Time Patients

Dental implants Perth patients often look for a long-term solution for missing teeth without the hassle of dentures or bridges. If you are thinking ...

Why Protective Packaging Matters More Than Ever In Modern Shipping

In today’s fast-paced world of logistics and eCommerce, ensuring that products reach customers safely is a top priority. This is where a bubble wrap...

Pest Control Albury: Protecting Your Property From Hidden Damage And Health Risks

Pests rarely announce their arrival. They creep into spaces quietly, turning small, unnoticed corners into breeding grounds for bigger problems. Tha...

Why Root Canal Treatment Melbourne Is Essential For Saving Natural Teeth

Tooth pain has a way of demanding attention at the worst possible time. When the discomfort becomes persistent and intense, it often signals an infe...

How Bird Flight Diverters Help Protect Wildlife Around Power Infrastructure

Power infrastructure plays an essential role in modern life, but it can also create risks for wildlife, particularly birds moving through establishe...

What Businesses Should Look for in a Commercial Coffee Partner

Choosing a commercial coffee partner is not the same as choosing a machine. It is a broader decision that affects beverage quality, staff efficiency...

3PL Logistics Australia Driving Smarter Supply Chains And Faster Deliveries

In a world where customers expect speed almost as much as quality, logistics has become the silent heartbeat of every successful business. Behind th...

Why Professional Electrical Services Are Essential For Modern Properties

Electricity powers almost every aspect of daily life, from lighting and appliances to complex systems in homes and businesses. This makes choosing a...

What Not to Pack When Moving: The Essential Guide to Smart Packing

Moving house is one of those all-encompassing events in life and most people focus their energy on deciding what to pack. But knowing what not to pa...

From Assistance to Independence: Progression in Daily Living Skills

The ultimate goal of many support systems is to empower individuals to lead lives defined by autonomy and self-reliance. While some support requiremen...