Superannuation cyber security: lessons from the super fund attacks

Superannuation cyber security: lessons from the super fund attacks

Insights • July 10, 2026 • 15-minute read

Key Takeaways

  • In April 2025, a number of Australian superannuation funds were breached in a series of coordinated credential stuffing attacks.
  • Credential stuffing attacks exploit reused passwords from previous breaches, highlighting the need for robust controls like multi-factor authentication and continuous monitoring.
  • APRA emphasises the importance of effective security controls and resilience, and is placing greater scrutiny on the technology environments supporting superannuation funds.

Financial services has long been one of the world’s most heavily targeted industries for cyber crime.  

According to the International Monetary Fund’s 2024 Global Financial Stability Report, nearly one in five reported cyber incidents over the past two decades has affected the financial sector, contributing to around US$12 billion in direct losses.  

What’s more, the IBM Cost of a Data Breach Report 2025 paints a similar picture, estimating the average financial-sector data breach now costs US$5.56 million, well above the cross-industry average.  

Certainly, the reasons are easy to understand. Financial institutions concentrate on two things cyber criminals value most: money and identity data. Superannuation funds do both at enormous scale, managing the retirement savings of millions of Australians alongside the personal information used to protect those accounts.  

That combination was brought sharply into focus in April 2025, when a coordinated credential-stuffing attack targeted several of Australia’s largest super funds. The incident attracted widespread attention, but it wasn’t an isolated event. It followed a series of attacks across the sector that exposed recurring weaknesses in authentication, detection and cyber resilience.  

The good news? The lessons are super clear. 

This guide examines what happened, why superannuation funds continue to be attractive targets, how credential-stuffing attacks work, what APRA expects from regulated entities under CPS 234, and the practical steps funds can take to better protect their members. 

 

Why super funds are prime targets 

Superannuation cyber security has become a board-level issue for one simple reason: super funds bring together exactly what cyber criminals are looking for.  

For starters, they manage billions of dollars in retirement savings while also holding large volumes of personal information, including names, addresses, contact details and account information.  

It’s that combination of money and identity data that makes them an attractive target for cyber crime and superannuation fraud. 

Tellingly, the attacks on Australia’s largest super funds in April 2025 highlighted another important lesson. Attackers didn’t target every account equally. Instead, they focused on pension and drawdown accounts because they provide the fastest path from gaining access to moving money.  

For risk leaders, that highlights an important priority. The accounts carrying the greatest financial risk also require the strongest authentication, monitoring and fraud controls. 

At the same time, technology complexity adds another layer of risk. Superannuation funds continue to consolidate, bringing together different infrastructure, applications and security controls that have evolved over many years.  

Those mergers create larger technology estates that take time to modernise, increasing the number of systems that need to be secured, monitored and evidenced under APRA’s information security requirements. Older infrastructure can also make it more difficult to demonstrate that systems are current, supported and appropriately governed. 

That’s becoming an increasingly important consideration as APRA places greater scrutiny on the technology environments supporting regulated entities, including whether infrastructure remains supported, maintained and fit for purpose. 

A pattern, not an incident: super fund data breaches since 2022

Certainly, the coordinated attacks on Australian super funds in April 2025 dominated headlines, but they weren’t an isolated event. They were the latest chapter in a pattern that’s been developing for several years.

Between 2022 and April 2025, when the latest breach was discovered, several Australian super funds have been targeted in a series of attacks. The attacks saw adversaries gain access to member data through methods including phishing and credential stuffing.

Looking at these incidents together reveals something important. Funds of different sizes, structures and ownership models have all been targeted. More importantly, many of the same weaknesses continue to appear, whether that’s authentication, detection speed or the protection of member information.

Taken together, these incidents tell a much more useful story than any single breach ever could. They show that super fund data breaches and cyber attacks aren’t confined to one organisation or one type of fund. Industry funds, retail funds and public-sector funds have all been targeted. They also reveal that attackers continue to exploit familiar weaknesses rather than relying on sophisticated new techniques.

But perhaps the most important lesson is that superannuation cyber security is built over time. Strong authentication, faster detection, continuous monitoring and regular testing all work together to reduce risk.

For risk leaders, that means the priority is strengthening the controls that attackers continue to exploit, while also building the visibility to detect and respond more quickly when something does happen.

 

How credential stuffing works against super funds

It’s important to note that credential stuffing is one of the simplest and cheapest cyber attacks to launch, which is exactly why it remains so effective.

The attack works by taking usernames and passwords that have already been exposed in previous data breaches and automatically testing them against other websites and online services. Attackers aren’t guessing passwords or breaking into systems. They’re betting that people have reused the same password across multiple accounts.

That’s the human behaviour credential stuffing exploits.

If a member uses the same password for their super account that they previously used for another online service, and that password has since been exposed in a data breach, attackers can simply try those stolen credentials against the fund’s login page. If they match, the attacker gains access using what appears to be a legitimate login.

One of the most important points to understand is where those credentials came from.

The usernames and passwords used in the 2025 attacks weren’t stolen from superannuation funds. They came from large-scale breaches of other organisations, including the Optus and Medibank data breaches in 2022. Those incidents placed millions of Australians’ personal details into circulation, creating a pool of compromised credentials that attackers continue to use years later.

That’s what makes credential stuffing so challenging. A breach at one organisation can become the starting point for an attack on a completely different organisation.

Because credential stuffing relies on legitimate usernames and passwords, it doesn’t resemble a traditional cyber attack. There may be no malware, no exploited software vulnerability and no obvious attempt to break through a firewall. Instead, there are thousands of login attempts using real credentials, some of which succeed.

That’s why protecting super funds increasingly depends on strong authentication, continuous monitoring and the ability to detect unusual login behaviour. Those are the controls that make credential stuffing significantly harder to execute successfully.

 

Lessons for risk leaders: preventing superannuation fraud

Notably, the attacks on Australia’s super funds highlighted several practical lessons for the industry.

Some reinforce long-standing cyber security principles, while others reflect how attackers are changing their approach. Together, they provide a practical roadmap for strengthening superannuation cyber security and reducing the risk of superannuation fraud.

 

Here are 5 clear lessons: 

Require MFA at login, not just for transactions.


One of the clearest lessons from the April 2025 attacks was the importance of protecting the login itself. Multi-factor authentication (MFA) is highly effective at stopping credential-stuffing attacks because a stolen password alone is no longer enough to gain access. Requiring MFA for every member login closes the door attackers are trying to walk through, rather than waiting until a transaction is attempted.

Monitor for exposed credentials before attackers use them.


The credentials used during the attacks had been exposed in earlier breaches of other organisations. Monitoring for compromised member credentials and forcing password resets before those credentials are used can significantly reduce the opportunity for attackers to succeed.

Look for unusual behaviour, not just failed logins.


Credential stuffing leaves patterns. Large numbers of login attempts, repeated access requests from unusual locations or devices, and unexpected activity involving pension or drawdown accounts can all indicate an attack is underway. Behavioural monitoring helps identify those signals earlier, even when attackers are using legitimate usernames and passwords.

Move beyond SMS-based verification.


SMS authentication remains better than relying on passwords alone, but stronger app-based or phishing-resistant authentication methods provide greater protection against modern attack techniques, including SIM-swapping and social engineering.

Treat detection speed as a security metric.


One of the most important lessons came from an earlier superannuation incident that reportedly took around two months to detect. The longer an attacker remains undetected, the greater the opportunity to access data, move through systems and increase the impact of the attack. Measuring the time between compromise, detection and response should be treated as a core security metric rather than simply an operational target.

Ultimately, protecting members from superannuation fraud and super fund scams relies on layers of defence working together. Strong authentication, credential monitoring, behavioural detection and rapid response all play a role in making attacks harder to execute and easier to stop before members are affected.

The threat is about to get harder: AI-orchestrated attacks

Certainly, the April 2025 attacks showed how much damage a relatively simple cyber attack could cause. The next challenge for superannuation funds is preparing for attacks that become faster, more targeted and increasingly automated.

One of the clearest examples of that big change came in November 2025, when Anthropic revealed what it described as the first documented large-scale cyber attack carried out largely by an AI system rather than human operators.

According to Anthropic, a state-sponsored threat group manipulated its AI coding assistant into targeting around 30 organisations, including financial institutions. The AI reportedly completed 80 to 90 per cent of the work involved in the attack, with humans stepping in only at key decision points. The attackers were also able to bypass the AI’s guardrails by presenting the activity as legitimate security testing.

But Anthropic was careful to point out the limitations. The AI wasn’t fully autonomous and still hallucinated or invented information during parts of the attack.

Even so, the company concluded that AI had significantly lowered the barrier to carrying out sophisticated cyber attacks, putting capabilities once reserved for highly skilled teams within reach of far more attackers.

And that matters for Australian superannuation funds.

These AI-assisted attacks have already been directed at financial institutions overseas. They haven’t yet been reported against Australian super funds, but the April 2025 attacks showed that even relatively straightforward credential-stuffing campaigns can succeed when the right controls aren’t in place.

As AI makes those campaigns faster and more sophisticated, the question becomes less about whether the threat will evolve and more about whether organisations are prepared when it does.

Certainly, the encouraging news is that the fundamentals haven’t changed. AI may increase the speed and sophistication of attacks, but it still relies on familiar opportunities: weak credentials, missing multi-factor authentication, unpatched systems and delayed detection.

Ultimately, organisations that strengthen those foundations today will also be the best prepared for the next generation of threats.

 

APRA’s expectations: MFA and CPS 234

Let’s face it: the April 2025 attacks didn’t come out of nowhere. They were the real-world manifestation of risks APRA had been highlighting for several years.

In July 2023, APRA completed its largest-ever cyber resilience stocktake, assessing more than 300 banks, insurers and superannuation trustees against the information security standard CPS 234. The review identified a range of gaps across the industry, including information security governance, third-party risk management, security testing and incident response capabilities.

Later that year, APRA reinforced that message, warning the industry that, despite CPS 234 having been in effect for several years, many organisations were still falling short of fundamental cyber security expectations.

The attacks that followed in April 2025 highlighted why those concerns mattered.

In July 2025, APRA brought together the superannuation industry for a dedicated cyber resilience roundtable, reinforcing its expectations around authentication, cyber resilience and the protection of member accounts. Rather than introducing a new direction, the roundtable strengthened a message the regulator had been delivering for years.

For superannuation funds, CPS 234 establishes the information security obligations that protect member data, while CPS 230 focuses on operational resilience and ensuring critical services continue during disruption.

Together, the two prudential standards require funds not only to implement appropriate security controls, but also to demonstrate those controls are operating effectively and that critical services can remain resilient during cyber incidents.

 

The supplier-scrutiny aftermath: witnessed evidence, not assurance

The attacks also changed the way superannuation funds assess their suppliers.

For many years, organisations relied heavily on contracts, policies and supplier assurances. Today, the conversation has shifted. Trustees, auditors and regulators increasingly want evidence that security controls have been tested and are operating effectively, not simply documented in an agreement.

That expectation mirrors the broader direction of CPS 234, where organisations are expected to demonstrate that controls are working, both within their own environments and across the third parties that support them.

In practice, that means asking suppliers to demonstrate their controls, not simply describe them. For example:

  • A documented process rather than a statement that one exists.
  • Evidence of a successful system restore.
  • Results from a failover exercise.
  • Findings from a simulated cyber attack or penetration test.

Those examples represent a broader shift from assurance to evidence. The question is no longer whether a supplier says a control exists, but whether they can demonstrate it’s been tested and is operating effectively.

At the same time, supplier independence has also become a bigger consideration.

Many organisations now separate key security responsibilities across different providers to preserve independent oversight. For example, a provider operating the environment may not also be responsible for independently monitoring or assessing its security. That separation helps ensure nobody is, in effect, marking their own homework.

These expectations align closely with CPS 234, which requires organisations to maintain oversight of third-party providers, and they also explain the growing demand for independent assurance reports such as SOC 2 Type II. The common thread is evidence. Organisations increasingly expect suppliers to demonstrate that controls have been tested, observed and are operating effectively, rather than relying solely on contractual commitments.

[Internal link: CPS 234 Hub]

For risk leaders, the practical takeaway is build your evidence before you’re asked for it, and expect your suppliers to do the same.

 

What to do now: a readiness pathway

The attacks on Australia’s super funds highlighted that cyber resilience isn’t built through a single control or technology investment. It comes from strengthening the fundamentals, testing them regularly and being able to demonstrate they work.

A practical readiness pathway can be thought of in three stages: secure, prove and extend.

1. Secure the front door

Credential-stuffing attacks rely on one thing: gaining access with legitimate credentials. Reducing that risk starts with strengthening the member login experience.

Focus on the basics:

  • Enforce multi-factor authentication (MFA) for every member login.
  • Move beyond SMS-only verification to stronger, app-based or phishing-resistant authentication.
  • Monitor for exposed credentials and require password resets before compromised passwords can be used.
  • Detect unusual login behaviour and measure how quickly suspicious activity is identified and investigated.

2. Prove your controls work

Security controls only provide confidence when they’ve been tested. The same applies to the evidence supporting them.

In fact, organisations should be able to demonstrate that critical controls have been exercised, not simply documented.

  • Run simulated cyber attacks and review the findings.
  • Perform system restores and verify they succeed.
  • Rehearse failover procedures before they’re needed.
  • Test backup and disaster recovery capabilities regularly and retain the evidence.

 

3. Extend the same discipline across your ecosystem

Let’s remember, cyber resilience doesn’t stop at your own environment.

So apply the same level of scrutiny to suppliers and critical service providers. Ask for evidence that security controls have been tested, review independent assurance where appropriate and ensure responsibilities are clearly understood.

Aligning those activities with CPS 234 and CPS 230 creates a stronger overall security posture, where protecting members and demonstrating that protection become part of the same ongoing discipline.

Ultimately, to protect superannuation members effectively is to assume an attack will happen, prepare for it, test the preparation and be ready to demonstrate the outcome.

 

How Interactive helps super funds strengthen cyber resilience

Certainly, the recent superannuation attacks highlight an important lesson: cyber resilience isn’t built through a single product or security control.

In fact, it comes from bringing together secure infrastructure, operational resilience, independent assurance and the ability to demonstrate that critical controls are working when they’re needed most.

Importantly, Interactive supports APRA-regulated organisations across that entire journey. Its capabilities span cloud migration, managed cloud, cyber security, data centres, disaster recovery and business continuity, helping organisations build, operate and continually strengthen resilient technology environments.

Through Slipstream Cyber, Interactive also provides independent cyber assurance, giving organisations confidence that critical controls have been tested and are operating effectively.

That combination is particularly valuable for organisations working under CPS 234 and CPS 230, where protecting critical services and demonstrating the effectiveness of security controls go hand in hand.

Interactive supports organisations across key areas including:

  • Multi-factor authentication (MFA) implementation and authentication uplift.
  • Credential exposure monitoring and anomaly detection to help identify credential-stuffing attacks earlier.
  • Cloud migration and managed cloud services.
  • Cyber security and managed detection and response.
  • Data centres and sovereign cloud.
  • Disaster recovery and business continuity.
  • Independent cyber assurance through Slipstream Cyber.
  • Ongoing support for APRA-regulated environments.

As the lessons from the recent attacks have shown, strengthening cyber resilience requires more than responding to a single incident. It requires a long-term approach to improving security capability, reducing risk and continually validating that critical controls are working as intended.

Whether the objective is strengthening multi-factor authentication, improving resilience, preparing for a CPS 234 review or modernising infrastructure, the goal remains the same: helping protect members, strengthen cyber resilience and build confidence that critical services will continue when they’re needed most.

Book a free MFA readiness assessment to identify potential gaps, strengthen your authentication and cyber security posture, and prioritise the next steps towards a more resilient technology environment.

[wpforms id="15231"]
[wpforms id="14210"]
FORM HEADINF
Search by industry
  • All
  • Automotive and Logistics
  • Consumer Packaged Goods
  • Corporate
  • Financial Services
  • FMCG
  • Government
  • Healthcare
  • IT, Data and Software
  • Manufacturing
  • Media and Entertainment
  • Real Estate
  • Retail
  • Superannuation
  • Travel