Your super fund got phished with someone else's password: what the credential-stuffing wave taught 18 million Australians
Your super fund got phished with someone else's password
The April 2025 attacks on Australia's superannuation sector were, by the standards of modern cybercrime, almost boring in their mechanics. No zero-days. No software compromise. Criminals took usernames and passwords stolen years earlier in other breaches — the Optus and Medibank incidents of 2022 were named as source pools — and simply tried them against the login pages of the country's largest retirement funds. That technique is called credential stuffing, and it works for one reason only: people reuse passwords.
It worked often enough to matter. ABC News reported at the time that AustralianSuper, the nation's largest fund, believed criminals had used up to 600 members' stolen passwords in attempts to commit fraud, targeting lump-sum withdrawals; around $750,000 was drained from ten AustralianSuper accounts before the campaign was contained. REST, Hostplus, Insignia and Australian Retirement Trust were also targeted, though no member losses were confirmed at those funds. Cybersecurity experts quoted by the ABC — including RMIT's Professor Matt Warren and CyberCX's Alastair MacGibbon — made the same point repeatedly: the attack was unsophisticated, and it succeeded because parts of a sector holding $4.5 trillion for 18 million Australians did not enforce multi-factor authentication on member logins.
Why super funds were the softest valuable target
Super accounts have properties that make them unusually attractive and, until recently, unusually exposed. On the attractive side: every Australian with a job has one, balances are large, and identity data attached to accounts — names, dates of birth, contact details — feeds the broader identity-theft economy. On the exposed side, several funds historically allowed login with a password alone, and analysis of the sector's breach pattern since 2022 noted that some accounts lacked MFA entirely, that detection of an earlier sector incident reportedly took around two months, and that attackers concentrated on pension and drawdown accounts because they offer the fastest path from access to money movement.
There's also a structural wrinkle worth understanding: super's preservation rules — you generally can't touch the money until a condition of release — are a genuine defence against mass extraction. But the same compulsory, long-horizon design breeds disengagement. Most members check their balance a few times a year, which means an attacker with valid credentials has weeks, not hours, before anyone notices a changed bank detail or a small withdrawal.
The credentials in the April 2025 campaign weren't stolen from the funds themselves. That distinction matters for how you think about your own exposure: your super fund can have flawless server-side security and your account can still be emptied because you reused a password that leaked from a shopping site in 2019.
What the sector did about it
The more interesting story is what happened next, because it's a live experiment in whether Australia's financial sector can coordinate on security faster than attackers can rotate targets.
The Association of Superannuation Funds of Australia (ASFA) ran a sector-wide post-incident review and concluded, in the words of its own leadership, that the sector's response had been hampered by the absence of trusted channels between competing funds — one fund reported suspicious activity to government, but other funds weren't alerted, and public messaging emerged inconsistently through media reporting. The fix is the Superannuation Cyber and Financial Crime Exchange, or SuperFCX: a dedicated threat-intelligence sharing platform for which ASFA sought ACCC authorisation in March 2026, because rival funds sharing operational security intelligence would otherwise risk breaching competition law. The application covers threat trends, tactics and procedures, bypassed security controls, active threat actors and technical indicators — while explicitly excluding pricing, sales and commercial strategy. It parallels the Australian Financial Crimes Exchange the big four banks built in 2016.
ASFA has framed the whole program as the SC3 framework — Superannuation Cyber and Financial Crime Coordination — built on four pillars: the SuperFCX intelligence exchange, a sector incident response playbook developed by cross-sector working groups, annual response exercises (the first, described as the most comprehensive the sector has attempted, ran in September 2026), and standing specialist forums. On the regulatory side, APRA's prudential standards do the heavy lifting: CPS 234 sets information security obligations for funds, and CPS 230, effective from July 2025, adds operational resilience requirements. The Financial Services Council had also moved in 2024 to make MFA compulsory for its members' systems, with implementation expected by July 2026 — though not all targeted funds are FSC members, a gap experts flagged immediately after the April attacks.
The regulator's structural answer — and its limit
It's worth being clear about what none of this fixes. Credential stuffing is an identity problem, and the identity problem starts with breached credentials circulating years after the original incident. The ACS reported in July 2026 that a threat actor claimed to have taken more than 33,900 records from a Sydney-based accounting and SMSF administration firm, including tax file numbers, trustee details and portfolio values — precisely the "complete financial blueprint" combination that fuels the next round of targeted fraud against self-managed super members. The data from breaches already in circulation cannot be recalled; every fresh leak feeds the stuffing lists indefinitely.
That's why the member-side controls are not optional extras. In order of impact:
- Turn on MFA at login on every super account — and every financial account — today. Prefer an authenticator app or hardware key over SMS, because SMS codes are themselves the target of SIM-swap attacks. If a fund offers app-based login approval, use it.
- Make the super password unique. A password manager makes this a one-hour project across your whole financial life. If you reused anything from before 2022 anywhere, assume it's on a criminal list.
- Check contact and bank details on your super account and set up balance alerts if the fund offers them. Detection speed is the variable that turned a contained incident into a $750,000 loss.
- Treat unexpected contact about your super as hostile. Scammers who hold leaked data — your name, TFN, fund, even portfolio value — sound legitimate precisely because the details are real. Call the fund back on the number from its official website, never the one in the message.
There's a hardware angle too. If you're hardening a home office or a small business that touches financial data, physical isolation still earns its keep: keeping the machine that does your banking off questionable networks is simpler with a home DNS appliance kit that filters where your household's devices resolve to in the first place, and a webcam cover 3-pack is the two-dollar answer to the camera on the laptop where your password manager lives. None of it substitutes for unique passwords and MFA — but defence in depth means no single failure is fatal.
What to watch
The April 2025 campaign will be studied for a while as a case study in sector-level response: the losses were small relative to the system's size, the attackers used no novel techniques, and the lasting damage was to trust — which ASFA's own review conceded took a reputational hit when communication failed. Whether SuperFCX clears the ACCC and whether the sector's first large-scale exercise in September 2026 produces real coordination will tell us whether "collective resilience" is a real capability or a slide deck. For members, the honest summary is this: the system defended most accounts, but the accounts that fell were defended by nothing but a reused password. That part is still yours to fix.
This article is general information only and not financial or legal advice.