AustralianSuper and rival funds hit by coordinated credential stuffing

Organization
AustralianSuper
Exploit
Credential Compromise
Industry
Pensions and Retirement Savings

Over the weekend beginning Friday, April 4, 2025, several of Australia's largest superannuation funds disclosed that member accounts had been accessed by attackers reusing passwords stolen in earlier, unrelated breaches. AustralianSuper, Australian Retirement Trust, Rest, Hostplus and Insignia Financial all confirmed they had been targeted in what was described as a large and coordinated campaign.

AustralianSuper said criminals may have used up to 600 members' stolen passwords to log into accounts in attempts to commit fraud. Chief member officer Rose Kerlin said four members in the retirement phase lost a combined A$500,000. The fund said it took immediate action to lock affected accounts.

Rest said fewer than 1% of its members were affected, reported as up to about 8,000 accounts, and said no money was transferred out. It shut its MemberAccess portal on detecting the activity. Australian Retirement Trust found unusual login activity but identified no suspicious transactions. Insignia said around 100 MLC Expand accounts were touched with no financial impact, and Hostplus said its investigation was continuing.

The credentials were understood to have been bought on criminal markets after being stolen from unrelated services. The Association of Superannuation Funds of Australia issued a statement but declined to say when it learned the sector was under attack. APRA referred questions to the National Cyber Security Coordinator, and the matter was escalated to the Australian Signals Directorate.

Sources