affected by a recent cyber incident.
On 27 April, the firm announced it had suffered a cyber incident involving an unauthorised party gaining access to part of our system via a third-party service provider.
Subsequently, on 17 May, it informed the market that it had become aware of a third-party naming Generation Life online alongside claims that they had accessed some of its data, although it reassured investments remained secure.
Having conducted an investigation with specialist cybersecurity and forensic experts which reviewed the data, it said on 24 June that it is in the process of notifying individuals whose personal information has been affected.
“Following a detailed investigation and data review, we are now in the process of notifying individuals whose personal information has been confirmed as impacted, in line with our obligations.
“This relates to a limited number of individuals, and we are committed to providing them with the appropriate support and guidance to protect their information.”
The investigation confirmed that there was no access to the core systems responsible for investment activities or evidence of any unauthorised transactions, client investments and funds have not been impacted, and that its services continue to operate as normal.
There was also no impact to Evidentia Group or Lonsec Research & Ratings systems.
Generation Life said it has increased its transaction monitoring and controls as a precaution and has notified APRA , the Office of the Australian Information Commissioner (OAIC) as well as the Australian Cyber Security Centre (ACSC) and the National Office of Cyber Security (NOCS).
Last year, Insignia Financial experienced a cyber attack on its Expand platform, affecting its superannuation members which was understood to be a coordinated cyber attack which affected Insignia, as well as superannuation funds AustralianSuper, Australian Retirement Trust, Hostplus and Rest.




