It was announced on 27 April by parent Generation Development Group (GDG) that Generation Life had suffered a “contained cyber incident” via an external service provider and an investigation had been launched, as reported by ifa’s sister brand, Money Management.
At the time, it said there had been “no evidence of impact on Generation Life’s core systems and no evidence of unauthorised transactions”.
In an update on 17 May, Generation Life said it had now become aware that a third party is claiming to have accessed the firm’s data.
“We have since become aware of a third-party naming Generation Life online alongside claims that they have accessed some of our data. Since the incident was first identified, specialist cybersecurity and forensic experts have been continuously engaged to investigate and assess these claims, including this latest development.
“Our services continue to operate as normal, and we have increased our transaction monitoring and controls as a precaution.
“We are working around the clock to investigate data that may have been affected. Where we identify a need for follow-up, we will reach out directly to individuals with clear guidance and support.”
When contacted for clarification on whether any data was successfully accessed, Generation Life said: “Our client investments are secure and our services continue to operate as normal. At this stage, there is no evidence of any unauthorised transactions. We have put increased transaction monitoring and controls in place as a precaution.”
The firm has also contacted Australian Prudential Regulation Authority (APRA), the Australian Cyber Security Centre (ACSC), the Office of the Australian Information Commissioner (OAIC) and National Office of Cyber Security (NOCS) over the incident.
It recommended any clients who receive correspondence purporting to come from Generation Life should contact its dedicated support team at support@genlife.com.au and it has also set up a dedicated phoneline.
“As always, we recommend that our clients, advisers and partners stay vigilant against any unusual or unsolicited communications, including emails, phone calls, SMS, and unfamiliar links.”
Last year, Insignia Financial experienced a cyber attack on its Expand platform, affecting its superannuation members which was understood to be a coordinated cyber attack which affected Insignia, as well as superannuation funds AustralianSuper, Australian Retirement Trust, Hostplus and Rest.




