X
  • About
  • Advertise
  • Contact
Get the latest news! Subscribe to the ifa bulletin
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
No Results
View All Results
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
No Results
View All Results
No Results
View All Results
Home News

Super fund suffers broad phishing attack

Around 50,000 member records were impacted by the breach that took place earlier this month.

by Jon Bragg
May 31, 2022
in News
Reading Time: 3 mins read
Share on FacebookShare on Twitter

Spirit Super has confirmed that 50,000 of its member records have been compromised following what the super fund described as a broad phishing attack campaign.

The member records date back to 2019 and 2020 and contain names, addresses, ages, emails, phone numbers, account numbers and balances.

X

However, according to the fund, the records do not include dates of birth, government identification numbers such as tax file numbers or driver’s licence details, or any bank account information.

The $26 billion industry super fund with 325,000 members said that members’ money remained safe following the incident and all those affected had been contacted.

“The breach was the result of an email phishing activity rather than a system error, regardless, we are taking all reasonable steps to prevent this from happening again,” Spirit Super said.

“Please be assured investigations to date indicate that accounts have not been compromised. We have increased the levels of security to ensure our members’ accounts remain safe. Our investigation will continue.”

Explaining the incident, Spirit Super said that an email account of one of its staff members was compromised on 19 May.

“In short, it was human error during a malicious email attack posing as official correspondence,” the fund said.

“This was not the result of a material security control weakness or technology failure. The malicious email resulted in a staff member’s password being compromised.”

Despite employing multi-factor authentication in addition to usernames and passwords, the super fund said the additional layer of protection had been thwarted by the attacker.

“Phishing attacks such as this are becoming increasingly sophisticated and common,” said Spirit Super.

“We have a skilled internal team focused on cyber security and protecting your information. This team detected the compromised account and acted quickly to contain and limit the impact of the breach. No further accounts or systems were impacted.”

Spirit Super said that it did not believe the attack was targeted and it remained unclear whether the attacker was aware that they had access to the personal information.
Members have been told to remain vigilant to unsolicited emails, text messages or phone calls and to report any suspicious matters to the ACCC’s Scamwatch.

Those impacted by the breach have also been encouraged to not publicly share that their personal information may have been compromised to help avoid being targeted.

“Spirit Super takes your privacy and the security of our information and systems extremely seriously. Online threats are constantly evolving, and no organisation can completely mitigate these risks,” the fund said.

“We continue to invest in internal capability, technology, improved internal processes, and staff training to reduce the likelihood and severity of future data breach events.”

Related Posts

Image/Financial Services Council

Legislative fix for drafting error vital to avoid more adviser losses: FSC

by Keith Ford
November 12, 2025
0

The Financial Services Council has warned that unless an omnibus bill is passed before 1 January 2026, an “inadvertent drafting...

Clearer boundaries between different levels of support needed to help client outcomes

by Alex Driscoll
November 12, 2025
0

Touching on this issue on the ifa Show podcast, Andrew Gale and Stephen Huppert from the Actuaries Institute’s Help, Guidance...

Image: Who is Danny/stock.adobe.com

Open banking platform aims to provide advisers ‘verified financial truth’ for clients

by Keith Ford
November 12, 2025
0

Fintech platform WealthX is using its partnership with Padua to “bridge critical gaps between broking and advice” through a new...

Comments 2

  1. Anonymous says:
    3 years ago

    These breaches are an existential threat to members. Cyber security is paramount.

    Reply
  2. Anonymous says:
    3 years ago

    Hrmm so we have ASIC taking a licensee (RI Advice) to task and fining them $750k for inadequate cyber security. Let’s see what ASIC do to their industry super mates. I am betting a slap on the wrist, and away they go.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Private Credit in Transition: Governance, Growth, and the Road Ahead

Private credit is reshaping commercial real estate finance. Success now depends on collaboration, discipline, and strong governance across the market.

by Zagga
October 29, 2025
Promoted Content

Boring can be brilliant: why steady investing builds lasting wealth

Excitement sells stories, not stability. For long-term wealth, consistency and compounding matter most — proving that sometimes boring is the...

by Zagga
September 30, 2025
Promoted Content

Helping clients build wealth? Boring often works best.

Excitement drives headlines, but steady returns build wealth. Real estate private credit delivers predictable performance, even through volatility.

by Zagga
September 26, 2025
Promoted Content

Navigating Cardano Staking Rewards and Investment Risks for Australian Investors

Australian investors increasingly view Cardano (ADA) as a compelling cryptocurrency investment opportunity, particularly through staking mechanisms that generate passive income....

by Underfive
September 4, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Poll

This poll has closed

Do you have clients that would be impacted by the proposed Division 296 $3 million super tax?
Vote
www.ifa.com.au is a digital platform that offers daily online news, analysis, reports, and business strategy content that is specifically designed to address the issues and industry developments that are most relevant to the evolving financial planning industry in Australia. The platform is dedicated to serving advisers and is created with their needs and interests as the primary focus.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About IFA

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • News
  • Risk
  • Opinion
  • Podcast
  • Promoted Content
  • Video
  • Profiles
  • Events

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Opinion
  • Podcast
  • Risk
  • Events
  • Video
  • Promoted Content
  • Webcasts
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited