“While members of the affected super funds are being urged to check their accounts for suspicious activity, media reports suggest that the threat actors targeted accounts in the pension drawdown phase, as those accounts can request lump-sum withdrawals.”

Attackers used reused passwords to break into accounts at five major Australian superannuation funds. They went after retirees, whose accounts can request lump sums. None of the funds offered protection strong enough to stop recycled passwords. The industry’s response is a toolkit and a working group.