Latest / Tech Talks With Kinsoft / Australian Super Fund Cyberattack: Prevention and Response
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. This is the
- 0:02show where we try to cut through some of the
- 0:04noise, the digital static, and, you know, get
- 0:06straight to the insights that matter. And lately,
- 0:10you might have seen some headlines, making waves,
- 0:13stories that maybe hit a bit close to home, especially
- 0:16when they're talking about your financial security
- 0:18in, well, this very digital world we live in.
- 0:22Yeah, absolutely. So today we're really diving
- 0:25into a situation that's pretty critical. It's
- 0:28impacted a lot of Australians, possibly even
- 0:30your own retirement savings. We're talking about
- 0:32a major cyber incident that hit the Australian
- 0:36superannuation sector and crucially, what it
- 0:39all means for your financial future. It is. And
- 0:42it's understandable that it's caused a lot of
- 0:44concern. So our mission today really is to unpack
- 0:47what actually happened, why it's so significant
- 0:50for you, the listener, and maybe most importantly,
- 0:52give you some concrete practical steps you can
- 0:55take, things you can do to safeguard your financial
- 0:57future. Right. We want to bring clarity, some
- 0:58useful insights, not just, you know, drown everyone
- 1:01in tech jargon. Exactly. And the urgency here,
- 1:04why we're covering this now, is this isn't just
- 1:06theory anymore, is it? No, not at all. Around
- 1:08April 4th, 2025. Several really big Australian
- 1:13super funds. We're talking Australian super,
- 1:15Australian Retirement Trust, Host Plus, Rest,
- 1:18CBUS, Insignia. They were all hit by what looks
- 1:21like a coordinated cyber attack. Now, before
- 1:24we go any further, just a quick point. If you
- 1:27happen to be a StockSpot super customer, good
- 1:30news for you. Your fund was not caught up in
- 1:32this specific breach. So you can breathe a little
- 1:36easier on that front. That's definitely reassuring
- 1:38for them. OK, so let's get into the mechanics.
- 1:42What actually happened here? What was the attack
- 1:44method? Because it wasn't like some super sophisticated
- 1:47complex hack deep inside their systems, was it?
- 1:50No, not really. It was surprisingly simple, actually,
- 1:53but very effective. It's a technique called credential
- 1:56stuffing. Have you heard much about that? I've
- 1:58heard the term, but maybe you could break it
- 1:59down for us. How does that actually work? Sure.
- 2:01So what's kind of fascinating. and a bit scary,
- 2:04is how straightforward it is. Imagine hackers
- 2:07get their hands on a huge list, maybe millions
- 2:10of usernames and passwords. Okay. These usually
- 2:13come from past data breaches, you know, completely
- 2:15different websites maybe breached years ago.
- 2:18Could be an old social media site, an online
- 2:20shop you used once, a forum you forgot about.
- 2:23Right, those old breaches we hear about. Exactly.
- 2:26So the hackers take this massive list and they
- 2:29just... automate the process of trying these
- 2:31logins, stuffing them into other websites. In
- 2:34this case, the login pages for these super funds.
- 2:36Wow. So hang on. If I use the same password for
- 2:39my super account, let's say. as I did for, I
- 2:42don't know, some stream service that got hacked
- 2:44five years back, that old compromised password
- 2:47could suddenly unlock my retirement savings.
- 2:49That's precisely it. It's quite a sobering thought,
- 2:51isn't it? It really is. So the vulnerability
- 2:53wasn't necessarily a flaw deep within the Superfund's
- 2:56own security, but more exploiting our habits,
- 2:59our password reuse. Exactly. It really shines
- 3:02a light on how often the weakest link isn't the
- 3:05sophisticated tech, but, well. Us. Or individual
- 3:08security practices. Yeah. You can build the strongest
- 3:11digital fortress. But if someone reuses a key
- 3:14that's already been stolen from somewhere else,
- 3:16somewhere less secure, well, that fortress door
- 3:19just got opened. And the impact wasn't just theoretical,
- 3:22sadly. Australian Super, they confirmed 600 members
- 3:25had their accounts accessed. But here's the bit
- 3:28that really stands out. Specifically, 10 of those
- 3:32members lost a combined a $750 ,000. That's almost
- 3:36half a million U .S. dollars. Ouch. Now, good
- 3:40news, if you can call it that, is Australian
- 3:42Super did fully reimburse those members. That's
- 3:44important. Definitely. But the information we
- 3:46have suggests something critical about how that
- 3:48was funded. Since these industry super funds
- 3:51don't operate like banks with their own capital
- 3:53reserves, the reports say these losses were covered
- 3:56using other members' fees. Right. And when you
- 3:58hear that. Well, it makes you think, doesn't
- 4:01it? About the bigger picture, the shared pool
- 4:04of funds. It absolutely raises a big question.
- 4:07You know, what was different about the funds
- 4:08where money wasn't actually stolen? Because we
- 4:12know Rest Super, for example, they confirmed
- 4:14suspicious activity on 8 ,000 accounts. Way more
- 4:17than Australian Super. 8 ,000. Wow. Yeah, but
- 4:20critically, no money was lost. Host Plus also
- 4:24said no financial losses. Australian Retirement
- 4:28Trust hadn't found suspicious transactions when
- 4:30this was reported. So it suggests that getting
- 4:32in was one thing. Right. But actually getting
- 4:34money out was another challenge, thankfully,
- 4:37in many cases. And that difference, looking at
- 4:39where money wasn't lost, seems to point directly
- 4:41at one key thing. Multi -factor authentication
- 4:44or MFA? Ah, yes. The crucial layer. That $750
- 4:49,000 that was stolen. The sources we looked at
- 4:52explicitly say it could likely have been prevented
- 4:54if those funds had offered and importantly enforced
- 4:562FA, which is just another term for MFA on those
- 4:59accounts. Exactly. It feels like such a basic
- 5:01security step that just wasn't there for some.
- 5:03It really is fundamental in today's world. MFA,
- 5:07you know, at its heart, it's just about meeting
- 5:10something extra besides your password to prove
- 5:13it's really you. Like a second lock on the door.
- 5:16Precisely. Think of it in categories. There's
- 5:18something you know that's your password. Then
- 5:20something you have, like a code from an app on
- 5:22your phone or maybe a little physical security
- 5:24key. And something that's biometrics, like a
- 5:28fingerprint or face scan. The key is they are
- 5:31independent. So even if a hacker gets your password,
- 5:35they still hit that second wall. They need that
- 5:37other factor. And what about SMS codes, you know,
- 5:40where they text you a number? Lots of places
- 5:42use that. Yeah, they do. And look, it is a form
- 5:45of MFA and it's certainly better than just a
- 5:47password, but it's increasingly seen as, well,
- 5:51outdated and vulnerable. Criminals have got pretty
- 5:54clever at intercepting those SMS codes or worse,
- 5:57they do something called a SIM swap attack. Right.
- 5:59I've heard about that. That sounds nasty. It
- 6:01is. They basically trick your phone company into
- 6:04transferring your number to their phone. So when
- 6:07you try to log in, that verification code goes
- 6:10straight to the bad guy. Oh, wow. OK. Yeah. It's
- 6:13a surprisingly effective workaround for SMS MFA.
- 6:16That's why security pros really push for authenticator
- 6:19apps like Google Authenticator or Authy or even
- 6:23better, those physical hardware keys. They're
- 6:25much harder to compromise. So this whole incident
- 6:27wasn't just about. Stolen passwords and missing
- 6:30MFA, then. The information suggests it exposed
- 6:33wider issues, too, like weaknesses in internal
- 6:36controls, financial processes. Exactly right.
- 6:39If you look at the bigger picture, it's about
- 6:41the whole chain of trust and verification inside
- 6:44the organization. A cyber incident might start
- 6:47with stolen logins, an IT problem, you could
- 6:49say. But the impact often ripples right into
- 6:51finance operations. The problem wasn't just that
- 6:54hackers got access. It was that once they were
- 6:56in, the actual payment systems, the workflows
- 6:59for moving money, didn't have enough checks and
- 7:01balances built in. They lacked the layers needed
- 7:05to maybe flag, escalate, pause, or just completely
- 7:08stop a suspicious transaction before the money
- 7:10actually left the building. So things like needing
- 7:13a second person to approve a large withdrawal
- 7:16or... Extra checks for unusual activity, that
- 7:19kind of thing. Precisely. Yeah. We talk about
- 7:21segregation of duties or multi -person approval
- 7:23in finance. Yeah. Even if someone bypasses the
- 7:26first login hurdle, these internal checks should
- 7:29kick in. They should be separate, require maybe
- 7:32another human or another system verification
- 7:34before big sums can move. That makes total sense.
- 7:37It's like even if someone picks the first lock
- 7:39on the vault door, there should be another lock
- 7:41inside, maybe needing a different key or a manager's
- 7:44approval before you can actually get to the cash.
- 7:46That's a great analogy. And it points to a deeper
- 7:49challenge, which is modernizing some of these
- 7:51older financial systems and processes. Right.
- 7:53These institutions often have processes built
- 7:56for a slower, perhaps more manual world. And
- 7:59now they're facing these incredibly fast automated
- 8:02cyber attacks, trying to rely on old methods
- 8:05like. say, phoning a member back to double check
- 8:08a large withdrawal request. Yeah, that sounds
- 8:10slow. It's too slow. Just can't keep pace with
- 8:13automated fraud attempts happening in milliseconds.
- 8:15Plus, it introduces delays and, frankly, the
- 8:18risk of human error, especially under pressure.
- 8:20That whole chain of trust needs updating for
- 8:22the digital age. OK, so we've painted a picture
- 8:25of how these attacks work and the vulnerabilities,
- 8:28both user level and institutional. It really
- 8:30underscores that we as individuals need to be
- 8:32proactive. So let's shift to empowerment. What
- 8:35can you listening right now actually do to put
- 8:38a stronger shield around your super and frankly,
- 8:41all your important online accounts? It might
- 8:43feel a bit daunting, but there are definite steps.
- 8:45Absolutely. And the good news is many of the
- 8:48most powerful defenses are things you can control
- 8:50yourself and they aren't necessarily super complicated.
- 8:53Let's run through five key practical steps drawn
- 8:56right from the lessons of this breach that you
- 8:58should really think about implementing. Okay,
- 9:00let's hear it. First, and honestly, I can't stress
- 9:02this enough, use strong, unique passwords. We've
- 9:06seen how reusing passwords is just, well, asking
- 9:09for trouble. It's the number one way in, it seems.
- 9:12It often is. So you need a good mix of letters,
- 9:15numbers, symbols, and critically, a different
- 9:19strong password for every single important account.
- 9:21especially financial ones. Please don't use password
- 9:24123 or your pet's name everywhere. Yeah, probably
- 9:27not the best. My top tip here, get a good password
- 9:30manager. Seriously. They generate complex, unique
- 9:33passwords for you, store them securely, and often
- 9:36fill them in automatically. Takes the hassle
- 9:38out of it and massively boosts your security.
- 9:41Good advice. What's number two? Number two, and
- 9:44just as crucial. enable multi -factor authentication,
- 9:49MFA, wherever it's offered. We talked about this.
- 9:51If you're super fine, your bank, your email,
- 9:53anything important offers MFA or 2FA, switch
- 9:56it on. Now, today. Don't delay. Don't delay.
- 10:00It's probably the single biggest security upgrade
- 10:02you can make. Even if someone does get your password
- 10:05somehow, MFA is designed to stop them cold. And
- 10:08again, if you have a choice, aim for an authenticator
- 10:11app or hardware key over SMS. if possible. Right.
- 10:14Stronger options. Okay. Number three. Third,
- 10:16regularly monitor your accounts. Now, I don't
- 10:19mean obsessively checking every five minutes.
- 10:21That's not healthy. No, but make it a habit maybe
- 10:24once a month or even quarterly. Just log into
- 10:26your super, your bank accounts, credit cards,
- 10:28just scan for anything weird, unauthorized transactions,
- 10:31changes to your address or phone number you didn't
- 10:33make. Okay. If you see anything suspicious, anything
- 10:35at all, report it immediately. Don't wait. Quick
- 10:38action really can make a huge difference. Good
- 10:40habit to build. What's fourth? Fourth, is about
- 10:43being savvy. Watch out for the phishing scams.
- 10:47Criminals are always trying to trick us. You
- 10:49get those fake emails, text messages, maybe even
- 10:51phone calls, trying to panic you into giving
- 10:53up logins or personal info. Yeah, they can look
- 10:56very convincing sometimes. They really can. Be
- 10:59super cautious of anything asking you to click
- 11:01weird links, download attachments, or provide
- 11:04sensitive data, especially if it sounds urgent.
- 11:07Remember, your Superfund or bank is very unlikely
- 11:10to ask for your full password or login details
- 11:13via email. If you're ever unsure, don't click
- 11:16the link. Go directly to their official website
- 11:19yourself or call them using a number you know
- 11:21is correct. Always go direct. Got it. And the
- 11:23last one, number five. And finally, number five.
- 11:26Keep your contact details up to date. Seems simple,
- 11:29but it's important. Make sure your email address
- 11:31and phone number on file with your Superfund,
- 11:33bank, everyone are current. Why is that so critical?
- 11:37Because that's how they'll send you security
- 11:38alerts. If there is suspicious activity, like
- 11:41a login from a strange location or a password
- 11:43change request, they'll notify you using those
- 11:46details. If they're wrong, you won't get the
- 11:48alert and you lose that crucial early warning.
- 11:51Ah, okay. It makes sense. Vital for getting those
- 11:54alerts quickly. Exactly. So those are great preventative
- 11:57steps. But let's say... Worst case scenario,
- 12:01despite your best efforts, you think, oh, something's
- 12:03wrong. I suspect my account has been compromised.
- 12:06We know acting fast is key. What's the absolute
- 12:09first move? Right. If you suspect a breach, don't
- 12:13panic, but act decisively. The very first thing.
- 12:16Contact your super fund or bank immediately.
- 12:19Find their official fraud hotline number. Don't
- 12:22just Google it. Get it from their official site
- 12:23or your statements. Okay. Call them. Tell them
- 12:26you suspect a compromise. Explain why maybe you
- 12:28saw a weird email, a transaction you don't recognize,
- 12:31whatever it is. Ask them to lock the account
- 12:33down right away and start an investigation. Lock
- 12:35it down first. Got it. What next? Second, change
- 12:38your password for that account immediately. And
- 12:41crucially, if you've been naughty and reused
- 12:43that password anywhere else, you need to change
- 12:46it on all those other accounts too. Right away.
- 12:49This is where that password manager habit really
- 12:51pays off because it stops one breach turning
- 12:54into many. Stops the domino effect. Makes sense.
- 12:57And third. Third, be proactive. Check all your
- 13:01other financial accounts, bank accounts, credit
- 13:03cards, any investment accounts. Look for any
- 13:06suspicious activity there, too. If criminals
- 13:08got into one account or got hold of some of your
- 13:11personal details, they might try to use that
- 13:13information elsewhere or even try identity theft.
- 13:16Right. Check everything. Yeah. Just be vigilant
- 13:18across the board. Catching things early can save
- 13:21you a massive amount of time, money, and frankly,
- 13:24stress down the line. Cleaning up after a breach
- 13:26is not fun. Prevention and quick response are
- 13:29definitely the way to go. Okay, so wrapping this
- 13:31up, what we've discussed today really throws
- 13:34a spotlight on, well, two main things, doesn't
- 13:36it? Firstly, how vital our own personal cyber
- 13:39hygiene is, strong, unique passwords, always
- 13:42using MFA. Absolutely fundamental. But secondly,
- 13:46it also shows the bigger picture. The importance
- 13:49of robust financial controls within these institutions
- 13:52and how quickly modern automated attacks can
- 13:56find the cracks in older, perhaps less agile
- 13:58systems. It really does. And maybe it leaves
- 14:01us with a final thought or perhaps a question
- 14:03to ponder. You know, while the criminals are
- 14:05constantly shifting, constantly evolving their
- 14:07tactics. Always seem to be one step ahead sometimes.
- 14:09It can feel like that, but. Our defenses, both
- 14:13personal and institutional, they have to evolve
- 14:15too. The next attack might look different, maybe
- 14:18target something else entirely, but chances are
- 14:20it'll exploit similar kinds of gaps, gaps in
- 14:23process, gaps in technology, gaps in awareness
- 14:25if we leave them open. So this incident, it's
- 14:29a really powerful reminder, isn't it? To think
- 14:31critically about the security of all our online
- 14:33activity, not just super. It's an ongoing thing,
- 14:36vigilance, adaptation. A continuous process.
- 14:39Well said. Thank you for tuning in to Tech Talks
- 14:41with Kinsoft. We genuinely hope this discussion
- 14:43has given you some valuable insights and, more
- 14:47importantly, some actionable advice to help you
- 14:49better protect your digital self. We hope so,
- 14:51too. Stay safe out there. And look, for any of
- 14:55your security and IT needs, maybe you're thinking
- 14:57about how to better protect your business after
- 14:59hearing this or just want to understand these
- 15:01threats more deeply, we absolutely encourage
- 15:03you to visit us at www .kinsoft .com .au.