We recently reviewed an article from SecurityBrief covering the 2025 superannuation cyber incidents, along with updates relating to APRA’s CPS 230 operational risk standard. We believe this is an important topic for our audience, particularly as it highlights how credential theft continues to put Australians’ retirement savings at risk.
With cyber threats evolving and regulatory expectations rising, this is a timely reminder for the superannuation sector to reassess how member accounts are protected. Below, we explore what these developments mean and why stronger authentication measures — including passkeys — are gaining attention across financial services.
Superannuation remains one of Australia’s most trusted financial pillars, with more than $3.7 trillion in assets under management. For millions of Australians, it represents long-term financial security and retirement stability.
But as superannuation funds continue expanding their digital services, they are also expanding their attack surface.
Several high-profile incidents in 2025 demonstrated just how vulnerable retirement savings can be when identity security is weak.
What Happened — And Why It Matters
In 2025, a cyberattack targeting multiple Australian superannuation funds led to hundreds of thousands of dollars being stolen. Funds affected included Australian Retirement Trust, AustralianSuper, Hostplus, Rest, and Insignia.
Attackers did not exploit complex system vulnerabilities.
They exploited compromised and reused passwords.
Using stolen credentials, cybercriminals gained unauthorised access to member accounts. This type of attack highlights a recurring issue across financial services: identity security remains the weakest link.
These incidents underscore a broader reality — superannuation funds hold not only significant financial assets, but also highly sensitive personal data. That combination makes them attractive targets.
The Problem with Legacy MFA
Many organisations, including financial institutions, continue to rely on legacy multi-factor authentication (MFA), particularly SMS-based one-time passcodes (OTPs).
While these methods were once considered sufficient, modern attack techniques have evolved:
- SIM swapping
- Real-time phishing proxy attacks
- Malware-in-the-browser attacks
- MFA fatigue and session hijacking
SMS OTPs can be intercepted, socially engineered, or bypassed. When attackers already possess valid credentials, legacy MFA often provides only a thin additional layer of defence.
Despite global momentum toward passwordless authentication, adoption within Australia’s superannuation sector has been relatively slow.
Why Passkeys Change the Equation
Passkeys represent a modern, phishing-resistant approach to authentication.
Instead of relying on passwords and SMS codes, passkeys use device-bound cryptographic credentials. This removes password reuse risk and makes credential interception significantly more difficult.
Benefits include:
- Phishing resistance
- Elimination of shared or reused passwords
- Reduced reliance on SMS infrastructure
- Improved login experience
- Lower risk of account takeover
From a user perspective, passkeys can simplify login processes. There is no need to remember complex passwords or retrieve codes from secondary devices.
For members who may only access their superannuation accounts occasionally, simplicity and clarity are important.
Regulatory Momentum: APRA’s CPS 230
Regulatory expectations are also rising.
As of July 1, APRA’s CPS 230 operational risk management standard places stronger emphasis on resilience and control environments within financial institutions.
For superannuation funds, this means demonstrating not only compliance, but proactive management of operational and information security risks.
Phishing-resistant MFA directly aligns with CPS 230 objectives by:
- Reducing credential compromise risk
- Strengthening access controls
- Minimising reliance on vulnerable authentication methods
- Improving operational resilience
Boards and executives are increasingly being asked to justify cybersecurity investments. Strong authentication controls are one of the most visible and measurable safeguards available.
Security and Customer Experience Can Co-Exist
A common misconception is that stronger security inevitably creates friction.
Modern authentication challenges that assumption.
Passkeys remove the need to remember complex passwords or wait for SMS codes. Instead, they allow secure authentication through built-in device mechanisms such as biometrics or hardware-based credentials.
For members, this means:
- Fewer login frustrations
- Reduced password reset requests
- Stronger protection against phishing
For internal staff managing sensitive member data, hardware-based authentication also reduces exposure to credential theft and phishing campaigns.
Security improvements can therefore enhance operational efficiency as well as protection.
Rebuilding Trust Through Proactive Action
Trust is fundamental to Australia’s superannuation system. Repeated data breaches and identity-based attacks erode that trust.
Moving beyond reactive security measures is essential.
Investing in phishing-resistant authentication sends a clear signal that protecting member savings is a priority.
Transparency also matters. When members understand how their data and funds are protected, confidence increases.
A CSB Perspective
At CSB, we see identity security becoming the central control point across financial services.
Passwords and SMS-based MFA were designed for an earlier threat landscape. Today’s attacks are faster, automated, and often identity-driven.
Superannuation funds, given the scale of assets and personal data involved, cannot afford to rely on legacy controls alone.
Practical considerations for organisations include:
- Assessing exposure to credential reuse
- Reviewing MFA configuration and push-based authentication risks
- Evaluating readiness for phishing-resistant MFA adoption
- Aligning identity controls with CPS 230 requirements
- Ensuring internal staff access is equally protected
Strong authentication is not a silver bullet, but it significantly reduces the most common pathway into financial accounts.