Home/Incidents/REST and AustralianSuper

REST and AustralianSuper

4 Apr 2025 · National · Finance & Insurance
Data Breach MEDIUM ✓ Verified

What happened

Coordinated malicious credential stuffing campaign targeted major Australian superannuation funds. Threat actors used leaked credential lists to compromise ~600 individual AustralianSuper accounts and an undisclosed number of REST accounts, successfully executing fraudulent member balance transfers.

Incident details

Organisation
REST and AustralianSuper
Date
4 Apr 2025
Attack type
Data Breach
Severity
MEDIUM
Sector
Finance & Insurance
State
National
Records affected
~600 accounts
Threat actor
Unknown

Source

cyberdaily.au ↗
← Back to all incidents