Coordinated malicious credential stuffing campaign targeted major Australian superannuation funds. Threat actors used leaked credential lists to compromise ~600 individual AustralianSuper accounts and an undisclosed number of REST accounts, successfully executing fraudulent member balance transfers.