Is it a scam? How it works
Superannuation

The account nobody checks: superannuation scams in Australia

Updated 7 August 2026 · 9 min read · Written in Australia
The short answer: never give your tax file number or member number to anyone who contacted you — your fund already has both. And no real super fund ever emails you a link to its login page. If a message worries you, close it and log in the way you normally do.

You would notice $500 missing from your bank account by lunchtime. You might not notice $80,000 missing from your super for a year.

That gap is the entire opportunity. Superannuation is the largest balance most Australians have and the one they look at least — often once a year, when the statement arrives. Criminals worked this out some time ago.

What actually happened in 2025

In April 2025, several major funds — AustralianSuper, Rest, Hostplus, Australian Retirement Trust and Insignia among them — were hit by a coordinated attack. It is worth understanding precisely, because the popular version is wrong.

The funds were not, for the most part, hacked. The passwords were — somewhere else. The technique is called credential stuffing: criminals take username and password pairs leaked from unrelated breaches — a retailer, a forum, an airline — and try them, automatically, against super fund logins. It only works on reused passwords.

AustralianSuper confirmed around 600 accounts were accessed and four members lost $500,000 (other reporting put the total at $750,000, which the fund committed to reimbursing). Rest reported about 8,000 accounts where personal information was accessed, with no money transferred. The attackers concentrated on pension drawdown accounts, which allow lump-sum withdrawals.

Afterwards, APRA pointed to persistent weaknesses in authentication practices across the superannuation industry, and reminded funds of their obligations under Prudential Standard CPS 234. ASIC issued a further call for financial firms to strengthen cyber resilience in May 2026.

The practical lesson for you is small and unglamorous: a password used nowhere else defeats this attack entirely.

The four messages that turn up

1. “Unlock your super early”

What arrives“You may be eligible to access up to $20,000 from your superannuation before preservation age. Free eligibility check — approval within 48 hours. Application fee $550.”

Early access exists in narrow circumstances defined by law, applied for through the ATO or your fund directly, and never through a service charging a fee to arrange it. Preservation age is 60 for anyone born after 1 July 1964, and no change is planned — so any message claiming the rules are about to change is simply false. Illegal early release also lands you with serious tax penalties, on top of losing the money.

2. The self-managed fund rollover

A pitch to roll your balance into an SMSF that will earn far more — usually in crypto, usually with a guaranteed return. Sometimes the SMSF is created in your name using your own identity documents. Once your super is inside a fund the criminal controls, it is gone in the ordinary way, not the recoverable way.

3. The free review call

What it sounds like“I'm just doing a free review of your super — I can see you've got a couple of accounts, we can consolidate those and save you the duplicate fees. I'll just need your member number and TFN to bring it up.”

Friendly, plausible, and the request at the end is the whole call. If you want your accounts consolidated you can do it yourself through myGov linked to the ATO, in a few minutes, for nothing.

4. “Your super is at risk” — after a breach in the news

This one follows every publicised data breach, and it is the most dangerous because the fear is real and current. A message says your superannuation is affected and offers to move your balance somewhere “protected” while it is sorted out.

There is no safe holding account. No fund, bank or government agency relocates your money for safekeeping. Anyone offering to is taking it. This is the same “safe account” script used in bank scams, pointed at a bigger balance.

The one rule worth remembering

Never give your tax file number or member number to anyone who contacted you. Your own fund already has both. A tax agent or a new employer may legitimately need your TFN — but they are people you approached. The direction of contact is the whole test, and it needs no expertise to apply.

Ten minutes, today

  1. Log in the way you normally do — the app, or by typing the address yourself. Never through a link in a message, including for a password reset.
  2. Give it a password used nowhere else. This is the one that defeats credential stuffing outright.
  3. Turn on two-factor authentication if your fund offers it.
  4. Check the contact details on file. An email or mobile you do not recognise means the alerts are going to someone else. That is the quiet sign of a compromised account.
  5. Look for rollovers, withdrawals or cancelled insurance you did not request. Criminals sometimes cancel insurance to free up a larger balance to take.

If something has already happened

  1. Ring your fund on the number from your statement or their website — not one in the message.
  2. Change the password, there and anywhere else you reused it.
  3. Report it to ReportCyber at cyber.gov.au and Scamwatch at scamwatch.gov.au.
  4. Call IDCARE on 1800 595 160 — Australia's free national identity and cyber support service.
  5. Check your myGov and ATO details too. The same credentials often unlock more than one door.

Common questions

Was my super fund hacked?

In the April 2025 attacks, mostly not. The technique was credential stuffing: criminals took username and password pairs leaked in unrelated breaches - a retailer, a forum, an airline - and tried them against super fund logins. It works on reused passwords, so the fund's systems were not necessarily breached at all. AustralianSuper confirmed around 600 accounts were accessed and four members lost $500,000; Rest reported about 8,000 accounts where personal information was accessed but no money moved. APRA's assessment afterwards pointed to persistent weaknesses in authentication practices across the industry.

What is the single clearest rule for super scams?

Never give your tax file number or member number to anyone who contacted you. Not by email, not by text, not on a call you did not place. Your own fund already has both. A tax agent or a new employer may legitimately need your TFN - but those are people you approached. The direction of contact is the whole test.

Can I really access my super early?

Only in narrow circumstances defined by law, applied for through the ATO or your fund directly, and never through a service that charges a fee to arrange it. Preservation age is 60 for anyone born after 1 July 1964 and no change is planned. Any message claiming the rules are about to change, or offering to unlock your super for an upfront fee, is a scam. Illegal early release also exposes you to serious tax penalties on top of losing the money.

Someone rang offering a free review of my super. Is that legitimate?

Treat an unsolicited call about your super as a scam until proven otherwise. The 'free review' or 'consolidation' pitch is a long-running script, and it usually ends with a request for your member number and TFN, or a form that rolls your balance into a fund the caller earns from. Hang up and ring your own fund on the number from your statement. If you want your accounts consolidated, you can do it yourself through myGov linked to the ATO, at no cost.

What does a real super fund never do?

It never sends you a link to a login page and asks you to sign in there. AustralianSuper's own guidance is to navigate directly to the login page yourself, including for password resets, and not to respond directly to emails claiming to be from them. A real fund also never asks for your password, and never asks you to move your balance somewhere for safekeeping.

There was a data breach in the news. Now I'm being told my super is at risk.

That sequence is itself a scam pattern. After every publicised breach, messages appear claiming your superannuation or bank account is affected and offering to move your balance to a 'protected' or 'safe' account. There is no such thing. Funds do not relocate your money to a holding account, and anyone offering to is taking it. Check your account by logging in the way you normally do.

How would I even know if money had gone?

This is the uncomfortable part, and the reason super is targeted. Most people check their super once or twice a year. A withdrawal or rollover can sit unnoticed for months. Log in today, and check three things: your contact details, especially the email and mobile on file; any recent rollovers or withdrawals you did not request; and your insurance, which criminals sometimes cancel to free up a larger balance.

What should I do right now to protect it?

Turn on two-factor authentication if your fund offers it. Use a password that is not used anywhere else - that alone defeats credential stuffing. Check the contact details on your account so alerts reach you rather than a criminal. And log in through the app or by typing the address yourself, never through a link in a message.

Read next

Not sure about a message about your super?

Forward it — the email, the text, or just type what the caller said — and Is it a scam? answers in seconds, in plain English. One saved number, for you and the people you'd normally ring.

See how it works
Written by the Is it a scam? team. We build scam checking for Australian families and small businesses, from the Sunshine Coast, Queensland. Our verdicts come from a rules engine with published reasoning — not a guess.