
ASIC has sounded the alarm over scam protections across Australia’s $4.3 trillion super system. Here’s what you need to know.
You probably keep a close eye on your bank account and credit card, but when was the last time you checked your super for something you didn’t recognise?
Australia’s corporate watchdog has warned superannuation trustees to strengthen their defences against scams and fraud, amid concerns the nation’s $4.3 trillion retirement savings pool is becoming an increasingly attractive target for criminals.
ASIC Commissioner Simone Constant has previously warned that as banks, telecommunications providers and other financial businesses improve their protections, super funds must do the same or risk becoming a “soft target”.
And ASIC’s latest examination suggests there is plenty of room for improvement.
ASIC examined scam and fraud information on the websites of 47 super funds and compared it with similar information provided by Australia’s big four banks.
The banks scored positively against more than 80 per cent of the criteria assessed. Most super funds managed only 40 to 60 per cent.
Only 19 per cent of funds clearly defined what constituted a scam. About one-third provided actionable information to help members prevent or report scams and fraud, while just one in five offered a dedicated contact method for reporting one.
The comparison wasn’t a test of whether criminals could hack into the funds. ASIC assessed the availability, quality and usefulness of the information provided to members.
But the wider warning is serious. Australians lost $22 million to super-related scams in 2025, according to figures cited by ASIC from the National Anti-Scam Centre.
A criminal doesn’t necessarily need to hack your super fund.
They can pose as a bank, super fund or financial business and attempt to steal personal information or login details through phishing and other scams.
With enough information, a scammer may be able to create another super account or fake self-managed super fund in your name, transfer your super into it and withdraw the money.
Stolen myGov sign-in details can also provide access to personal information and superannuation accounts.
Other scams rely on convincing you to move the money yourself.
You might be encouraged to establish an SMSF, transfer your savings into a supposedly lucrative investment or, if you’re eligible, withdraw your super and invest it elsewhere.
Once money reaches a scammer, recovering it can be extremely difficult.
For many Australians, super represents decades of work and one of the largest pools of money they will accumulate.
The risk can change as retirement approaches.
Once you’re eligible to access your super, a criminal can try to convince you to withdraw the money legitimately and then direct it towards a fraudulent investment or account.
Warning signs include promises of high returns with little or no risk, pressure to act quickly, attempts to discourage independent advice and requests to invest in something you don’t understand.
Unsolicited offers involving “super health checks”, lost super, early access or claims that your existing fund is underperforming should also be treated cautiously.
Yes.
ASIC’s findings don’t mean super funds have no security obligations.
APRA-regulated entities are subject to information-security requirements under Prudential Standard CPS 234. These include maintaining security capabilities appropriate to the threats they face, implementing controls to protect information and regularly testing those controls.
The board of an APRA-regulated entity is ultimately responsible for ensuring those requirements are met.
Following credential-stuffing attacks against super funds, APRA also reinforced its expectations around authentication controls across the sector.
ASIC’s concern extends beyond cyber security. It says scam and fraud prevention, detection and response capabilities across super are still not sufficiently addressing the risks facing members.
Log into your super account directly and look for transfer requests, withdrawals you don’t recognise or unexpected changes to your details.
Make sure your fund has your current mobile number, email and postal address. That gives it a better chance of reaching you if suspicious activity is detected.
Protect your passwords and login details. If your fund offers multi-factor authentication, Moneysmart recommends considering switching it on.
If someone claims to represent your super fund, contact the fund yourself using details from its official website, app or statement. Don’t rely on the phone number, link or contact details provided by the person who approached you.
Be particularly cautious about offers involving early access to super, setting up an SMSF, moving funds or investments promising unusually high returns.
If you think someone has gained access to your super, act quickly.
Contact your super fund and report the incident to Scamwatch and the Australian Taxation Office. If it involves hacking, stolen login details or unauthorised access to an online account, it can also be reported through ReportCyber.
After spending decades building your retirement savings, checking your super shouldn’t stop at watching its investment performance.
It pays to check that every dollar is still exactly where it should be.
Comments 0
Join the conversation. Comments are reviewed before they appear.
Be the first to comment.
Join the conversation
Tell us who you are to post a comment. We'll remember you next time.