Skip to main content Scroll Top

Cybercrime: No retirement fund is safe

The global cost of cybercrime is projected to hit an annual R200 trillion this year. And retirement funds – from small to large, well-resourced funds – are at risk.

R6 million – that’s how much money cybercriminals stole from retirement funds in Australia in April. In the past few years retirement funds have been attacked in the United Kingdom, the United States, and on home ground. All retirement funds – including yours – can fall victim, even large well-resourced funds are under threat.

The largest cyberattack on a local retirement fund took place in February 2024 on the Government Pensions Administration Agency (GPAA), which manages the Government Employees Pension Fund (GEPF). The ransomware group LockBit accessed the GPAA’s systems. According to MyBroadband, LockBit set a deadline in March for the GPAA to pay the ransom. The GPAA refused, and LockBit then released a 668 GB file allegedly containing data stolen from hundreds of government employees on the dark web.

The exact technical details of how LockBit gained initial access to the GPAA systems haven’t been fully disclosed by the GPAA. Usually cybercriminals gain access by sending fake emails (phishing) or exploiting vulnerabilities in public-facing applications (web servers and VPNs) or compromising remote desktop service credentials. Click here to learn about types of cyberattacks.

Australia: Coordinated attacks on super funds

On 4 April 2025, several major Australian superannuation funds were hit by a wave of cyberattacks.

AustralianSuper confirmed that around 600 member accounts were compromised, with R6 million stolen from just four members. Rest Super said it detected unauthorised access to 20 000 accounts. In some cases, personal and financial details were accessed, and attempts were made to change contact details to intercept transactions. While Hostplus and Insignia Financial detected attempted breaches, they reported no financial loss.

As a result, several funds temporarily shut down online access to member accounts while they investigated the extent of the impact. 

The attacks have forced the super funds to invest heavily in IT security upgrades and incident response mechanisms. The Australian government has since committed about R70 billion over seven years to improving cybersecurity in the sector.     

What is a superannuation fund?
In a nutshell, it is the Australian version of a defined-contribution retirement fund. It is also commonly called a super fund.

United Kingdom: Capita’s breach hits retirement funds hard

In March 2023, Capita plc, a major UK pension administrator, suffered a serious cyberattack by the Russian Black Basta gang.

The breach affected hundreds of pension schemes, including Universities Superannuation Scheme, The Salvation Army Employees Pension Fund and the Reuters Pension Fund. A substantial amount of personal pension data had been accessed or copied, including member names, dates of birth, and possibly bank details.

In response, the UK Pensions Regulator contacted trustees of funds administered by Capita to highlight the expectations set out in their cybersecurity guidance and the steps they expected trustees to take. Since Capita is actually a third party provider, their clients – the retirement funds – remained responsible for safeguarding their members’ data.

Although to date, there has been no financial losses for retirement funds, group legal actions by members are lining up against Capita. They argue that the breach has exposed them to serious risks of identity theft, fraud and emotional distress.

United States: California’s pension giants breached

Later that same year, the CL0P ransomware gang accessed systems used by the two largest public retirement funds in the United States – CalPERS and CalSTRS. These funds serve millions of members, including teachers, police officers, and other public sector workers. The breach occurred through a third-party contractor and exposed the personal data of around 769 000 retirees, including social security numbers and birthdates.

Affected members were offered credit monitoring for two years and identity theft protection – but trust in the retirement funds took a massive knock.

What is credit monitoring?
Credit monitoring is a service that watches your credit profile for any suspicious activity – like someone trying to open a store account, apply for a loan, or change your personal details. If something unusual happens, you’ll be alerted quickly so you can take action before you lose money or your identity is stolen.

Cyberattacks can have far-reaching impacts – from financial loss and reputational damage to legal liability and member distrust. Even well-funded, professionally managed systems are at risk when cybersecurity is neglected or outsourced without proper oversight.

Cybercrime is growing at an alarming rate as the financial industry continues to digitise their services. All parties involved – from trustees and retirement funds to administrators and regulators – should be preparing for a war with an unseen enemy.

To learn more about cybercrime, check out the Cybercrime Learning Lab. Or if you would like more in-depth knowledge, Atleha-edu and the ASISA Academy offer workshops for South African trustees and members of retirement funds on cybersecurity and other themes.

Sources

Burges-Salmon:The latest on the capita cyber incident: What does it mean for pension schemes
Citywire: Capita warns pension data ‘likely’ leaked during cyberattack
Governing: The nation’s two biggest pension systems report a data breach
Reuters: Hackers strike Australia’s largest pension funds in coordinated attacks
The Conversation: Hackers have hit major super funds. A cyber expert explains how to stop it happening again
The Guardian: $500,000 stolen in Australian super fund data breach

Funded by

Hi there, we can't wait to share our content with you. Please help us send you information that is most relevant to you.