Menu
Browse

Cyber Incident Victim: Spirit Super

Date:

May 2022

Location:

Australia

Summary

A Spirit Super staff email account was compromised through phishing, leading to unauthorized access of a mailbox containing personal member information. The breached data primarily resembled annual statement details such as names, addresses, ages, contact information, account numbers, and balances, though a limited subset included sensitive documents like identification records, tax file numbers, bank details, and birthdates. The organization swiftly contained the incident, initiated an investigation to determine impacted individuals, and prioritized outreach to those affected by the exposure of higher-risk data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On 19 May 2022, Spirit Super detected unauthorized access to a staff member’s email account, which was compromised through a phishing attack. The organization identified the security breach promptly and contained the affected account to prevent further unauthorized activity. An investigation followed to assess the scope of the incident, revealing that the compromised mailbox contained personal member data. The breach did not stem from a system vulnerability or technical failure but resulted directly from the phishing activity targeting the employee’s credentials. Spirit Super confirmed that unauthorized actors accessed information typically found in annual statements, including member names, addresses, email addresses, telephone numbers, account numbers, and balances as recorded in 2019 and 2020. The majority of exposed records did not contain highly sensitive identifiers such as full dates of birth, tax file numbers, driver’s license details, or bank account information.

Cyber Incident Image

A smaller subset of compromised data included identification documents such as passports and driver’s licenses, along with bank account details, tax file numbers, dates of birth, and statements for a limited number of individuals. Spirit Super prioritized direct notification and support for those affected by this more sensitive data exposure. The organization emphasized that the breach was isolated to the single email account and did not compromise broader IT systems or databases. No evidence suggested misuse of the exposed data beyond the initial unauthorized access. Spirit Super undertook steps to reinforce security protocols and prevent similar incidents, though specific technical or procedural changes were not disclosed publicly. Impacted members received guidance on monitoring their accounts for suspicious activity, though the organization did not report any downstream financial fraud or identity theft linked directly to the breach at the time of their public statement on 19 August 2022.

Sources
Sources available to members
2 sources