CSIDB logo
Incident

Spirit Super

Incident posture

Attack window
May 2022
Location
Australia
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-03 11:34

Linked entities

Victim
Spirit Super
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2022
Discovered
May 2022
Disclosed
May 2022
Resolved
Pending

Summary

A phishing attack compromised a staff member's email account at an Australian superannuation fund, resulting in unauthorized access to a mailbox containing personal data belonging to approximately 50,000 of its 330,000-plus members. The compromised information included names, addresses, ages, email addresses, phone numbers, super account numbers, and account balances from the 2019-20 financial year, though no tax file numbers, driver's licence details, or bank account credentials were reportedly exposed. According to the organization, the attacker overcame multi-factor authentication by tricking the staff member into surrendering their password via a malicious email disguised as official correspondence. The breach was detected quickly and contained, with the fund notifying relevant authorities, including the Privacy Commissioner, while reviewing its data handling practices, staff training, and account security controls.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On 19 May 2022, Spirit Super, a Tasmanian-based industry superannuation fund formed from the 2021 merger of MTAA Super and Tasplan, suffered a data incident when a staff member's email mailbox was accessed by an unauthorised party. The breach was detected quickly and contained, according to a statement the fund later published on its website. The method used by the attacker involved the compromise of a staff member's password followed by the circumvention of the multi-factor authentication (MFA) controls that Spirit Super employs as an additional layer of protection beyond a username and password. Specifically, Spirit Super reported that the malicious cyber attacker overcame MFA through the use of a phishing email "posing as official correspondence," enabling the attacker to gain access to a mailbox that contained personal information belonging to members.

The compromised mailbox held a defined set of personal data fields, and Spirit Super's subsequent communications identified what was and was not exposed. The information that was accessible included member names, addresses, ages, email addresses, phone numbers, superannuation account numbers, and account balances drawn from the 2019-20 financial year. The fund explicitly stated that it appeared no tax file numbers, driver's licence details, or bank account details were stolen during the incident. The breach affected approximately 50,000 of Spirit Super's roughly 330,000 total members, making this a significant portion of the fund's membership base even though only a limited category of data was involved.

Following detection and containment of the mailbox compromise, Spirit Super initiated contact with impacted individuals and relevant authorities. During the week commencing 31 May 2022, the fund reached out to almost 50,000 members to advise them of the data incident and the nature of the information that had been exposed. The company confirmed that it had notified all relevant authorities, including the Privacy Commissioner, in accordance with its regulatory obligations. Spirit Super also stated that its investigation to date indicated that member accounts themselves had not been compromised, distinguishing the mailbox-level data exposure from any broader account-level intrusion or financial transaction impact.

In parallel with regulatory notification and member communication, Spirit Super began a series of internal reviews and remediation steps in response to the incident. The fund announced it was in the process of reviewing all of its data handling practices and staff training, aiming to identify any procedural or human-factor weaknesses that contributed to the successful phishing attack. Spirit Super also indicated it was reviewing account activity and placing enhanced controls on accounts, while pledging to further strengthen its IT security posture to reduce the risk of future cyber incidents. The fund increased its levels of security to help ensure that members' accounts remain safe, framing these as direct responses to the identified incident rather than as part of any pre-existing initiative.

The incident itself was characterised by Spirit Super as the result of a sophisticated phishing attack rather than a material security control weakness or technology failure. The fund noted that phishing attacks of this nature were becoming increasingly sophisticated and common, and that the specific compromise had occurred through a staff member's password being obtained and MFA being subsequently bypassed. The investigation was described as ongoing, with Spirit Super stating on its website that its inquiries would continue beyond the initial containment and notification phase. The breach was publicly reported in industry media coverage on 31 May 2022, drawing attention to the event shortly after the fund began contacting affected members and authorities.

Sources

Sources available to members: 1 source.

CSIDB