Yes, in some cases you may be able to recover stolen funds from your superannuation account after a data breach - but it's not guaranteed. Your ability to get reimbursed depends on the super fund’s internal policies, the speed of your response and the specific circumstances of the attack. Funds like AustralianSuper are assisting authorities with investigations, but have not committed to automatic compensation for affected members.

Super Funds Whitepaper. Practical guidance, rollout patterns, and KPIs for passkey programs.
If your account was compromised, you should contact your fund immediately, file a formal complaint, and request remediation options. Some users may recover losses through insurance or legal claims, but past cases show mixed outcomes.
When funds are illegally withdrawn, super funds typically:
AustralianSuper, for instance, is assisting with the recovery of $500,000 stolen from four members but hasn't publicly confirmed whether those members will receive full compensation.
It depends. Here’s what the outcome often hinges on:
In 2020, an Australian retiree lost $180,000 to scammers and only recovered one-third of the amount after a four-year legal battle.. Legal costs often exceed the recovered sum, and results vary significantly depending on evidence and legal representation.
Corbado is the Authentication Intelligence Platform for CIAM teams running consumer authentication at scale. We help you see what IDP logs and generic analytics tools can't: where passkeys, passwords, OTP, social login and fallback journeys succeed, stall or fail, which devices and browsers create friction, and when an OS update silently breaks login. Two products: Corbado Observe layers process mining and observability across authentication journeys. Corbado Connect adds managed passkeys with analytics built in alongside your IDP. VicRoads runs passkeys for 5M+ users with Corbado (+80% passkey activation). Talk to a Passkey Expert →

Discover why superannuation funds are vulnerable and how regulations, including FSC Standard No. 29, recommend MFA and phishing-resistant authentication.
Read the full articleRead by 5,000+ security leaders.
Table of Contents