ASIC warns super funds are falling short on protection against scams
Last updated: September 9, 2026
Australia’s superannuation industry has been urged to strengthen its response to scams after a regulatory review identified significant gaps in the information and support provided to members.
The Australian Securities and Investments Commission examined scam and fraud material published by 47 superannuation funds.
ASIC compared that material with information available from Australia’s four major banks. The banks performed positively against more than 80 per cent of the criteria assessed, while most super funds met only between 40 and 60 per cent.
The review considered whether warnings were easy to find, clearly written and useful to a person who suspected that they had been targeted.
Superannuation funds collectively oversee approximately $4.3 trillion in Australian retirement savings. That enormous pool of money makes accounts an attractive target for criminals.
ASIC Commissioner Simone Constant said funds often lacked “clarity, accessibility, and support for scam victims.”
How superannuation scams operate
A criminal may impersonate a super fund, bank, government agency or financial adviser. The person may offer to help a victim access super early, transfer it into a self-managed fund or place it in a supposedly exclusive investment.
Other attacks begin with stolen myGov credentials or a phishing message designed to collect identity information.
Consumers should be cautious about unsolicited requests to move their superannuation, particularly when the approach includes promises of unusually high or guaranteed returns.
A professional-looking website is not proof that an investment is legitimate. Scammers can copy company branding, licence information and employee identities.
ASIC’s Moneysmart service recommends checking whether a person offering financial products holds an Australian financial services licence or is properly authorised. Consumers should conduct that check independently instead of using a link supplied by the person contacting them.
Members can also reduce their exposure by enabling strong authentication, protecting email and myGov accounts, monitoring their {superannuation balance} and checking that contact details have not been changed without permission.
Anyone who believes that their account has been compromised should contact their fund immediately. They should also notify their bank where relevant, change affected passwords and report the incident through official scam-reporting channels.
The regulator’s findings do not mean that every super fund has weak security systems. The review focused primarily on the quality and accessibility of information presented to members. However, clear instructions can be critical when a victim must act quickly.