multi-factor login available, but not enforced, and SMS-based factors still in use
The March 2025 attacks succeeded primarily because credential reuse from prior unrelated breaches was matched against super fund logins where multi-factor login was offered but not required. Several funds also relied on SMS-based multi-factor login, which is increasingly considered insufficient for high-value financial accounts. The Financial Services Council recommended mandatory multi-factor login for super funds by July 2026.
- multi-factor login enforcement gaps at login on member-facing portals
- SMS-based factors still in use for sensitive transactions
- Limited adoption of phishing-resistant authentication (passkeys, hardware tokens)