The Breach Ledger is a Coastal Cyber research series examining cyber incident trends across Australian industries. Each edition draws on three primary sources: the Webber Insurance named breach register [1] (678 Australian incidents, 2018–2026), OAIC Notifiable Data Breach reports published since the scheme commenced in February 2018 [2], and threat intelligence from the ASD Annual Cyber Threat Report [3]. Together, they map what is happening in a given sector, what the consequences look like in practice, and what organisations are risking by treating security as next year’s budget problem.

This is the Finance Edition.

Levitas Capital, NSW — September 2020

An administrator at Levitas Capital, a Sydney hedge fund manager, opened an email containing what looked like a routine Zoom meeting link from a colleague. It wasn’t. The click handed attackers access to the firm’s email system. [4]

Over the following days, the attackers used that access to submit fraudulent invoices requesting $8.7 million in transfers — $1.2 million to a domestic account, $2.5 million to Hong Kong, $5 million to Singapore. One of the firm’s co-founders noticed a missing $7.5 million the next day and clawed most of it back. The attackers still got away with $781,000. [4]

The money wasn’t the fatal blow. The reputational damage was. Levitas Capital’s largest client withdrew its funds, and the firm — which had managed approximately $75 million — wound down within weeks. No ransomware. No hacking in the conventional sense. One email, and a firm that had operated for years was gone.

This is not a hypothetical. It is documented. And Levitas Capital is not alone.

The Short Version — Cut to the Chase

Six named incidents in the Australian breach record since 2020, spanning hedge funds, consumer lenders, mortgage brokers, superannuation funds, and fintech lending platforms.

Year Organisation State What happened
2020 Levitas Capital [4] NSW Business email compromise via a fake Zoom invite; $8.7m in fraudulent transfers approved, $781,000 lost, hedge fund wound down
2022 RI Advice Group [5] National Federal Court found the AFSL holder failed to adequately manage cyber risk after incidents at authorised representatives between 2014 and 2020, including a brute-force compromise of a file server holding client data
2023 Latitude Financial [6] National Compromised employee login at two service providers; 14 million records including 7.9 million driver’s licences and 53,000 passport numbers, some dating to 2005
2024 Finsure [7] National Third-party marketing platform (ActivePipe) compromise; approximately 300,000 mortgage customer email addresses and contact details exposed (the vendor disputes the scale)
2025 REST, AustralianSuper, Hostplus & others [8] National Coordinated credential-stuffing attack; over 20,000 member accounts targeted across five funds, approximately $500,000 withdrawn from four AustralianSuper members
2026 youX [9] NSW / National 141GB stolen from an unsecured cloud database; 444,538 records including loan applications, driver’s licences and residential addresses, cascading through 797 broker organisations and 90+ lenders

Three attack types, no common technical vector — a phishing email, a brute-force login, stolen credentials, a third-party platform, recycled passwords, and an unsecured cloud database. The common thread is not the method. It is the target: organisations holding the data and the payment rails that make fraud immediately profitable.

73

Finance sector (incl. superannuation) NDB notifications in the first half of 2025 — the second-highest count of any sector, behind Health service providers (96) and ahead of Australian Government (67). [2]

The Webber Insurance breach register does not tag incidents by sector in a way that produces a precise financial services count, and Coastal Cyber has not built that count independently — treat any figure here as approximate. What the register does show clearly, in its own year-by-year record, is financial services incidents in every year since 2018: NAB and CBA in 2019, RI Advice in 2020, Spirit Super in 2022, Latitude in 2023, Firstmac and Suncorp Bank in 2024, the superannuation credential-stuffing attack in 2025, youX in 2026.

The trajectory across the full 2018–2026 dataset is not flat. The sector has appeared in every landmark year: the RI Advice case reshaped regulatory expectations in 2022, Latitude produced the largest single breach by record count in Australian history at the time in 2023, and the 2025 superannuation attack demonstrated that even funds with tens of billions under management can lose member money to a technique requiring no more sophistication than a list of leaked passwords.

A financial services business — whether a mortgage broker, financial adviser, boutique fund manager, or accounting-adjacent practice — holds a data inventory that combines identity, income, and access in one place.

The payment-rail point is what separates this sector from most others in this series. A school or charity breach exposes data. A financial services breach can directly move money — which is exactly what happened at Levitas Capital and in the 2025 superannuation attack. The data and the cash are the same target.

66%

Of 73 Finance sector NDB notifications in the first half of 2025 were malicious or criminal attacks. Only 22 (30%) were human error. [2]

That split sits above the national average across all sectors (59% malicious, 37% human error), and it is the inverse of what this series found in the Education sector, where human error accounted for 74% of notifications. [2] Financial services is not primarily a story of misdirected emails and process slips. It is a sector being actively, deliberately targeted — credential stuffing against super fund logins, business email compromise against firms handling client transfers, brute-force attacks against file servers holding client records.

That does not mean process and training are irrelevant. Levitas Capital’s collapse traces back to a single click and a payment approval process with no independent verification step — a process failure, not a software failure. But the sector-wide split tells you where to weight investment: firms in this sector face determined, resourced attackers more often than firms in most other sectors in this series, and defences need to assume that from the outset rather than treating a well-trained team as sufficient on its own.

For a financial services business without an enterprise security budget, the starting point is not a penetration test. It is these six things.

  1. 1
    Require independent verification for any payment or transfer instruction change
    A phone call to a known number, not a reply to the email that made the request. This single control would have stopped the Levitas Capital transfers.
  2. 2
    Enforce MFA on every client-facing login and every internal system with financial or client data
    The 2025 superannuation attack succeeded in part because MFA was inconsistently applied across funds — a gap regulators had already flagged before the attack.
  3. 3
    Treat your AFSL cyber obligations as a compliance requirement, not a best-practice aspiration
    The RI Advice judgment established that inadequate cybersecurity risk management can itself be a breach of licence conditions. That precedent applies to every AFSL holder, not just the firm that was sued.
  4. 4
    Vet the security posture of any third-party platform handling client data before you connect it
    Finsure’s exposure ran through a marketing platform, not its own systems. A vendor with access to your client list is part of your attack surface.
  5. 5
    Verify your backups and build a one-page incident response plan
    Who calls the regulator, who calls affected clients, who calls the insurer, and in what order — decided before an incident, not during one.
  6. 6
    Commission a professional cyber health assessment
    An independent assessment gives a small or mid-sized financial services practice an evidenced picture of where it stands before a regulator or an attacker forces the conversation. Coastal Cyber’s Cyber Health Check is designed specifically for financial services firms and other resource-constrained organisations.

None of these require an enterprise security team. They require deciding, in advance, what happens when a request looks slightly wrong.

The Federal Court has already answered the question of whether “adequate cybersecurity” is optional for a financial services licensee. It isn’t.

The harder question for a smaller firm is whether it could show, today, that its cyber risk management is adequate — not eventually, not once there’s budget for it, but as things stand. Adequate is a standard that gets tested after an incident, using the systems and processes that existed before it. Building them afterwards doesn’t count.

The cost of getting ahead of that question is a rounding error against the cost of finding out the answer the way RI Advice, Latitude, and Levitas Capital did.

That’s because it is. Managing cyber and data risk in a financial services firm isn’t one job — it’s several, spread across compliance, IT, client-facing staff, and leadership, in a business that runs on trust and on other people’s money. Doing it without a trusted partner is where most small and mid-sized financial services firms stall.

If you’re wondering which thread to pull first, that is exactly the conversation worth having with a GRC professional before you spend a quarter going in circles. A few hours of advice early saves weeks of internal debate and considerable heartache later.

Book a 20-minute conversation

If your firm’s cyber and privacy posture needs a clear-eyed assessment, start here. No sales process. No commitment. Just clarity on which thread to pull first.

Book a call →