The Breach Ledger is a Coastal Cyber research series examining cyber incident trends across Australian industries. Each edition draws on three primary sources: the Webber Insurance named breach register [1] (678 Australian incidents, 2018–2026), OAIC Notifiable Data Breach reports published since the scheme commenced in February 2018 [2], and threat intelligence from the ASD Annual Cyber Threat Report [3]. Together, they map what is happening in a given sector, what the consequences look like in practice, and what organisations are risking by treating security as next year’s budget problem.
This is the Finance Edition.
An administrator at Levitas Capital, a Sydney hedge fund manager, opened an email containing what looked like a routine Zoom meeting link from a colleague. It wasn’t. The click handed attackers access to the firm’s email system. [4]
Over the following days, the attackers used that access to submit fraudulent invoices requesting $8.7 million in transfers — $1.2 million to a domestic account, $2.5 million to Hong Kong, $5 million to Singapore. One of the firm’s co-founders noticed a missing $7.5 million the next day and clawed most of it back. The attackers still got away with $781,000. [4]
The money wasn’t the fatal blow. The reputational damage was. Levitas Capital’s largest client withdrew its funds, and the firm — which had managed approximately $75 million — wound down within weeks. No ransomware. No hacking in the conventional sense. One email, and a firm that had operated for years was gone.
This is not a hypothetical. It is documented. And Levitas Capital is not alone.
- Financial services is the second most-notified sector in Australia. 73 OAIC notifications in the first half of 2025 alone, behind only health service providers.
- This sector is targeted deliberately, not caught in the crossfire. 66% of Finance sector NDB notifications in the first half of 2025 were malicious or criminal attacks — well above the 59% national average across all sectors.
- The size of the firm doesn’t buy safety. A $75 million boutique hedge fund and some of Australia’s largest superannuation funds both appear in this record — one collapsed, the others lost member savings to a technique that costs almost nothing to run.
- The regulatory bar has already moved. The Federal Court has ruled that “adequate cybersecurity” is a legal obligation for AFSL holders, not a best-practice suggestion. That precedent exists now, and it applies regardless of firm size.
Six named incidents in the Australian breach record since 2020, spanning hedge funds, consumer lenders, mortgage brokers, superannuation funds, and fintech lending platforms.
| Year | Organisation | State | What happened |
|---|---|---|---|
| 2020 | Levitas Capital [4] | NSW | Business email compromise via a fake Zoom invite; $8.7m in fraudulent transfers approved, $781,000 lost, hedge fund wound down |
| 2022 | RI Advice Group [5] | National | Federal Court found the AFSL holder failed to adequately manage cyber risk after incidents at authorised representatives between 2014 and 2020, including a brute-force compromise of a file server holding client data |
| 2023 | Latitude Financial [6] | National | Compromised employee login at two service providers; 14 million records including 7.9 million driver’s licences and 53,000 passport numbers, some dating to 2005 |
| 2024 | Finsure [7] | National | Third-party marketing platform (ActivePipe) compromise; approximately 300,000 mortgage customer email addresses and contact details exposed (the vendor disputes the scale) |
| 2025 | REST, AustralianSuper, Hostplus & others [8] | National | Coordinated credential-stuffing attack; over 20,000 member accounts targeted across five funds, approximately $500,000 withdrawn from four AustralianSuper members |
| 2026 | youX [9] | NSW / National | 141GB stolen from an unsecured cloud database; 444,538 records including loan applications, driver’s licences and residential addresses, cascading through 797 broker organisations and 90+ lenders |
Three attack types, no common technical vector — a phishing email, a brute-force login, stolen credentials, a third-party platform, recycled passwords, and an unsecured cloud database. The common thread is not the method. It is the target: organisations holding the data and the payment rails that make fraud immediately profitable.
Finance sector (incl. superannuation) NDB notifications in the first half of 2025 — the second-highest count of any sector, behind Health service providers (96) and ahead of Australian Government (67). [2]
The Webber Insurance breach register does not tag incidents by sector in a way that produces a precise financial services count, and Coastal Cyber has not built that count independently — treat any figure here as approximate. What the register does show clearly, in its own year-by-year record, is financial services incidents in every year since 2018: NAB and CBA in 2019, RI Advice in 2020, Spirit Super in 2022, Latitude in 2023, Firstmac and Suncorp Bank in 2024, the superannuation credential-stuffing attack in 2025, youX in 2026.
The trajectory across the full 2018–2026 dataset is not flat. The sector has appeared in every landmark year: the RI Advice case reshaped regulatory expectations in 2022, Latitude produced the largest single breach by record count in Australian history at the time in 2023, and the 2025 superannuation attack demonstrated that even funds with tens of billions under management can lose member money to a technique requiring no more sophistication than a list of leaked passwords.
A financial services business — whether a mortgage broker, financial adviser, boutique fund manager, or accounting-adjacent practice — holds a data inventory that combines identity, income, and access in one place.
- Identity documents: driver’s licences, passports, birth certificates collected for KYC and AML obligations
- Financial position: income statements, asset and liability schedules, credit reports, bank and super details
- Loan and application data: mortgage and finance applications, often with years of supporting documentation
- Payment rails: the ability to move client money, or to instruct a third party to move it
- Tax file numbers and superannuation account access
- Physical records: paper client files, signed authority forms, and loan documentation, frequently retained well past any documented destruction schedule
The payment-rail point is what separates this sector from most others in this series. A school or charity breach exposes data. A financial services breach can directly move money — which is exactly what happened at Levitas Capital and in the 2025 superannuation attack. The data and the cash are the same target.
Of 73 Finance sector NDB notifications in the first half of 2025 were malicious or criminal attacks. Only 22 (30%) were human error. [2]
That split sits above the national average across all sectors (59% malicious, 37% human error), and it is the inverse of what this series found in the Education sector, where human error accounted for 74% of notifications. [2] Financial services is not primarily a story of misdirected emails and process slips. It is a sector being actively, deliberately targeted — credential stuffing against super fund logins, business email compromise against firms handling client transfers, brute-force attacks against file servers holding client records.
That does not mean process and training are irrelevant. Levitas Capital’s collapse traces back to a single click and a payment approval process with no independent verification step — a process failure, not a software failure. But the sector-wide split tells you where to weight investment: firms in this sector face determined, resourced attackers more often than firms in most other sectors in this series, and defences need to assume that from the outset rather than treating a well-trained team as sufficient on its own.
For a financial services business without an enterprise security budget, the starting point is not a penetration test. It is these six things.
-
1Require independent verification for any payment or transfer instruction changeA phone call to a known number, not a reply to the email that made the request. This single control would have stopped the Levitas Capital transfers.
-
2Enforce MFA on every client-facing login and every internal system with financial or client dataThe 2025 superannuation attack succeeded in part because MFA was inconsistently applied across funds — a gap regulators had already flagged before the attack.
-
3Treat your AFSL cyber obligations as a compliance requirement, not a best-practice aspirationThe RI Advice judgment established that inadequate cybersecurity risk management can itself be a breach of licence conditions. That precedent applies to every AFSL holder, not just the firm that was sued.
-
4Vet the security posture of any third-party platform handling client data before you connect itFinsure’s exposure ran through a marketing platform, not its own systems. A vendor with access to your client list is part of your attack surface.
-
5Verify your backups and build a one-page incident response planWho calls the regulator, who calls affected clients, who calls the insurer, and in what order — decided before an incident, not during one.
-
6Commission a professional cyber health assessmentAn independent assessment gives a small or mid-sized financial services practice an evidenced picture of where it stands before a regulator or an attacker forces the conversation. Coastal Cyber’s Cyber Health Check is designed specifically for financial services firms and other resource-constrained organisations.
None of these require an enterprise security team. They require deciding, in advance, what happens when a request looks slightly wrong.
The Federal Court has already answered the question of whether “adequate cybersecurity” is optional for a financial services licensee. It isn’t.
The harder question for a smaller firm is whether it could show, today, that its cyber risk management is adequate — not eventually, not once there’s budget for it, but as things stand. Adequate is a standard that gets tested after an incident, using the systems and processes that existed before it. Building them afterwards doesn’t count.
The cost of getting ahead of that question is a rounding error against the cost of finding out the answer the way RI Advice, Latitude, and Levitas Capital did.
That’s because it is. Managing cyber and data risk in a financial services firm isn’t one job — it’s several, spread across compliance, IT, client-facing staff, and leadership, in a business that runs on trust and on other people’s money. Doing it without a trusted partner is where most small and mid-sized financial services firms stall.
If you’re wondering which thread to pull first, that is exactly the conversation worth having with a GRC professional before you spend a quarter going in circles. A few hours of advice early saves weeks of internal debate and considerable heartache later.
Book a 20-minute conversation
If your firm’s cyber and privacy posture needs a clear-eyed assessment, start here. No sales process. No commitment. Just clarity on which thread to pull first.