Could MFA save the day?

A cyberattack on superannuation funds underscores the need for Multi-Factor Authentication (MFA) and unique passwords to prevent credential stuffing and safeguard financial assets.

Image of a mobile phone, pot plant and pair of glasses

A lack of Multi-factor Authentication (MFA) has been identified as the key cause of a significant cyberattack last week, which targeted some of Australia’s largest superannuation funds.

“’Credential stuffing’ is one of the most simple but effective attack types,” said Matthew Thorley, Threat Response and Vulnerability Manager at the University of Melbourne. “Criminals use usernames and passwords stolen from previous data breaches and simply try their luck to see if these combinations work on other websites.”

“If you are someone who reuses the same passwords on multiple accounts, it’s only a matter of time until an attacker gains access and as we saw last week, this can result in significant financial loss,” warned Matthew.

Fortunately, there are two simple steps that people can take to drastically reduce their vulnerability to credential stuffing attacks.

  1. Never reuse the same password on multiple accounts. Learn more about password management.
  2. Set-up Multi-Factor Authentication (MFA) wherever possible. This means that even if an attacker has access to your password and username, they will be unable to break into your account. Learn more about MFA at the University.

The University advises staff and students who suspect they may be impacted by the superannuation fund attack to contact their fund directly (not by following a link in an email or SMS) and stay vigilant for any unexpected activity on their account.