top of page

The Cybercrime Threat Facing SMSFs

Sep 7
5 min read

Updated: Sep 8

SMSFs are faced with cybercrime threats everyday

Cybercrime is often described through soft terms such as hackers, scammers, malware, phishing and threat actors. For SMSF professionals, the wording can make the risk sound smaller and more distant than it is.


Cybercrime is organised crime, and SMSFs are attractive targets because they are characterised by high asset values with comparatively weak points of access.


The average SMSF contains $1.51 million, but it rarely has the cyber strength of a bank, large platform, or APRA-regulated fund. Instead, its practical defences depend on people, process and professional judgement across the advice chain.


Why SMSFs are attractive targets

The appeal is obvious to cybercriminals because SMSF trustees are older and regularly interact with advisers and accountants who email hundreds of clients.


SMSFs can also involve large single payments and may have security no stronger than a trustee's personal email account, home internet connection, mobile phone, and record-keeping habits. That makes the SMSF environment high-value and, in many cases, low-friction.


The Australian Institute of Criminology's 2025 cybercrime report surveyed 10,593 Australians and found that nearly half experienced some form of cybercrime in the previous 12 months, with fraud, scams, malware and identity misuse remaining major concerns.


The National Anti-Scam Centre also reported that Australians lost around $2.18 billion to scams in 2025, including $837.7 million to investment scams. For SMSFs, these figures highlight the risk to retirement savings.


Cybercriminals Target the SMSF Ecosystem

The key point is that cybercriminals do not always need to compromise the fund itself. They only need to compromise the SMSF ecosystem in a way that influences an SMSF transaction through a trustee's email account, an adviser's instructions, a conveyancer's settlement correspondence, or an accountant's client records.


All of these can become entry points for an attack that may not be immediate.


Cybercriminals can monitor communications over time, learn who is involved, wait for a high-value transaction, and then intervene at a critical point.


Business Email Compromise and Payment Fraud

Business email compromise remains one of the most common examples. A trustee purchasing property could exchange emails with a conveyancer, accountant, and solicitor for weeks. If criminals gained access to the conveyancer's inbox using stolen credentials, they could study the transaction and email changed bank details just before settlement. The email may look authentic, refer to the correct property and arrive at exactly the expected time.


The control failure is not simply that bank details changed. It is that no one independently verified the change through a known, trusted channel.


The practical rule is never verify changed payment details using the communication channel that delivered the change.


Call a known number, use a previously verified communication method and document the verification before money moves.


Impersonation, myGov and MFA Limits

The same principle applies to government impersonation and myGov-related fraud. A trustee who receives a fake, threatening SMS about an overdue SMSF supervisory levy may click a link, enter credentials into a cloned website, and hand over a one-time code while under pressure.


Multifactor authentication ("MFA") is important, but it is not a magic wand. If criminals manipulate a trustee into giving them the information needed to pass over control, it makes sense to treat the wider SMSF ecosystem as compromised until contained.


For professionals, the appropriate response is not just to tell the trustee to change a password. It is to treat the situation as an active incident and check whether contact details, rollover instructions, bank account details, payment authorities or SMSF records have changed. It also means liaising quickly with the trustee, the ATO, the bank and all relevant service providers.


SMSF Investment Scams

Investment scams present another challenge because they can involve fake advisers, cloned websites, professional-looking investor portals, fabricated returns and artificial investment urgency that creates an illusion of legitimacy.


Due diligence should not stop when a brochure seems polished or an online dashboard shows growth; a portal balance is not evidence that an asset exists, is properly held, or belongs to the fund.


SMSF trustees and professionals are both responsible for independently verifying credentials, licensing, product legitimacy, custody, title, liquidity and withdrawal restrictions before any fund money moves.


If returns appear unusually high, the product is difficult to explain, the adviser is pushing the investment as a matter of urgency, or the trustee cannot withdraw funds without paying a fee, challenge the investment as it could prevent permanent loss.


Information Harvesting

Information harvesting is equally serious. A seemingly simple request from the trustee to send an audit report to a new email address can expose member details, tax file numbers, addresses, bank information, pension data and investment records.


Criminals can use that information immediately, or combine it with other data over time to build a more complete identity profile. Familiarity is not verification, and a long-standing client relationship cannot replace a documented identity check.


SMSF professionals should follow documented processes and not simply react. An informal request to change contact details, payment instructions, adviser authority or access to confidential documents should trigger a consistent verification process.


Use recognised contact details, escalate unusual requests, record the process and avoid relying on the same communication channel that delivered the change.


Cybersecurity, Cybercrime and SMSF Governance

Cybersecurity should also be part of SMSF governance. Trustees and their advisers should consider MFA, unique passphrases, secure identity and access management, staff training, documented data-handling requirements, incident-reporting policies, and tested response plans.


For trustees, it is not simply an IT issue because SIS compliance requires governance to operate the fund prudently, ensure the investment strategy identifies appropriate risks, avoid mixing fund assets with the trustee’s personal assets, and to meet the obligation to protect retirement benefits.

 

From a practical viewpoint, the question is what would an SMSF professional do if a trustee called to say they had clicked a fake ATO link?


If the answer depends on who picks up the phone, that becomes the second weakest link in the SMSF ecosystem because cyber risk requires rehearsed responses and an incident plan, not improvisation.


Conclusion

The practical takeaway is to create a culture of shared responsibility amongst all SMSF stakeholders that slows the process down when something changes.


It ensures that new financial details are independently verified, unusual instructions are challenged, urgency is treated as a warning sign, and identities are confirmed before information is released.


Cybercriminals are looking for the easiest path to access valuable money and data. In the SMSF sector, that path may run through the inbox, the phone call, the cloned website, the trusted adviser or the rushed request.


The best defence is not a single control, but a culture of verification so everyone in the SMSF ecosystem understands their role in preventing fraud.


🎁Bonus Reading

Cybercrime is only part of the picture. Our previous article, Why Cybersecurity Matters for SMSFs, discusses why cybersecurity should be a priority for SMSFs and the wider risks that can emerge from insufficient protection.



Comments


bottom of page