Account takeover fraud: How to protect your account online

Scammers target big account balances: take steps to protect your account online from account takeover fraud.

Summary

CFS customer Jane was unaware a scammer had gained access to her email account. Then the scammer tried to withdraw $100,000 from her super in an attempted account takeover fraud. It could happen to anyone, so it’s important to take steps to protect your money. 

Jane has been a Colonial First State member for many years. She keeps a careful eye on her accounts, and logs in to FirstNet Investor from the same home computer she has used for years. 

 

Yet, sophisticated criminals came very close to taking $100,000 from her retirement savings.

 

Unbeknownst to Jane (not her real name), the fraudsters had gained access to her email account, intercepted a one-time password, and used this to gain access to her super and pension accounts.

 

Once inside, they opened several new accounts linked to her profile, positioning them to receive internal rollovers from her genuine super and pension balances. 

 

They then lodged a $100,000 withdrawal request from her pension account, directing it to a bank account she had never used. 

 

CFS' Fraud Management Team identified this unusual activity, stopped every pending payment, and worked directly with Jane to secure her details.

 

They helped her to place a block on her myGov account and connected her with IDCARE. 

 

During those follow-up conversations, Jane remembered a phone call weeks earlier from someone claiming to be from Microsoft, offering to help check her computer's security. She believes she may have granted them remote access.

Help protect your online accounts from account takeover fraud

In keeping with this year's Scam Awareness Week theme – No one's just a number – we’re sharing Jane’s story to help inspire more members to take proactive steps to avoid getting caught out by an account takeover or superannuation fraud. 

 

According to scam prevention website Scamwatch, 12,378 cases of account or identity takeover scams have been reported in Australia so far this year1

Account takeover fraud in Australia does not target the careless or the uninformed. It targets accounts with meaningful balances, and it uses techniques refined by professional criminals.

And while the total number of cases appears to be trending lower than last year, average losses are greater.

 

Over the first eight months of 2026, losses of approximately $16.5 million were reported – which is 32% higher than the $12.5 million in losses reported for all of 20251

What is account takeover fraud and why does it target super?

Account takeover fraud is when a criminal gains unauthorised access to a legitimate online account, then uses it as if they were the account holder, effectively impersonating them. 

 

In a super account takeover, that access is used to redirect payments, initiate rollovers to fraudulent accounts, or request lump-sum withdrawals. 

The mechanics usually involve some combination of stolen login credentials, one-time password (OTP) interception through a compromised email inbox, and remote access to the victim's device. 

The Australian Signals Directorate has consistently identified credential-based attacks and business email compromise as among the most financially damaging categories of cybercrime affecting Australians.

 

Identity theft super account cases in Australia have grown in sophistication because superannuation is a uniquely attractive target. Balances are large, members may log in infrequently, and pension payments follow predictable patterns that a fraudster can quietly interrupt. 

Help to stay safe online

Our Staying safe online hub is updated regularly with tips on how to keep your accounts safe and some of the warning signs to watch out for when it comes to scams.

How fraudsters target super accounts in 2026: the tactics to know

The methods used in super account takeovers this year are refined, patient, and often involve multiple stages. 

 

Understanding the tactics is the first step to recognising them.

 

Remote access scam activity in Australia continues to feature prominently in Scamwatch reporting, and it is the tactic Jane appears to have encountered. 

 

These attacks succeed not because victims are careless, but because the callers are trained to sound legitimate and urgent.

Common account takeover tactics targeting super

Fraud tactic
How it works
Warning signs
Fraud tactic

Phone impersonation (tech support scam) 

How it works

Caller claims to be from a known company such as Microsoft or your bank and asks for remote device access. 

Warning signs

Unsolicited call; caller asks you to install software or visit a website. 

Fraud tactic

One-time password scam (OTP interception) 

How it works

Fraudster accesses your email or phone to capture one-time passwords sent by your super fund. 

Warning signs

Login alerts you did not initiate; unexpected password reset emails. 

Fraud tactic

Phishing email 

How it works

Fake email mimics a trusted brand to steal your login credentials. 

Warning signs

Suspicious sender address; urgent tone; link directs to an unfamiliar URL. 

Fraud tactic

SIM swapping

How it works

Fraudster convinces your telco to transfer your phone number to their SIM. 

Warning signs

Sudden loss of mobile service; inability to make calls or receive SMS. 

Fraud tactic

Remote access tool abuse 

How it works

Victim is tricked into granting screen-sharing or remote control access. 

Warning signs

Software installation requested by unsolicited caller; unusual device behaviour. 

Signs a super account may be compromised

Early detection matters. The sooner a customer spots something unusual, the sooner the Fraud Management Team, and the customer themselves, can act to protect a super account online.

 

Some signs your super account may be compromised may include:

  • A login alert or OTP email you did not request.
  • A new bank account added to your member profile that you do not recognise.
  • Linked accounts or rollover requests you did not initiate.
  • A change to the bank account receiving your pension payment.
  • Difficulty accessing your myGov account, or notifications of a myGov account takeover attempt.
  • Password reset emails you did not ask for.
  • Your mobile suddenly showing no service, which can indicate a SIM swap.

If any of these appear, treat them as urgent. Contact CFS immediately and, if you suspect your identity has been compromised more broadly, contact IDCARE. 

How CFS protects your superannuation and pension accounts

CFS proactively monitors customer account activity to flag unusual events, engages with affected members, and provides clear information to help Australians protect their financial future.

 

Our dedicated Fraud Management Team watches for the patterns and anomalies that typically precede a super account takeover. 

 

In Jane's case, that monitoring is why the $100,000 withdrawal was stopped before it left her account. 

 

The team also plays an educational role, working one-on-one with affected members to help them secure their devices, review their personal information hygiene, and take the best next steps with agencies such as myGov and IDCARE.

Steps to protect your super account online from account takeover fraud

To protect super account online access, a small number of practical steps make a significant difference.

  1. Secure your email account first. Your email is the recovery point for almost every other account. Use a strong, unique password and enable multi-factor authentication.
  2. Use a strong, unique password for FirstNet Investor. Do not reuse a password from another site. Consider a reputable password manager.
  3. Enable multi-factor authentication wherever it is offered.
  4. Never grant remote access to an unsolicited caller. Legitimate organisations, including Microsoft, banks, and CFS, will not phone you out of the blue and ask to control your computer.
  5. Place a block on your myGov account if you suspect it has been accessed. myGov provides guidance on securing your account and reporting compromise.
  6. Contact IDCARE on 1800 595 160. IDCARE is Australia and New Zealand's national identity and cyber support community, and can guide you through recovery.
  7. Contact CFS immediately if you notice anything unusual on your super or pension account. The Fraud Management Team can review activity and act quickly.

Visit ScamWatch for all scam alerts

Check out scam tips, news and alerts through the Australian Government’s Scamwatch website

You can also subscribe to Scamwatch email alerts to keep up to date with the latest scams. 

Frequently asked questions

Account takeover fraud is when a criminal gains unauthorised access to a legitimate online account and uses it to move money or change payment details. In a super context, this can mean redirected pension payments, fraudulent rollovers, or attempted lump-sum withdrawals to bank accounts controlled by the fraudster.

Many one-time password interceptions begin with a compromised email inbox or a phone that has been SIM-swapped. Once the fraudster controls the channel that receives the OTP, they can complete logins and approve changes that appear legitimate to the fund. 

Contact CFS immediately so the Fraud Management Team can review activity on your account. Then change the password on your email and FirstNet Investor logins from a secure device, and contact IDCARE on 1800 595 160 for identity recovery support. 

IDCARE is Australia and New Zealand's national identity and cyber support community. Their specialist case managers help Australians affected by identity theft, including superannuation fraud Australia cases, work through recovery steps such as securing myGov, credit reporting, and device security. 

Use a strong unique password, enable multi-factor authentication, secure your email inbox, never grant remote access to unsolicited callers, and review your account regularly for unfamiliar linked accounts or payment changes. These simple habits significantly reduce the risk of a super account takeover.

Related articles

¹ Scam statistics, published by Scamwatch as at 31 August 2026.

Disclaimer

 

Information provided by Avanteos Investments Limited and Colonial First State Investments Limited. Consider the PDS and TMD at cfs.com.au to see if it’s right for you.

 

Avanteos Investments Limited ABN 20 096 259 979, AFSL 245531 (AIL) is the trustee of the Colonial First State FirstChoice Superannuation Trust ABN 26 458 298 557 and issuer of FirstChoice range of super and pension products. Colonial First State Investments Limited ABN 98 002 348 352, AFSL 232468 (CFSIL) is the responsible entity and issuer of products made available under FirstChoice Investments and FirstChoice Wholesale Investments.

Information on this webpage is provided by AIL and CFSIL. It may include general advice but does not consider your individual objectives, financial situation, needs or tax circumstances. You can find the target market determinations (TMD) for our financial products at https://www.cfs.com.au/tmd which include a description of who a financial product might suit. You should read the relevant Product Disclosure Statement (PDS) and Financial Services Guide (FSG) carefully, assess whether the information is appropriate for you, and consider talking to a financial adviser before making an investment decision. You can get the PDS and FSG at www.cfs.com.au or by calling us on 13 13 36.