Scammers target big account balances: take steps to protect your account online from account takeover fraud.
CFS customer Jane was unaware a scammer had gained access to her email account. Then the scammer tried to withdraw $100,000 from her super in an attempted account takeover fraud. It could happen to anyone, so it’s important to take steps to protect your money.
Jane has been a Colonial First State member for many years. She keeps a careful eye on her accounts, and logs in to FirstNet Investor from the same home computer she has used for years.
Yet, sophisticated criminals came very close to taking $100,000 from her retirement savings.
Unbeknownst to Jane (not her real name), the fraudsters had gained access to her email account, intercepted a one-time password, and used this to gain access to her super and pension accounts.
Once inside, they opened several new accounts linked to her profile, positioning them to receive internal rollovers from her genuine super and pension balances.
They then lodged a $100,000 withdrawal request from her pension account, directing it to a bank account she had never used.
CFS' Fraud Management Team identified this unusual activity, stopped every pending payment, and worked directly with Jane to secure her details.
They helped her to place a block on her myGov account and connected her with IDCARE.
During those follow-up conversations, Jane remembered a phone call weeks earlier from someone claiming to be from Microsoft, offering to help check her computer's security. She believes she may have granted them remote access.
In keeping with this year's Scam Awareness Week theme – No one's just a number – we’re sharing Jane’s story to help inspire more members to take proactive steps to avoid getting caught out by an account takeover or superannuation fraud.
According to scam prevention website Scamwatch, 12,378 cases of account or identity takeover scams have been reported in Australia so far this year1.
Account takeover fraud in Australia does not target the careless or the uninformed. It targets accounts with meaningful balances, and it uses techniques refined by professional criminals.
And while the total number of cases appears to be trending lower than last year, average losses are greater.
Over the first eight months of 2026, losses of approximately $16.5 million were reported – which is 32% higher than the $12.5 million in losses reported for all of 20251.
Account takeover fraud is when a criminal gains unauthorised access to a legitimate online account, then uses it as if they were the account holder, effectively impersonating them.
In a super account takeover, that access is used to redirect payments, initiate rollovers to fraudulent accounts, or request lump-sum withdrawals.
The mechanics usually involve some combination of stolen login credentials, one-time password (OTP) interception through a compromised email inbox, and remote access to the victim's device.
The Australian Signals Directorate has consistently identified credential-based attacks and business email compromise as among the most financially damaging categories of cybercrime affecting Australians.
Identity theft super account cases in Australia have grown in sophistication because superannuation is a uniquely attractive target. Balances are large, members may log in infrequently, and pension payments follow predictable patterns that a fraudster can quietly interrupt.
Our Staying safe online hub is updated regularly with tips on how to keep your accounts safe and some of the warning signs to watch out for when it comes to scams.
The methods used in super account takeovers this year are refined, patient, and often involve multiple stages.
Understanding the tactics is the first step to recognising them.
Remote access scam activity in Australia continues to feature prominently in Scamwatch reporting, and it is the tactic Jane appears to have encountered.
These attacks succeed not because victims are careless, but because the callers are trained to sound legitimate and urgent.
Phone impersonation (tech support scam)
Caller claims to be from a known company such as Microsoft or your bank and asks for remote device access.
Unsolicited call; caller asks you to install software or visit a website.
One-time password scam (OTP interception)
Fraudster accesses your email or phone to capture one-time passwords sent by your super fund.
Login alerts you did not initiate; unexpected password reset emails.
Phishing email
Fake email mimics a trusted brand to steal your login credentials.
Suspicious sender address; urgent tone; link directs to an unfamiliar URL.
SIM swapping
Fraudster convinces your telco to transfer your phone number to their SIM.
Sudden loss of mobile service; inability to make calls or receive SMS.
Remote access tool abuse
Victim is tricked into granting screen-sharing or remote control access.
Software installation requested by unsolicited caller; unusual device behaviour.
Early detection matters. The sooner a customer spots something unusual, the sooner the Fraud Management Team, and the customer themselves, can act to protect a super account online.
Some signs your super account may be compromised may include:
If any of these appear, treat them as urgent. Contact CFS immediately and, if you suspect your identity has been compromised more broadly, contact IDCARE.
CFS proactively monitors customer account activity to flag unusual events, engages with affected members, and provides clear information to help Australians protect their financial future.
Our dedicated Fraud Management Team watches for the patterns and anomalies that typically precede a super account takeover.
In Jane's case, that monitoring is why the $100,000 withdrawal was stopped before it left her account.
The team also plays an educational role, working one-on-one with affected members to help them secure their devices, review their personal information hygiene, and take the best next steps with agencies such as myGov and IDCARE.
To protect super account online access, a small number of practical steps make a significant difference.
Check out scam tips, news and alerts through the Australian Government’s Scamwatch website.
You can also subscribe to Scamwatch email alerts to keep up to date with the latest scams.
Account takeover fraud is when a criminal gains unauthorised access to a legitimate online account and uses it to move money or change payment details. In a super context, this can mean redirected pension payments, fraudulent rollovers, or attempted lump-sum withdrawals to bank accounts controlled by the fraudster.
Many one-time password interceptions begin with a compromised email inbox or a phone that has been SIM-swapped. Once the fraudster controls the channel that receives the OTP, they can complete logins and approve changes that appear legitimate to the fund.
Contact CFS immediately so the Fraud Management Team can review activity on your account. Then change the password on your email and FirstNet Investor logins from a secure device, and contact IDCARE on 1800 595 160 for identity recovery support.
IDCARE is Australia and New Zealand's national identity and cyber support community. Their specialist case managers help Australians affected by identity theft, including superannuation fraud Australia cases, work through recovery steps such as securing myGov, credit reporting, and device security.
Use a strong unique password, enable multi-factor authentication, secure your email inbox, never grant remote access to unsolicited callers, and review your account regularly for unfamiliar linked accounts or payment changes. These simple habits significantly reduce the risk of a super account takeover.
¹ Scam statistics, published by Scamwatch as at 31 August 2026.
Disclaimer
Information provided by Avanteos Investments Limited and Colonial First State Investments Limited. Consider the PDS and TMD at cfs.com.au to see if it’s right for you.
Avanteos Investments Limited ABN 20 096 259 979, AFSL 245531 (AIL) is the trustee of the Colonial First State FirstChoice Superannuation Trust ABN 26 458 298 557 and issuer of FirstChoice range of super and pension products. Colonial First State Investments Limited ABN 98 002 348 352, AFSL 232468 (CFSIL) is the responsible entity and issuer of products made available under FirstChoice Investments and FirstChoice Wholesale Investments.
Information on this webpage is provided by AIL and CFSIL. It may include general advice but does not consider your individual objectives, financial situation, needs or tax circumstances. You can find the target market determinations (TMD) for our financial products at https://www.cfs.com.au/tmd which include a description of who a financial product might suit. You should read the relevant Product Disclosure Statement (PDS) and Financial Services Guide (FSG) carefully, assess whether the information is appropriate for you, and consider talking to a financial adviser before making an investment decision. You can get the PDS and FSG at www.cfs.com.au or by calling us on 13 13 36.