Your super and investment savings represent years of hard work for a secure future. Unfortunately, they can be a prime target for scammers, causing significant financial loss and emotional distress.

Financial scams are on the rise and becoming more sophisticated, making them harder to detect. This page will help you recognise common types of super and investment scams, how to identify them, and how to protect yourself and your loved ones.

Think you might be facing a scam?

Click here to learn the best steps to take immediately.

image-01

Protect yourself from scams

  • Outright reject suspicious contacts
  • Use strong and unique passwords
  • Avoid using public Wi-Fi
  • Lock and shield your screen in public
  • Enable multi-factor authentication (MFA) for additional security
  • Stay informed about current scams targeting financial services, including super.
img-02

Remember, MLC will never ask for:

  • Your Online Banking Security login details
  • Your *product name* details
  • Help to catch cyber criminals or assist with internal investigations
  • Your money to be moved to a "safe" account, or to any account with another bank.

Impersonation scams

Impersonation scams impersonate authorities like police, government, banks, and well-known businesses to gain your trust.

For example, we have seen scammers pretending to be from Insignia Financial (OnePath's parent company) use cold calls to offer high-return investment accounts, or term deposits with “special one-time rates”. They may direct victims to legitimate websites to appear credible. These scams often feature genuine Insignia Financial logos/images to deceive victims, but upon closer inspection reveals discrepancies. For instance:

  • Addresses used are not actual Insignia Financial locations.
  • Website/domain name have variations such as additional symbols like “-“or additional letters. Examples include:
    • insigniafinancial-wm.com
    • insigniafinancial-clientportal.com
    • insigniafinancial.com--about-us.com

Scammer may email details about these investments. Please note that OnePath (and Insignia Financial) employees do not make unsolicited (cold) calls to promote products or business offerings.

Impersonation scams constantly evolve and exploit trusted brands to deceive victims. Visit Scamwatch for more information on impersonation scams.

Identity theft scams

These scams involve criminals stealing your personal information (name, date of birth, and Tax File Number). With this data, they can open bank accounts, credit cards, and other financial accounts in your name, leaving you with the debt and a damaged credit score.

We recommend that you:

  • Keep your personal information secure and beware of unsolicited messages asking for it.
  • Regularly check your bank accounts for suspicious activity.

If you suspect that your identity has been stolen, contact your bank or financial institution immediately and report the fraud to the Australian Cyber Security Centre.

Credential Stuffing

What is Credential stuffing and how can you protect yourself against it?

Cyber-attacks are evolving and becoming more sophisticated every day. One of the latest attacks allows hackers to access members' accounts using their stolen passwords, via a method known as Credential stuffing.

Credential stuffing is a type of cyber-attack whereby cyber criminals collect stolen usernames and passwords available on the dark web from previous data breaches, and then attempt to use those credentials on other websites or services. If an affected user uses the same password across multiple accounts, a successful credential stuffing attack could compromise all of their accounts.

To protect against this type of attack, it is important to follow the cyber security advice as given by the Australian Government with 3 easy steps:

  • Set up multi-factor authentication to add an extra layer of security to your online accounts.
  • Create strong and unique passphrases of 14 or more characters long. These passphrases should be different for each account you hold.
  • Install software updates regularly to keep your devices secure.

Please refer to the Australian Government's best cyber practices and protect yourself online at cyber.gov.au

Impersonation scams

Impersonation scams impersonate authorities like police, government, banks, and well-known businesses to gain your trust.

For example, we have seen scammers pretending to be from Insignia Financial (OnePath's parent company) use cold calls to offer high-return investment accounts, or term deposits with “special one-time rates”. They may direct victims to legitimate websites to appear credible. These scams often feature genuine Insignia Financial logos/images to deceive victims, but upon closer inspection reveals discrepancies. For instance:

  • Addresses used are not actual Insignia Financial locations.
  • Website/domain name have variations such as additional symbols like “-“or additional letters. Examples include:
    • insigniafinancial-wm.com
    • insigniafinancial-clientportal.com
    • insigniafinancial.com--about-us.com

Scammer may email details about these investments. Please note that OnePath (and Insignia Financial) employees do not make unsolicited (cold) calls to promote products or business offerings.

Impersonation scams constantly evolve and exploit trusted brands to deceive victims. Visit Scamwatch for more information on impersonation scams.

Identity theft scams

These scams involve criminals stealing your personal information (name, date of birth, and Tax File Number). With this data, they can open bank accounts, credit cards, and other financial accounts in your name, leaving you with the debt and a damaged credit score.

We recommend that you:

  • Keep your personal information secure and beware of unsolicited messages asking for it.
  • Regularly check your bank accounts for suspicious activity.

If you suspect that your identity has been stolen, contact your bank or financial institution immediately and report the fraud to the Australian Cyber Security Centre.

Credential Stuffing

What is Credential stuffing and how can you protect yourself against it?

Cyber-attacks are evolving and becoming more sophisticated every day. One of the latest attacks allows hackers to access members' accounts using their stolen passwords, via a method known as Credential stuffing.

Credential stuffing is a type of cyber-attack whereby cyber criminals collect stolen usernames and passwords available on the dark web from previous data breaches, and then attempt to use those credentials on other websites or services. If an affected user uses the same password across multiple accounts, a successful credential stuffing attack could compromise all of their accounts.

To protect against this type of attack, it is important to follow the cyber security advice as given by the Australian Government with 3 easy steps:

  • Set up multi-factor authentication to add an extra layer of security to your online accounts.
  • Create strong and unique passphrases of 14 or more characters long. These passphrases should be different for each account you hold.
  • Install software updates regularly to keep your devices secure.

Please refer to the Australian Government's best cyber practices and protect yourself online at cyber.gov.au

Stop, Protect, Report

Given the variety of scams out there, following these four steps can help prevent you falling victim to a scam.

If you receive a suspicious call, email, or text, pause and assess. Genuine organisations like OnePath never pressure you to act immediately or ask for your password via email.

Malware can target you through:

  • Emails or messages with links or attachments.
  • Malicious websites attempting to install malware.
  • Exploiting vulnerabilities in outdated software.

To spot malware, watch out for:

  • unusual account activity
  • Sluggish performance or rapid battery drain.
  • Unexpected or inaccessible files and frequent errors.
  • Automatic redirects to web pages you didn't intend to visit.

Cyber attackers piece together details from various sources to exploit and create accounts in your name. Whether it’s personal or work, staying vigilant is crucial. When in doubt, reject contact, delete suspicious messages, and avoid opening unknown links.

Avoid sharing your superannuation information

Be wary of the unknown

  • Always stop and think before opening attachments, clicking hyperlinks, or replying to suspicious emails. MLC will never ask for your password or provide a link to a login page for your account.

Never send personal information via email

  • Use secure document-sharing software like DocuSign instead.

Avoid using public Wi-Fi

  • It's vulnerable to cyber attacks.
  • Never share information about your superannuation with someone who contacts you, even if they seem to be from a trusted organisation. Always verify their identity by calling the organisation directly.

Thoroughly research investment opportunities

  • Be wary of high-return, low-risk investment opportunities - if it sounds too good to be true, it probably is.

Check against the ASIC website

  • If you're speaking with a financial adviser, verify their registration on the ASIC website. Anyone offering advice about financial products must hold an Australian Financial Services license from ASIC.

Protecting yourself from scams:

  • Outright reject suspicious contacts
  • Use strong and unique passwords
  • Avoid using public Wi-Fi
  • Lock and shield your screen in public
  • Enable multi-factor authentication (MFA) for additional security
  • Stay informed about current scams targeting financial services, including super.

Remember, OnePath will never ask for:

  • Your Online Banking Security login details
  • Your *product name* details
  • Help to catch cyber criminals or assist with internal investigations
  • Your money to be moved to a "safe" account, or to any account with another bank.

If you receive a suspicious email, do not click on any links or attachments or provide any information.

If you have responded to a phishing email, contact us immediately on 133 665 between 8:30 am and 6:30pm AEST/AEDT, Monday to Friday.

You can report suspicious emails by forwarding them to client@onepathsuperinvest.com.au.

We investigate every email reported. Where possible, please send the suspicious email as an attachment on a new email.

If you receive a suspicious email not related to OnePath, you can report it to the Australian Cyber Security Centre (ACSC).

More information and resources

Additional support

Here’s some useful information about how we protect your online security, along with some practical tips to help you stay safe online.

MoneySmart website

Spot the warning signs of financial scams with MoneySmart’s in-depth coverage of scam typologies.

Government websites

The Federal Government also has several useful resources with information on how to protect yourself.

Not all frauds and scams are conducted online

Find out more

Think you may be facing a scam?

If you have responded to a phishing email, contact us immediately on 133 665 between 8.30am and 6.30pm AEST/AEDT, Monday to Friday. You can report suspicious MLC emails by forwarding them to phish@mlc.com.au.