Join
Join

Helping to protect your super from online fraud and scams

At Hostplus, protecting your personal and financial information is a top priority. While our security controls work to safeguard your personal identifiable information, you can also take additional steps. Together, we can help protect you and your super from fraud and scams.

People protect personal information on computer, information security and encryption, secure access to user's personal information. Digital connections, Cyber security internet and networking concept.
Laptop, screen and business man for coding, software development and programming script in cybersecurity. Night, computer research and programmer or IT person with html code, system or data analysis.

About super fraud

Online fraud relating to super happens when a cybercriminal manipulates or gains unauthorised access to a super account, often using stolen personal information obtained through hacking, phishing or malware. Once they have access to your account, a cybercriminal can attempt to withdraw or transfer your super or pension balance.

About super scams

Super scams can take many forms. In some cases, scammers may try to trick you into giving up your sensitive data and information. In others, pushy sales tactics or exaggerated promises might be used to pressure you into transferring your super into high-risk or unregulated investments. It’s important to be aware of these tactics, and the red flags to watch for when making any decisions about your super. 

 

Scammers typically try to illegally access super in two main ways: through self-managed super funds, known as SMSFs, and through the process of claimingthe early release of super. 

It’s important for you to be aware of tactics that scammers use when targeting super. Cold calls from advisers or representatives who are not associated with your super fund should always be treated with caution.

In some cases,  scammers may try to transfer your super to an account they control by convincing you to ‘get control’ of your super. Others might try to encourage you to transfer some or all your balance to an SMSF, or into a high-risk scheme, by claiming that your fund is underperforming or making promises of high returns. If you’re unsure, seek advice from a qualified and licensed financial adviser before making any decisions, or call your existing super fund.

Under federal legislation, superannuation benefits must be ‘preserved’ for retirement. Benefits must remain within a complying superannuation fund like Hostplus, and can only be paid when a member meets a condition of release, such as retirement.  

Offers of quick and easy access to your super may not meet these conditions of release and could be scams. 

Click here for more information about the approved situations and conditions for accessing your super early. 

  • Be cautious about cold calls from advisers or representatives who are not associated with your superfund. 
  • Before making any decisions, call your existing super fund to find out what benefits you might lose if you exit, and speak to a financial adviser (for Hostplus members, this advice is available at no extra cost). 
  • Watch for red flags, like claims that your fund is underperforming, pressure to act fast and promises of unusually high returns. 
  • Check the history and performance of any investment option. 
  • Never be rushed into making a decision about your super. 
  • Ask your qualified and licensed adviser why a particular investment is right for you. 
canva-call-center-female

How we help protect you against fraudulent activity

There are many ways Hostplus works to secure your personal and financial information.  

We have specific preventative and detective controls that include:  

  • an industry-leading platform with multi-factor authentication (MFA) that notifies members via email of suspicious login attempts or logins from devices or browsers not previously used 
  • web application firewalls with protection to block automated programs (‘bots’) used in attacks 
  • industry-recognised email security validation measures to safeguard your data and ensure secure communication 
  • additional identification verification points through our customer-facing teams  
  • 24x7 security monitoring by threat detection and response specialists  
  • robust financial crimes detection and response processes 
  • engagement with law enforcement and regulators as needed. 

How does multi-factor authentication work?

Hostplus uses multi-factor authentication (MFA) to protect against unauthorised access to your information and accounts. When accessing your account online, you must enter a one-time PIN (OTP).   

You'll need an OTP to log in to Member Online and Pension Online. 

You'll also need an OTP to register for the Hostplus mobile app for the first time. Once registered, the mobile app uses a secure digital certificate and biometric or PIN identification to deliver seamless MFA without the OTP. Further information on this important security feature can be found here

Man on the phone, working from home

Steps to help protect yourself

Hostplus has many lines of defence against scammers and fraudulent activity. Here are some tips to help protect yourself from potential fraud: 

  • Stay vigilant. Remain alert to increased scam activity, especially email, SMS and telephone phishing scams. These are fraudulent communications that appear to come from an organisation you trust, including Hostplus.  
  • Protect your credentials. Always keep your security codes, PINs and passwords private. Store them only in a reputable password manager. At Hostplus, we would never ask you to share your password or OTP with us. 
  • Be wary of unsolicited offers to transfer your super or access it early. If it sounds too good to be true, it probably is. 
  • Do not provide remote access to your computer or device to unknown third parties. They may use this access to try to steal your information. 
  • Be cautious of unexpected emails and texts. Hover over links to check for misspelled web domain names and unusual sender email addresses. They can contain links that can damage your security. Official Hostplus emails come from addresses ending with hostplusmail.com.au or hostplus.com.au (for example, noreply@email.hostplus.com.au). 
  • Report suspicious activity. If you detect suspicious activity or receive OTPs you didn’t initiate, notify the provider sending them, as this may indicate someone is trying to access your account with your password. 
  • Use strong passphrases. Opt for unique, long (15+ characters) and unpredictable passphrases instead of passwords. Enable MFA on all online accounts where possible. More information about using MFA and passphrases can be found in the Australian Cyber Security Centre guidelines here
  • Maintain security software. Ensure any device you use to access your online accounts has up-to-date anti-virus or similar security protections.  
  • Keep your systems updated. Regularly apply software and operating system updates on your devices. 
  • Monitor your account. Stay up to date about your Hostplus account by downloading the Hostplus mobile app and enabling mobile app and email notifications. Read all correspondence from Hostplus, including notification alerts and your annual statement. 

What to do if you think your Hostplus account has been hacked or scammed

Contact Hostplus immediately on 1300 467 875 if you receive a suspicious call or email, or an alert for something you didn’t initiate.  Change your password immediately if you think someone has it. Notify Hostplus and your other financial institutions if this has happened. 

Helpful resources