What happened
Between 19 May and 8 June 2023, FIIG's IT systems were subject to a cyber-attack by a third-party actor, resulting in unauthorised access and theft of personal information. FIIG became aware of the incident on 2 June 2023, when it was notified by the Australian Cyber Security Centre (ACSC).
Data was accessed from our systems and was subsequently published externally.
What we did
As soon as we became aware that a third party had illegally accessed our IT systems, we activated our cyber breach response plan. As part of that process, our IT systems and our client-facing portal were temporarily taken offline while we worked on immediate resolution.
We acted with urgency to investigate and contain the incident to protect the security and privacy of the data we hold. This included the initiation of our cyber response strategy, working with third-party cybersecurity experts and isolating all affected systems.
We contacted affected individuals. We reported the incident to government bodies and regulators, including the Department of Home Affairs, the Australian Cyber Security Centre (ACSC) and Australian Federal Police (AFP), the Australian Securities and Investments Commission (ASIC), the Australian Prudential Regulation Authority (APRA), and the Office of the Australian Information Commissioner (OAIC).
Were clients' trades impacted?
The cyber-attack on our IT systems did not impact any client assets held in trust with JP Morgan. FIIG's priority was to fulfil obligations regarding the settlement of open trades and the transfer of client money. FIIG successfully settled trades on the first settlement day following the incident, and trading is completely restored and operating as expected.
What support was offered to impacted clients?
Within days of the cyber incident, FIIG partnered with IDCARE, Australia's national identity and cyber support community service, whose expert Case Managers worked with individuals addressing concerns in relation to personal information risks and any instances where information may have been misused.
FIIG also reimbursed impacted clients with re-issue and reimbursements of impacted identification documents. This reimbursement program has now been completed.
What was the impact?
Approximately 18,000 individuals were notified of the breach. Of these, 5,700 to 6,460 were private clients, who were a mix of retail and wholesale clients that were potentially impacted.
What support was offered to impacted clients?
Within days of the cyber incident, FIIG partnered with IDCARE, Australia's national identity and cyber support community service, whose expert Case Managers worked with individuals addressing concerns in relation to personal information risks and any instances where information may have been misused.
FIIG also reimbursed impacted clients with re-issue and reimbursements of impacted identification documents. This reimbursement program has now been completed.