Homepage / Cyber Security Response

Last updated: 12 August 2026

Cyber Security Response Centre

Transparency, accountability, and an ongoing commitment to protecting your information.

LATEST UPDATE

Settlement Reached: February 2026

ASIC brought proceedings against FIIG Securities in relation to the 2023 cybersecurity incident, and those proceedings have now concluded. We accept the Court's findings regarding these historical cybersecurity shortcomings.

FIIG has undertaken a comprehensive uplift of its cybersecurity, governance and risk management frameworks to better protect customer data and will continue to do so with the support of its parent company, AUSIEX. This has included significant investment in technology, enhanced monitoring and detection capabilities, strengthened access controls, expanded cyber expertise, and improved incident response and staff training.

As part of the Court-enforceable outcome, FIIG is undertaking a comprehensive compliance program, including the engagement of an independent cybersecurity expert to review, assess and report on its systems and controls.


FIIG continues to invest in cybersecurity capability, and ongoing security enhancements to respond to evolving threats and help protect client information.

A Message from Our CEO

"Since the cybersecurity incident occurred in 2023, FIIG has cooperated fully with ASIC and other regulators. We have continued to strengthen our systems, governance, and controls. No client assets were impacted, and we remain focused on ensuring the ongoing security of our operations, including the protection of client information.

We have invested significantly in cybersecurity improvements and continue to work with cybersecurity experts to progress the ongoing strengthening, resilience and sustainability of our cybersecurity protections."

Patrick Salis

Patrick Salis

CEO, AUSIEX

The 2023 Cyber Incident: What Happened and How We Responded

What happened

Between 19 May and 8 June 2023, FIIG's IT systems were subject to a cyber-attack by a third-party actor, resulting in unauthorised access and theft of personal information. FIIG became aware of the incident on 2 June 2023, when it was notified by the Australian Cyber Security Centre (ACSC).

Data was accessed from our systems and was subsequently published externally.

What we did

As soon as we became aware that a third party had illegally accessed our IT systems, we activated our cyber breach response plan. As part of that process, our IT systems and our client-facing portal were temporarily taken offline while we worked on immediate resolution.

We acted with urgency to investigate and contain the incident to protect the security and privacy of the data we hold. This included the initiation of our cyber response strategy, working with third-party cybersecurity experts and isolating all affected systems.

We contacted affected individuals. We reported the incident to government bodies and regulators, including the Department of Home Affairs, the Australian Cyber Security Centre (ACSC) and Australian Federal Police (AFP), the Australian Securities and Investments Commission (ASIC), the Australian Prudential Regulation Authority (APRA), and the Office of the Australian Information Commissioner (OAIC).

Were clients' trades impacted?

The cyber-attack on our IT systems did not impact any client assets held in trust with JP Morgan. FIIG's priority was to fulfil obligations regarding the settlement of open trades and the transfer of client money. FIIG successfully settled trades on the first settlement day following the incident, and trading is completely restored and operating as expected.

What support was offered to impacted clients?

Within days of the cyber incident, FIIG partnered with IDCARE, Australia's national identity and cyber support community service, whose expert Case Managers worked with individuals addressing concerns in relation to personal information risks and any instances where information may have been misused.

FIIG also reimbursed impacted clients with re-issue and reimbursements of impacted identification documents. This reimbursement program has now been completed.

What was the impact?

Approximately 18,000 individuals were notified of the breach. Of these, 5,700 to 6,460 were private clients, who were a mix of retail and wholesale clients that were potentially impacted.

What support was offered to impacted clients?

Within days of the cyber incident, FIIG partnered with IDCARE, Australia's national identity and cyber support community service, whose expert Case Managers worked with individuals addressing concerns in relation to personal information risks and any instances where information may have been misused. 

FIIG also reimbursed impacted clients with re-issue and reimbursements of impacted identification documents. This reimbursement program has now been completed. 

What FIIG Is Doing to Protect Your Data

Protecting client information is central to how FIIG operates. FIIG takes a considered, risk-managed and ongoing approach to managing security risks across systems, people, and processes.

FIIG’s enhanced cybersecurity strategy involves applying a layered security approach. This means FIIG does not rely on a single control to prevent or detect threats. Instead, FIIG uses a combination of preventative, detective and responsive measures across technology infrastructure, governance, risk and staff practices.

These measures are supported by ongoing enhancement activities to ensure resilience and superior cybersecurity capabilities.

As part of FIIG's FY26/27 cybersecurity priorities, we remain focused on strengthening our cybersecurity capability and resilience. FIIG’s cybersecurity program of work is endorsed and supported by its parent company, Australian Investment Exchange Limited (AUSIEX), which has attained ISO/IEC 27001:2022 Information Security Management System certification demonstrating the group’s key commitment to excellence in cybersecurity protection.

AUSIEX: ISO/IEC 27001:2022 Certified

AUSIEX as the parent company of FIIG, holds an internationally recognised information security certification demonstrating adherence to the global standard for cybersecurity frameworks.

What is FIIG doing to prevent this from happening again?

FIIG has comprehensively engaged in significant uplift in its cybersecurity framework; some of the key initiatives of our comprehensive framework include:

Monitoring, Logging & Threat Detection

FIIG uses monitoring and alerting capabilities designed to help identify suspicious activity, phishing attempts, malicious websites and other potential security risks. This includes monitoring of key systems and services to support the investigation of unusual activity. FIIG also maintains centralised security logging to support monitoring, investigation and auditability, and continues to enhance these capabilities as part of its cybersecurity program.

Email & Web Security Controls

FIIG maintains controls designed to reduce exposure to phishing, malicious links and harmful content, and to help prevent access to known malicious destinations. These measures form part of FIIG's layered security approach and are intended to assist in reducing the risk of credential theft, malware infection and unauthorised access.

Endpoint & Device Security

Devices used within FIIG's environment are supported by endpoint security controls designed to reduce the risk of malware, unauthorised software and other malicious activity. FIIG also applies device access controls including secure login requirements and biometric authentication, and continues to strengthen endpoint security capabilities as part of its ongoing cybersecurity improvement program.

Sensitive Data Handling & Encryption

FIIG applies safeguards including controls relating to data access, secure storage and the protection of data stored at rest. FIIG also uses encryption to help protect sensitive information when transmitted across networks. Client identification documents are redacted and securely stored and encrypted once the account opening process has been completed.

Authentication & Access Controls

FIIG uses layered authentication and access controls. For client access to MyFIIG, multi-factor authentication (MFA) is used. Account holders receive a unique One Time PIN (OTP) on each login. FIIG also maintains enhanced controls for privileged accounts and access lifecycle management processes and continues to review these controls as part of its broader cybersecurity program.

Vulnerability Management & Hardening

FIIG's systems are configured using security-focused practices. This includes strengthening baseline settings, disabling unnecessary services and applying security updates. Since 2023, FIIG has invested significantly in strengthening its cybersecurity capability with the support of external cybersecurity specialists and continues to enhance its security controls through ongoing uplift.

Secure Software Development

FIIG incorporates security practices into the development and change process for applications and technology services. FIIG undertakes security testing including independent penetration testing and vulnerability assessments. FIIG maintains separation between development, testing and production environments.

Network Security & Segmentation

FIIG maintains network controls designed to support the protection of systems and reduce exposure to external threats. This includes network segmentation and access controls. Remote access is subject to security controls including strong authentication. FIIG continues to review and strengthen these controls as part of its cybersecurity program.

Backup, Resilience & Recovery

FIIG maintains backup and recovery controls designed to support system resilience and facilitate restoration in the event of disruption or a security incident. Backups and recovery processes are reviewed and improved over time to support operational resilience.

Third-Party Risk Management

FIIG assesses and manages cyber security risks associated with third-party service providers, including due diligence, contractual security expectations, and ongoing review proportionate to the services provided.

Employee Training & Awareness

FIIG employees receive ongoing training to support awareness of cybersecurity and privacy risks, including recognising phishing attempts and handling information appropriately. Training is reinforced through regular communications, simulated phishing exercises, and clear internal escalation pathways.

Incident Response & Testing

FIIG maintains processes designed to support the identification, management and remediation of security incidents. This includes periodic testing of incident response processes, such as simulations or tabletop exercises, to support readiness and continuous improvement.

Continuous Improvement

Cybersecurity risks change over time. FIIG regularly reviews and updates controls and processes to help ensure they remain appropriate as technology and threats evolve. This includes ongoing remediation activities, control enhancements, and review of security measures.

Is It Safe to Invest with FIIG?

Since the 2023 incident, FIIG has undertaken one of the most comprehensive cybersecurity uplift programs in the Australian financial services sector. Key points for prospective and existing investors:

  • No client assets were ever at risk. Client assets are held in trust with JPMorgan and were not affected by the cyber incident.
  • AUSIEX parent company backing. FIIG's parent company, Australian Investment Exchange Limited (AUSIEX), provides governance, technology and cybersecurity expertise and support.
  • ISO/IEC 27001:2022 certification. AUSIEX holds internationally recognised information security management certification.
  • Independent expert review and assurance.
  • Ongoing FY26-27 cyber investment strategy. FIIG continues to invest in enhancing its cybersecurity capability, recognising that protecting clients' assets and personal data is of paramount importance.

FIIG is now operating under one of the most rigorously reviewed cyber frameworks in the Australian financial services market.

How You Can Protect Yourself

Clients also play an important role in protecting their information. To help keep accounts secure:

FIIG will never ask for passwords or sensitive security information via email or SMS.

1

Stay Alert to Phishing

Exercise usual caution when replying to emails, phone calls and text messages. Don't open suspicious texts, pop-up windows or emails, or click on suspicious links or open unusual attachments. Ensure you thoroughly identify callers and don't divulge personal information to unknown parties.

2

Beware of Cyber Extortion

Cyber extortion is a cybercrime where criminals use threats to intimidate victims into taking specific actions against their will. Beware of attempts from scammers who use a data release on the dark web to demand payment. Do not engage with scammers. Report attempts to ReportCyber (cyber.gov.au).

3

Change Your Passwords Regularly

We recommend you change your passwords regularly. Follow the Australian Cyber Security Centre's guidance on creating strong passphrases.

4

Enable Enhanced Security on Bank Accounts

We recommend you carefully monitor any transactions for any unusual activity. If you detect unusual activity, contact your bank immediately. We recommend you enact Two Factor Authentication on all bank accounts.

5

Identification Documents

For individuals who provided ID documents upon opening or to maintain an account, we believe a copy of these documents has been accessed. This incident does not affect the validity of any driver's licence or passport. IDCARE can provide further guidance. FIIG reimbursed impacted people the cost to replace their driver's licence.

6

Tax File Numbers

To protect your Tax File Number information, you can contact the ATO and ask for additional security measures to be placed on your account (call 1800 467 033 during 8am to 6pm AEDT Monday to Friday).

7

Credit Monitoring

We recommend that you review and continue to monitor your consumer credit report for any discrepancies or unusual activity. You can apply for an annual free credit report from Equifax, Illion, or Experian. You can also place a temporary ban on your credit report.

8

Medicare

If a Medicare card copy belonging to you may have been exposed, the easiest way to replace your Medicare card is by using your Medicare online account through myGov. Visit servicesaustralia.gov.au/databreach. If concerned, contact the Scams and Identity Theft Helpdesk on 1800 941 126.

9

General Recommendations

Turn on two-factor authentication for online accounts where possible, including your email, banking, and social media accounts. Follow the ACCC's Scamwatch guidance for protecting yourself from scams. If you need assistance, visit cyber.gov.au or contact IDCARE on 1800 595 160.

Frequently Asked Questions

What steps can I take to protect myself?

See the detailed steps in the 'How You Can Protect Yourself' section above, which covers phishing awareness, password management, bank account security, identity document protection, tax file numbers, credit monitoring, and general recommendations.

How can I have my passport DVS blocked?

Contact your FIIG relationship manager or call 1800 01 01 81 by phone with your first name, last name, email, and passport number. Do not provide these details via email. FIIG will submit the details to the Australian Government DVS to block your passport from online verification.

What does having my passport blocked include?

A blocked passport means that it cannot be used to verify an identity online through the DVS for confirmation of identity checks for government departments and organisations such as banks and telecommunication companies.

Can I continue to use my passport for travel or identity verification?

If you choose to have your passport blocked, you can continue to use your passport to travel and verify your identity in person, including for government or financial services. You can still book international travel with your passport number online.

Can I have my passport unblocked?

Once blocked in the DVS system, a passport cannot be unblocked. If you replace or renew your passport, your current document will be voided, and your new document (with a new document number) will safely verify through the DVS.

Can I replace a passport blocked in the DVS system?

Yes, if you opt to have your passport blocked, you can still choose to replace or renew this document at a later date. More information is available at passports.gov.au.

What other documents can I use to verify my identity online via DVS?

The DVS service also accepts driver licences and Medicare cards. As long as these documents are not also flagged within the DVS system, they will continue to be able to be used for digital verification. FIIG is unable to block any documents other than passports within the DVS system.

Where can I find more information about passports and data breaches?

For more information on your passport being involved in a data breach, visit passports.gov.au/data-breaches. For more information on the Australian Government's Document Verification Service, visit idmatch.gov.au/our-services.

Information for individuals who may have supplied passport information

As part of the application process for becoming a FIIG client, we sometimes require a passport number and, in some instances, a scanned copy. This incident does not affect the validity of any passport for travel purposes. FIIG can facilitate a block on your passport using the Commonwealth Credential Protection Register (CPR) through the Department of Home Affairs.

Did ASIC take action against FIIG?

Yes. The Federal Court ordered FIIG to pay a $2.5 million penalty and pay $500,000 towards ASIC's costs. The Court also ordered FIIG to undertake a compliance programme involving the engagement of an independent expert to ensure its cyber security and cyber resilience systems are reasonably managed. For further details, see the ASIC media release. Link: https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-021mr-asic-action-sees-fiig-securities-ordered-to-pay-2-5-million-over-cyber-security-failures/

Need Help?

If you have questions about the cyber incident or need assistance protecting your information, please reach out through any of the following channels.

 

Call FIIG
1800 01 01 81
Report Cybercrime
cyber.gov.au/report
Report a Scam
scamwatch.gov.au