Australia’s superannuation sector is preparing to put its cyber defences through a major stress test, with 15 funds set to participate in a coordinated exercise designed to simulate a significant attack on the industry.
The Gateway Network Governance Body (GNGB) will run its annual Operation Honey Bee exercise on August 19, bringing together more than 50 participants from superannuation funds, administrators, gateway operators, regulators and government agencies. The 2026 event will be the fourth iteration of the sector-wide exercise and its largest to date.
Rather than focusing solely on whether individual funds can repel an attack, the exercise will examine how the broader superannuation ecosystem responds when multiple organisations are affected.
Participants will work through a simulated cyber incident, testing collective response plans, information sharing and coordination between funds and critical service providers. The exercise is also intended to identify capability gaps, shared risks and areas where organisations’ response and recovery plans may not align.
That interconnectedness is particularly important in superannuation. GNGB oversees the Superannuation Transaction Network, which supports the movement of contribution and rollover data between employers, super funds and the Australian Taxation Office. A cyber incident affecting one participant therefore has the potential to create consequences elsewhere in the system.
Cyber resilience under scrutiny
The exercise follows heightened scrutiny of cyber security across Australia's super industry after coordinated credential-stuffing attacks hit several major funds in 2025.
Those attacks used credentials obtained from previous data breaches to attempt logins to members' super accounts and prompted regulators to demand stronger authentication protections across the sector.
The Australian Prudential Regulation Authority subsequently warned of “persistent weaknesses” in information-security controls, particularly authentication, and directed super trustees to assess their controls and ensure multi-factor authentication or equivalent safeguards were being applied to high-risk activities and privileged access.
APRA has also stressed that cyber resilience cannot be treated purely as an issue for individual funds. Following the 2025 attacks, the regulator said cooperation and coordination across the sector would be critical to protecting a superannuation system responsible for more than $4 trillion of Australians' retirement savings.