X
  • About
  • Advertise
  • Contact
  • Events
Subscribe to our Newsletter
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
No Results
View All Results
Home News Regulation

Investment firm sued by ASIC over breach linked to Russian ransomware gang

The financial regulator has announced it is pursuing an Australian investment firm over data breach in 2023 linked to the Russian ransomware gang ALPHV.

by David Hollingworth
March 13, 2025
in News, Regulation
Reading Time: 3 mins read
Share on FacebookShare on Twitter

The Australian Securities and Investment Commission (ASIC) has revealed it is suing FIIG Securities regarding alleged cyber security failures in the lead-up and response to a ransomware-related data breach in May and June of 2023.

“ASIC alleges from March 2019 to 8 June 2023, FIIG failed to take the appropriate steps, as is required by an Australian Financial Services (AFS) licensee, to ensure it had adequate cyber risk management systems in place,” ASIC said in a 13 March press release, referring to documents filed with the Federal Court of Australia.

X

According to ASIC, it was this lack of preparedness that allowed a Russian ransomware operator to gain access to FIIG’s network 19 between May and 8 June in 2023. This compromise saw the hackers steal 385 gigabytes of data, which the ALPHV ransomware gang published shortly after.

The stolen data included scans of driver’s licenses and passports, bank details, tax files numbers, and commercially confidential data. In the wake of the data breach, FIIG notified approximately 18,000 clients that their personal data may have been compromised.

FIIG was warned of a potential intrusion by the Australian Signals Directorate’s (ASD) Australian Cyber Security Centre (ACSC) on 2 June but was not aware of any network compromise prior to that date. FIIG’s own investigations did not occur until 8 June.

ASIC is seeking “declarations of contraventions, civil penalties and compliance orders” regarding FIIG’s alleged failures to properly configure and monitor its network firewalls, address security vulnerabilities within systems, provide adequate cyber security training to staff, and have the necessary human and technical resources in place to protect the company, its clients and their data.

“This matter should serve as a wake-up call to all companies on the dangers of neglecting your cyber security systems,” ASIC chair Joe Longo said in a statement.

“Cyber security isn’t a set-and-forget matter. All companies need to proactively and regularly check the adequacy of their cyber security measures and follow the advice of the ASD’S ACSC.

“Australian financial services licensees are required by law to have adequate cyber security risk management systems in place. We allege FIIG’s inadequate cyber security measures left the business and its confidential client information vulnerable and exposed to significant risk.”

At the time of the incident, several worried clients expressed their dismay to the ABC.

“It points to perhaps a certain negligence or complacency on the part of FIIG, which I find rather surprising given the high-profile cases of cyber security incidents we’ve seen in recent years,” one client told the national broadcaster.

“To get right down into the details of whether sensitive information that’s not required is being retained inappropriately, to make sure that sensitive data that’s not needed is securely destroyed.”

FIIG Securities has acknowledged ASIC’s civil proceedings and noted that “no client investments or funds were accessed as a result of the cyber incident”.

“The proceedings relate to that cyber incident only and there have been no further incidents since May 2023,” A FIIG spokesperson told InvestorDaily’s sister brand Cyber Daily.

“FIIG is considering the claims made by ASIC and will respond as appropriate. FIIG does not intend to make any further public comments regarding the proceedings at this time.”

Related Posts

Janus Henderson to go private following US$7.4bn acquisition

by Laura Dew
December 23, 2025

Global asset manager Janus Henderson has been acquired by Trian Fund Management and General Catalyst in a US$7.4 billion deal....

Australian Super targets $1trn within a decade

by Adrian Suljanovic
December 22, 2025

Australia’s largest superannuation fund has announced it is targeting $1 trillion in assets by 2035, up from its current size...

The biggest people moves of Q4

by Olivia Grace-Curran
December 22, 2025

InvestorDaily collates the biggest hires and exits in the financial service space from the final three months of 2025. Movements...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Why U.S. middle market private credit is a powerful income solution for Australian institutional investors

In today’s investment landscape, middle market direct lending, a key segment of private credit, has emerged as an attractive option...

by Tim Warrick
December 2, 2025
Promoted Content

Is Your SMSF Missing Out on the Crypto Boom?

Digital assets are the fastest-growing investment in SMSFs. Swyftx's expert team helps you securely and compliantly add crypto to your...

by Swyftx
December 2, 2025
Promoted Content

Global dividends reach US$519 billion, what’s behind the rise?

Global dividends surged to a record US$518.7 billion in Q3 2025, up 6.2% year-on-year, with financials leading the way. The...

by Capital Group
November 18, 2025
Promoted Content

Why smaller can be smarter in private credit

Over the past 15 years, middle market direct lending has grown into one of the most dynamic areas of alternative...

by Tim Warrick, Managing Director of Principal Alternative Credit, Principal Asset Management
November 14, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Latest Podcast

Podcast

Relative Return Insider: MYEFO, US data and a 2025 wrap up

by Staff Writer
December 18, 2025
After more than two decades, InvestorDaily continues to be an institution that connects and influences Australia’s financial services sector. This influential and integrated media brand connects with leading financial services professionals within superannuation, funds management, financial planning and intermediary distribution through a range of channels, including digital, social, research, broadcast, webcast and events.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • Markets
  • Appointments
  • Regulation
  • Super
  • Mergers & Acquisitions
  • Tech
  • Promoted Content
  • Analysis

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Markets
  • Regulation
  • Super
  • M&A
  • Tech
  • Appointments
  • Podcast
  • Webcasts
  • Promoted Content
  • Events
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited