Australian financial services licensees are facing spear-phishing campaigns in which criminals insert themselves into existing email threads posing as Australian Securities and Investments Commission staff, the corporate regulator said Wednesday.

The alert follows a fortnight in which three AFSL holders reported fraudulent “urgent compliance review” messages that referenced real meeting dates and adviser names harvested from LinkedIn. ASIC executive director Sarah Court said the messages linked to cloned ASIC Connect pages and asked recipients to reset passwords through a look-alike myGov gateway.

How the threads start

Attackers compromise a weak mailbox at a small accounting firm, then monitor outgoing correspondence with licensees. When a genuine ASIC notification arrives about annual fee invoices, the intruder replies-all within minutes with a PDF attachment labelled breach determination. The PDF contains a QR code leading to a phishing site hosted on recently registered .com domains with TLS certificates mimicking government styling.

Court said ASIC never requests portal credentials by reply email and does not use QR codes in enforcement notices. Legitimate communications direct users to type asic.gov.au manually or use bookmarked Connect logins with passkeys where enabled.

Who is being hit

The Australian Financial Complaints Authority separately noted an uptick in calls from retirees who received follow-on calls after advisers’ inboxes were breached. Cybersecurity firm CyberCX told InfoHandle Network that at least 40 domains impersonating ASIC were registered in September, many using homoglyph characters in the subdomain.

Licensees must report suspicious contact under breach reporting rules if client data may have been accessed. ASIC said it is coordinating with the Australian Cyber Security Centre to seize domains and has referred two incidents to the AFP for identity-theft investigations.

Defensive steps

ASIC urged firms to enable DMARC quarantine policies, strip reply-all on external threads containing attachments, and train staff to verify breach claims through the published ASIC switchboard. The regulator also recommended advisers register for its free alert feed and compare message headers against known government mail exchangers.

For consumers, the message is simpler: ASIC will not ask for myGov details to unlock an investigation. Anyone contacted should hang up, delete the email, and call ASIC on its public number to confirm whether a matter exists.