Public incident case study · Financial services · Australia
FIIG Securities Case Study
2023 cyber-attack · Federal Court outcome 2026
- 385GB
- confidential information stolen
- 18,000
- clients notified
- 4+ years
- cybersecurity failures cited
- ~A$3B
- client assets held while deficiencies persisted
Executive summary
Incident sequence
Control gaps persisted
From March 2019 to June 2023, FIIG admitted inadequate resources, controls, risk management, monitoring, and cybersecurity measures.
Attack went undetected
An adversary was in FIIG’s network from 19 May to 8 June 2023. The Court found FIIG’s failures enabled and worsened the breach.
Sensitive data was exposed
Stolen data included identity documents, bank account details, tax file numbers, names, addresses, and dates of birth.
Regulatory consequence
The Federal Court imposed a A$2.5M penalty, A$500k toward ASIC costs, and an independent-expert compliance program.
Full incident chronology
Incident timeline
Incident chronology.
- Mar 2019–Jun 2023
Control environment
Cyber-risk deficiencies persisted for more than four years
FIIG admitted that resources, controls, monitoring, risk management, and other cybersecurity measures remained inadequate across the period identified by ASIC.
Initial compromise
An adversary entered FIIG's network
The Federal Court record places the start of the attacker’s presence on 19 May, beginning a compromise that remained undetected for nearly three weeks.
- 19 May–8 Jun 2023
Attacker dwell
The intrusion continued without detection
During the dwell period, the attacker accessed FIIG systems and obtained confidential information before the activity was identified.
Detection
FIIG identified the compromise
Detection ended the documented attacker-presence period and initiated the breach response and subsequent regulatory scrutiny.
Federal Court outcome
The Court imposed penalties and independent oversight
FIIG was ordered to pay a A$2.5 million penalty, contribute A$500,000 to ASIC’s costs, and implement an independent-expert compliance programme.
Public enforcement record
ASIC published the concluded enforcement action
ASIC’s release connected the penalty to FIIG’s admitted prolonged cybersecurity deficiencies and the consequences of the 2023 breach.
Lykos analysis
What organisations should learn.
Why this matters to executives and boards
Cybersecurity became a licence-to-operate issue. The enforcement outcome ties prolonged deficiencies in resources, governance, risk management, monitoring, and response capability to legal and financial consequence.
Readiness gaps visible in the public record
The record identifies gaps including MFA for remote access, privileged-access controls, security configuration, vulnerability scanning, patching, threat-alert monitoring, staff training, and incident response testing.
How Lykos helps
Turn the lesson into tested capability.
Governance
Test authority, escalation, and executive oversight before an incident makes governance gaps public.
Explore IR AssuranceMonitoring and detection
Use threat hunting and compromise assessment to test what existing telemetry can actually prove.
Explore Threat OperationsAsset and vulnerability management
Establish whether critical assets, exposures, and remediation priorities are known before response begins.
Explore Capability ValidationNot sure where to begin? Start with Capability Validation.
Public record
Sources
Public record reviewed 21 Aug 2026.
- Australian Securities and Investments Commission v FIIG Securities Limited [2026] FCA 92Federal Court of Australia · 13 Feb 2026 · Court judgment
- ASIC action sees FIIG Securities ordered to pay $2.5 million over cyber security failuresAustralian Securities and Investments Commission · 13 Feb 2026 · Regulator