Public incident case study · Financial services · Australia

FIIG Securities Case Study

2023 cyber-attack · Federal Court outcome 2026

A$3.0Mcourt-ordered financial outcomeA$2.5M penalty + A$500k ASIC costs
385GB
confidential information stolen
18,000
clients notified
4+ years
cybersecurity failures cited
~A$3B
client assets held while deficiencies persisted
Executive summary

Incident sequence

  1. Control gaps persisted

    From March 2019 to June 2023, FIIG admitted inadequate resources, controls, risk management, monitoring, and cybersecurity measures.

  2. Attack went undetected

    An adversary was in FIIG’s network from 19 May to 8 June 2023. The Court found FIIG’s failures enabled and worsened the breach.

  3. Sensitive data was exposed

    Stolen data included identity documents, bank account details, tax file numbers, names, addresses, and dates of birth.

  4. Regulatory consequence

    The Federal Court imposed a A$2.5M penalty, A$500k toward ASIC costs, and an independent-expert compliance program.

Full incident chronology

Incident timeline

Incident chronology.

  1. Mar 2019–Jun 2023

    Control environment

    Cyber-risk deficiencies persisted for more than four years

    FIIG admitted that resources, controls, monitoring, risk management, and other cybersecurity measures remained inadequate across the period identified by ASIC.

  2. Initial compromise

    An adversary entered FIIG's network

    The Federal Court record places the start of the attacker’s presence on 19 May, beginning a compromise that remained undetected for nearly three weeks.

  3. 19 May–8 Jun 2023

    Attacker dwell

    The intrusion continued without detection

    During the dwell period, the attacker accessed FIIG systems and obtained confidential information before the activity was identified.

  4. Detection

    FIIG identified the compromise

    Detection ended the documented attacker-presence period and initiated the breach response and subsequent regulatory scrutiny.

  5. Federal Court outcome

    The Court imposed penalties and independent oversight

    FIIG was ordered to pay a A$2.5 million penalty, contribute A$500,000 to ASIC’s costs, and implement an independent-expert compliance programme.

  6. Public enforcement record

    ASIC published the concluded enforcement action

    ASIC’s release connected the penalty to FIIG’s admitted prolonged cybersecurity deficiencies and the consequences of the 2023 breach.

Lykos analysis

What organisations should learn.

Why this matters to executives and boards

Cybersecurity became a licence-to-operate issue. The enforcement outcome ties prolonged deficiencies in resources, governance, risk management, monitoring, and response capability to legal and financial consequence.

Readiness gaps visible in the public record

The record identifies gaps including MFA for remote access, privileged-access controls, security configuration, vulnerability scanning, patching, threat-alert monitoring, staff training, and incident response testing.

How Lykos helps

Turn the lesson into tested capability.

Governance

Test authority, escalation, and executive oversight before an incident makes governance gaps public.

Explore IR Assurance

Monitoring and detection

Use threat hunting and compromise assessment to test what existing telemetry can actually prove.

Explore Threat Operations

Asset and vulnerability management

Establish whether critical assets, exposures, and remediation priorities are known before response begins.

Explore Capability Validation

Not sure where to begin? Start with Capability Validation.

Public record

Sources

Public record reviewed 21 Aug 2026.

  1. Australian Securities and Investments Commission v FIIG Securities Limited [2026] FCA 92Federal Court of Australia · 13 Feb 2026 · Court judgment
  2. ASIC action sees FIIG Securities ordered to pay $2.5 million over cyber security failuresAustralian Securities and Investments Commission · 13 Feb 2026 · Regulator