Regulators warned licensees. Now scammers are testing whether they listened

ASIC's phishing alert is the scenario its May open letter anticipated - and social engineering losses often land in sublimited or excluded territory under standard cyber policies

Regulators warned licensees. Now scammers are testing whether they listened

Cyber

By Roxanne Libatique

Three months before warning that scammers were impersonating its staff to target financial services firms, the Australian Securities and Investments Commission (ASIC) told every licensee in the country that the clock was at a minute to midnight on cyber resilience. This week’s spear phishing alert is the threat that letter was anticipating – and it exposes a coverage gap that insurance brokers are well placed to address.

ASIC confirmed on August 17, 2026, that it had received multiple reports of scammers targeting personnel at market operators and financial businesses by posing as ASIC staff via email. The campaign uses spoofing – technology that replicates a legitimate @asic.gov.au sender address – to deceive recipients into clicking malicious links, disclosing credentials, or sharing confidential business information. ASIC said AI is enabling scammers to personalise attacks at scale, lowering both the cost and the skill threshold required to execute them.

The coverage question behind the operational alert

The attack that ASIC has described – an employee deceived by a convincing email, rather than a system directly compromised – is precisely where most cyber policies apply sublimits rather than full aggregate cover, and where some exclude the loss entirely. Funds transfer fraud sublimits are often set as low as $100,000 or $250,000 on a $1 million policy because insurers treat social engineering losses differently from network intrusions – the loss is severe, but no system was technically breached.

That technical distinction is the mechanism that creates the gap. When an employee is deceived into acting rather than a system being compromised, some insurers classify the event as a crime loss rather than a cyber loss, placing it outside the core cyber insuring agreement. Many Australian policies exclude losses from business email compromise or invoice fraud where no system was actually compromised, with social engineering cover often available only as an optional add-on.

According to a market guide published by Australian managed security provider Epic IT in June 2026, cyber policy wordings from 2024 and 2025 are substantially different from 2022 wordings, with broker-supplied summaries not always reflecting those changes – particularly around social engineering sublimits, ransomware payment caps, and exclusions for unsupported operating systems. Social engineering remains a common attack vector in Australia, with threat actors impersonating trusted parties to obtain access credentials, according to Gallagher’s September 2025 Cyber Insurance Market Update.

What ASIC has already told licensees

The August 17 alert does not arrive in a regulatory vacuum. In May 2026, ASIC Commissioner Simone Constant issued an open letter directly to all AFS licensees and market participants, instructing that it be tabled at board and risk governance committees. The letter called on all licensees and market participants to urgently strengthen their cyber resilience measures as frontier AI intensifies the global cyber risk environment, reminding industry that cyber resilience must be treated as a core licensing obligation, not simply an IT issue.

Commissioner Constant’s language was direct. “The clock is at a minute to midnight – if you aren’t on top of your cyber resilience already, the time to act and prepare is right now,” she said. The letter identified 12 specific actions for entities, including strengthening email security, reviewing user access privileges, preparing incident response playbooks, and actively managing third-party risks. That regulatory posture is backed by enforcement action. FIIG Securities was ordered to pay $2.5 million – the first time the Federal Court imposed civil penalties for cybersecurity failures under general AFS licensee obligations – with ASIC describing the outcome as setting a clear licence-to-operate expectation for robust cyber resilience. ASIC also filed civil proceedings against Fortnum Private Wealth in July 2025 over alleged failures to manage cybersecurity risks.

A single cyber incident can simultaneously engage the AFS licensing regime under ASIC, the prudential standards enforced by the Australian Prudential Regulation Authority (APRA) under CPS 234, the Notifiable Data Breaches (NDB) scheme under the Privacy Act enforced by the Office of the Australian Information Commissioner (OAIC), and in some cases the Security of Critical Infrastructure Act – each regime generating its own response obligations and cost exposure.

The data context

Cyber risk was cited by 91% of APRA-regulated banks, insurers, and superannuation trustees as a critical or high risk in APRA’s 2025 Stakeholder Survey – the top concern by a 20-percentage-point margin. Financial and insurance services rose to become the most frequently reporting non-government sector for cyber incidents in FY2024-25, according to the Australian Signals Directorate’s (ASD) Australian Cyber Security Centre (ACSC). The OAIC recorded 1,205 data breach notifications in 2025 – the highest annual total since the NDB scheme commenced in 2018 – with financial services the second most-affected sector at 157 notifications.

What brokers should raise before renewal

ASIC confirmed all legitimate communications originate from addresses ending in @asic.gov.au. Recipients should verify the full “from” field rather than the display name alone and can confirm correspondence by calling ASIC on 1300 935 075. Where a suspicious email arrives at a business address, ASIC recommended immediate internal IT notification, given the likelihood that multiple staff in the same organisation have been targeted simultaneously.

The alert gives brokers a specific, timely basis for raising coverage conversations with financial services clients before renewal. The questions worth raising with clients and their insurers include: whether the policy responds to social engineering losses where no network intrusion occurred; what sublimit applies to business email compromise; whether regulatory investigation costs – covering ASIC, APRA, and OAIC responses – fall within scope; whether a commercial crime policy provides layered cover for losses that fall outside the cyber trigger; and whether recent policy cycles have introduced AI-specific exclusions or narrowed existing social engineering definitions.

Under Section 912A of the Corporations Act 2001, AFSL holders must ensure representatives are adequately trained and that risk management systems are adequate. A phishing incident that succeeds because of insufficient staff protocols is not only a cyber event – it is a potential licence compliance failure. Brokers who surface that connection, and who identify coverage gaps before a claim, are delivering the market intelligence that distinguishes specialist advice from policy placement.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!