“It’s simply not good enough.”
That’s how South Australian treasurer Stephen Mullighan reacted in parliament on Wednesday when he was asked about a cyber security breach involving government superannuation provider Super SA.
Information linked to more than 14,000 members was accessed by hackers about two months ago.
But Mr Mullighan said he only found out about the incident less than a fortnight ago.
It’s the second time in less than two years that private data from a state government agency, held by a third-party firm, has been illegally accessed.
In November 2021, hackers hit payroll provider Frontier Software, impacting more than 90,000 public servants.
Here’s what we know about the latest cyber security breach so far.
Cyber attack related to 2019 breach
The government said the most recent security breach stemmed from a previous cyber attack involving Super SA in November 2019.
Data pertaining to 14,011 Super SA members was accessed during the hack.
To help respond to members caught up in the incident, Super SA hired the services of a call centre — Adelaide-based company Contact 121 — in 2020.
After its contract with Super SA ended, the government said, Contact 121 kept data about the members and about two months ago that information was accessed.
The government said Super SA became aware of the latest cyber security incident on September 1 this year, but it didn’t receive confirmation that a breach had occurred until October 4.
It said all members who were implicated in the 2019 cyber breach were also impacted by this latest attack.
Mr Mullighan told parliament last week the Department of the Premier and Cabinet was informed of the latest cyber breach on August 18, but he was only told on Thursday, October 12.
“Government agencies need to do a much, much better job at firstly, trying to insulate themselves as best they can against these attacks in the first place, but secondly respond to them in a timely, thorough and appropriate way,” he said on Wednesday.
Government still investigating breach
Mr Mullighan said the government was investigating why Contact 121 had retained Super SA members’ data on its systems.
“That raises … a series of further questions — what requirements are there for these agencies to not continue holding government data on their ICT systems after they complete doing work for government?” he told parliament on Wednesday.


