Fake Superannuation Scam Call Training 2026

Run practical fake superannuation scam call training in 2026 with scripts, verification rules, reporting steps and targeted follow-up.

Fake superannuation scam calls work because they borrow the language of retirement planning, urgent account action and helpful advice. This 2026 training guide gives managers a practical session plan for helping staff stop, verify and report a suspicious superannuation call without turning every legitimate enquiry into a crisis.

TL;DR

Why this matters

A caller may claim a fund is underperforming, an account needs urgent action, money can be accessed early, or a better return is available. They may sound informed and already know a name, employer or suburb. That is not authentication.

Moneysmart's guidance on pushy super calls says high-pressure sales tactics can put super savings at risk. The safe organisational response in 2026 is simple: an unsolicited caller does not set the timetable, the contact route or the next action.

Cyber Aware's phishing simulations help teams practise that response in a controlled setting, using realistic social-engineering pressure without collecting a password or financial detail.

What you'll need

Prepare a 35-minute session for payroll, HR, finance, customer service and any employee who may take calls involving personal information.

Use fictional names and account numbers. The session should teach a repeatable decision process, not encourage staff to investigate callers themselves.

Step 1: Define what a legitimate call can and cannot prove

Start by explaining that a caller's confidence, a familiar company name and partial personal information do not prove the caller is genuine. A real fund or adviser may contact a member, but a recipient should still verify the contact through a number or online account they obtained independently.

Ask staff to write down the one fact they must never provide during an unexpected call: passwords, one-time codes, full account details and identity documents all belong on that list. In 2026, a caller who asks for a code while remaining on the line is asking the target to bypass a security control.

Expected outcome: participants can explain that an inbound call is unverified until it is checked through a known channel.

Common mistake: accepting a caller ID label as proof. Phone numbers can be spoofed, and a label on a screen is not identity verification.

Step 2: Teach the pressure patterns

Run three short examples. The first claims the recipient can access super early. The second says a fund is underperforming and a transfer must happen today. The third offers a free health check but asks the employee to continue through an adviser they have never chosen.

Have the group identify the pressure device in each call: urgency, fear of missing out, a promise of better returns, or an attempt to isolate the target from independent advice. Moneysmart advises people to be cautious when unknown callers offer to compare or switch funds, especially where there is pressure to act now.

Expected outcome: staff can name the tactic before they judge the caller's story.

Common mistake: debating whether the promised financial result is realistic. The training goal is to stop unverified action, not to provide financial advice.

Step 3: Use the 60-second pause script

Give every participant the same script: “I do not make superannuation decisions on an unsolicited call. I will contact my fund using the details in my account or statement.” Then end the call.

Practise the script twice: once with a polite caller and once with a caller who insists that a deadline expires in 10 minutes. The script should not invite debate or reveal more information. A short, calm ending works better than trying to win an argument.

Expected outcome: each participant can end a suspicious call in under 60 seconds.

Common mistake: agreeing to a callback from the caller. If a discussion is needed, the employee should call the independently sourced number.

Step 4: Verify through a known route

After hanging up, open the official fund app or website through an existing bookmark, use a number on a statement, or ask the employer's approved contact to confirm the process. Do not search for the name and use the first advertising result, and do not call the number that appeared on the phone.

For staff who handle another person's information, the verification route should be written into the team procedure. A payroll employee does not need to determine whether an adviser is legitimate; they need to route the contact to the right internal owner.

Expected outcome: the next action happens outside the caller's control.

Common mistake: replying to a follow-up text sent by the caller. Treat the text as part of the same unverified channel.

Step 5: Report the call quickly

Ask staff to record the date, time, number shown, claimed organisation, requested action and any information disclosed. Then report it through the agreed security or fraud channel. A short report is enough; the employee does not need proof that the call was a scam.

Cyber Aware's human risk reporting gives managers a way to follow up on learning and phishing outcomes without treating an individual report as a failure. The goal is a faster signal when a campaign is reaching several people.

Expected outcome: suspicious calls are reported on the same day with enough detail to spot a pattern.

Common mistake: keeping quiet because no money was sent. The attempted manipulation is still useful intelligence.

Step 6: Rehearse the recovery path

Finish with two recovery scenarios. In the first, the employee gave a name and date of birth. In the second, they shared an account detail or one-time code. Participants should know to report promptly, contact the real fund and follow the organisation's incident process. They should not call the suspected scammer back.

Speed matters more than embarrassment. A staff member who reports within minutes gives the business and the affected person a chance to take protective steps before a second approach arrives.

Expected outcome: staff can state the first three actions after information has been disclosed.

Common mistake: deleting call notes or texts before reporting them. Preserve details through the approved process.

Troubleshooting

Staff say superannuation is private and outside work

Keep the training focused on safe handling of unexpected calls and organisational reporting. It does not provide personal financial advice or tell anyone where to invest.

A team member worries about hanging up on a real fund

A real organisation can be contacted through a known number or secure account. Verification protects both the employee and the legitimate provider.

The script feels unnatural

Let teams use their own words, but preserve the decision: no action during an unsolicited call and no callback through the caller's details.

Managers only track clicks, not reports

Add a reporting measure to the monthly review. CISA recommends regular reinforcement so people know how and where to report suspected phishing attempts.

The exercise creates anxiety

Make it clear that reporting is a positive action. The objective is early escalation, not a perfect score.

Tools and resources

FAQ

What is fake superannuation scam call training?

Fake superannuation scam call training teaches staff to end, verify and report unexpected calls about retirement savings. It focuses on stopping pressure tactics before account details, codes or fund-switch decisions are shared.

Should an employee give a caller a one-time code?

No. A one-time code is a security control and should never be read to an unexpected caller. Verify the request through the fund's official contact route instead.

What should staff say on a suspicious super call?

Staff should say they do not make superannuation decisions on unsolicited calls and will contact their fund independently. Then they should end the call without debating it.

How often should super scam call training run in 2026?

Run a 35-minute initial session and a 10-minute scenario refresh each quarter in 2026. Repeat it after changes to payroll, HR or employee-support processes.

What if someone shared information with a caller?

They should report it immediately and contact the genuine fund using a known number or account. Fast disclosure is more valuable than trying to work out whether the caller was genuine.

Who should attend this training?

Payroll, HR, finance, customer service and managers should attend because each may receive or route a suspicious call. Any employee can use the same pause-and-verify script.

One last thing

The training win is not proving every caller is fraudulent. It is making independent verification the automatic next step whenever an unexpected call asks a person to act quickly about their savings.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.