Information on the attack is scarce, but it sounds like attackers obtained credentials from prior breaches and used them against super funds. It is shameful that many of these funds have not yet implemented MFA in this day and age, but it's not like the actual fund got compromised.
Obviously, information at the moment is very light so this understanding may change, but this is the current position.