Received an unexpected ATO refund, tax debt, appointment or myGov notification? Here is how to verify it safely before clicking, replying, paying or sharing personal information.
You receive an unexpected text message while making dinner:
The message displays “ATO” as the sender. It uses formal language, mentions a believable refund amount and includes a button that appears to lead to myGov.
Another message may say you have an outstanding tax debt, a scheduled appointment, an account suspension or a document requiring urgent review. It may contain an attachment, QR code, phone number or warning that legal action will follow unless you respond immediately.
These messages can look convincing because scammers copy Australian Government logos, colours, terminology and writing styles. Some are professionally written and may even appear in the same SMS conversation as genuine messages.
On 26 June 2026, Scamwatch published an advisory about Australian Taxation Office and myGov impersonation scams ahead of tax time.
The advisory warns that scammers are making phone calls, sending fake emails, texts and other messages, and creating websites that resemble genuine ATO or myGov services. The communications commonly create urgency and direct recipients to fake websites, harmful attachments or phone numbers controlled by scammers.
The goal may be to steal:
- myGov usernames and passwords
- multifactor authentication codes
- Tax File Numbers
- identity-document information
- banking or card details
- money through fraudulent payments
- access to a phone, tablet or computer
Scammers do not need to compromise the real ATO or myGov systems. They only need to create a message, website or phone conversation that persuades someone to trust them.
- Copying the ATO or myGov logo into an email.
- Changing the visible sender name to “ATO”, “Australian Taxation Office” or “myGov”.
- Spoofing sender information so a call or message appears to come from a trusted source.
- Registering website addresses containing words such as “ato”, “mygov”, “refund” or “tax”.
- Creating fake login pages that resemble myGov.
- Sending dangerous attachments presented as tax statements, appointment notices or debt documents.
- Using QR codes that open fake login or payment pages.
- Directing recipients to phone numbers controlled by scammers.
- Making urgent claims about refunds, debts, account problems or legal action.
The Australian Cyber Security Centre explains that phishing messages often impersonate organisations people know and trust. They may attempt to steal passwords, banking details or verification codes, including through QR codes.
Most Australians recognise the ATO and myGov, making copied branding feel credible.
Claims about overdue tax, audits, penalties or legal action can push people to respond quickly.
Someone expecting money may be less cautious when a message says a refund is ready.
Short deadlines and threats reduce the time a person takes to verify a claim.
People may already be lodging returns, speaking with accountants or waiting for updates.
Phones may shorten sender details and web addresses, making fake sites harder to inspect.
The following examples are fictional and provided for awareness. The website addresses are deliberately disabled.
| Scam type | Fictional example | Main risk |
|---|---|---|
| Fake tax refund SMS | “Your ATO refund of $1,284.60 is ready. Confirm your account at ato-refund-example[.]net.” | Stolen myGov or banking details |
| Fake tax debt email | “Our records show an unpaid tax balance of $2,740. Payment is required by 5 pm.” | Fraudulent payment or identity theft |
| Fake myGov login alert | “A new device has accessed your account. Secure your profile at mygov-login-example[.]com.” | Stolen sign-in details and authentication code |
| Fake ATO appointment email | “An ATO compliance appointment has been scheduled. Open the attached notice.” | Malware or credential theft |
| Fake account suspension | “Your myGov account will be deactivated unless your identity is confirmed today.” | Personal information theft |
| Fake tax attachment | “Please review your updated Notice of Assessment in the attached ZIP or PDF file.” | Harmful software or fake login form |
| Fake ATO phone call | “You have an outstanding debt. Pay immediately or a warrant will be issued.” | Money theft and intimidation |
A polished design does not prove that a message is genuine. Modern scams may contain correct spelling, professional formatting and accurate government terminology.
Consider whether you recently lodged a return, contacted the ATO, changed your details or requested assistance.
Be cautious if it threatens arrest, account closure, penalties or loss of a refund unless you act immediately.
The ATO says it will not send an unsolicited message with a link asking you to provide personal information or log in.
Never provide your myGov password, PIN, secret-question answer or multifactor code in response to a message or unsolicited call.
Gift cards, cryptocurrency, prepaid cards and urgent money transfers are serious warning signs.
my.gov.au and ato.gov.au are official. A domain merely containing “ato” or “mygov” may not be.
A button may display “Sign in to myGov” while opening an unrelated website.
Services Australia says its text messages and emails will not ask you to open an attachment.
Check the sender, dates, branding and contact details, but do not rely on spelling mistakes alone.
Open the official service yourself or call using contact details obtained from the official website.
- Send an unsolicited message containing a link asking you to provide personal information or log in to ATO online services.
- Ask for your Tax File Number, banking details or myGov login details by email.
- Require you to use contact details contained only in a suspicious message to verify the communication.
- Send a link in a text message or email.
- Ask you to open an attachment in a text message or email.
- Ask you to reply with personal information or myGov sign-in details.
- Ask for remote access to your phone, tablet or computer.
- Threaten to deactivate your myGov account or Services Australia records.
- Threaten fines, arrest or jail through a text or email.
- Ask for your myGov password, PIN or secret-question answers during a phone call.
- Demand that a debt be paid immediately during a phone call.
Do not allow the message’s deadline or tone to control your response.
Avoid buttons, shortened URLs and QR codes contained in the message.
Attachments can contain harmful software or deceptive forms.
Replying may confirm that your contact details are active.
A number in a fraudulent message may connect directly to scammers.
Manually enter ato.gov.au or my.gov.au.
Check your genuine myGov Inbox, ATO account or account history.
Use official contact details. The ATO scam line is 1800 008 540.
Save screenshots, sender details, attachment names, dates, times and payment references.
Change affected passwords and contact the relevant organisations immediately.
OziShield is a free, privacy-first verification support tool that can help people assess suspicious digital content before interacting with it.
- suspicious links and website addresses
- SMS text
- possible government-brand impersonation
- QR-code destinations
- unusual domain structures
- misleading or high-pressure language
OziShield provides risk indicators and supporting information. It does not replace the ATO, myGov, Services Australia, Scamwatch, law enforcement or your financial institution.
It cannot guarantee that a link is safe, definitively authenticate an email sender or confirm that a communication was genuinely issued by the Australian Government.
Check it with OziShield before interacting with it, then confirm the communication independently through the official ATO or myGov website. Verify before you trust.
Check with OziShieldClose the page. Do not download anything or approve notifications. If a file downloaded, do not open it. Run a trusted security scan if the page behaved unexpectedly.
- Change your myGov password immediately through the genuine website or app.
- Change the password anywhere else you reused it.
- Enable stronger multifactor authentication where available.
- Review your myGov account history.
- Remove devices or passkeys you do not recognise.
- Check linked services for unauthorised changes.
Contact the ATO and any organisation connected to the exposed information. Seek confidential identity support from IDCARE.
Contact your bank immediately using its official website, app or the number on the back of your card. Ask it to secure the account and stop transactions where possible.
Disconnect the device from the internet if harmful software appears to be running. Run reputable security software and report the incident through ReportCyber where relevant.
Contact your bank immediately. A fast report may improve the chance of stopping or tracing a transaction, although recovery is not guaranteed.
- Disconnect the device from the internet.
- End the remote-access session.
- Remove the remote-access software.
- Run a trusted security scan.
- Change important passwords from a different trusted device.
- Contact your bank if financial accounts were accessible.
Report suspicious contact through the official Scamwatch reporting form.
Call the ATO scam line on 1800 008 540 to verify suspicious ATO contact or report that personal information or money has been shared.
Forward scam emails, or send a screenshot of a suspicious text, to reportascam@servicesaustralia.gov.au.
If you opened a link or shared myGov or identity information, contact the Services Australia Scams and Identity Theft Helpdesk on 1800 941 126.
Report malware, identity theft, stolen money and other cybercrime through the Australian Cyber Security Centre’s ReportCyber service.
Contact your bank immediately if banking information was entered or money was sent. Use the bank’s official contact details.
Contact IDCARE where identity information has been compromised or may be misused.
Yes. The ATO can send genuine emails and notifications. However, it will not send an unsolicited message containing a link asking you to provide personal information or log in to online services.
Yes. Do not assume a message is genuine because “ATO” appears as the sender. Verify it through the official website, app or ATO scam line.
Do not use the supplied link. Manually enter my.gov.au in a new browser window or use the official myGov app.
Yes. The visible sender name can be changed, and scammers may copy official logos, branding and language.
No. HTTPS only means the connection is encrypted. It does not prove that the site belongs to the ATO or myGov.
Yes. Do not rely only on the number shown on your screen. End the call and contact the organisation independently.
Do not enable macros, install software or enter passwords. Run a trusted security scan and use ReportCyber if you believe malware was installed.
No. OziShield can assess links, message text and impersonation indicators, but it cannot definitively authenticate an email sender.
No. Contact the ATO or myGov through independently accessed official channels.
Report it to Scamwatch and the ATO. Use ReportCyber where money, identity information, account access or malware is involved.
No. Genuine refunds occur. However, verify any refund by accessing your ATO account independently.
Knowing your name does not prove the sender is genuine. Personal details can come from public sources, previous breaches or stolen databases.
- Pause.
- Do not use the supplied link.
- Verify the full domain.
- Access the official account independently.
- Contact the organisation using official details.
- Report suspicious communication.
- Verify before you trust.
- Scamwatch — Australian Taxation Office and myGov impersonation scams, published 26 June 2026
- Australian Taxation Office — Verify or report an ATO scam
- myGov — How to spot a myGov scam
- myGov — What to do if you’ve been scammed
- Services Australia — Avoid and report scams
- Australian Cyber Security Centre — Phishing
- National Anti-Scam Centre — Report a scam
Not sure if a link, message or document is real?
Paste it into the free OziShield scanner — instant forensic analysis.
No login. No account. No cost. Takes 10 seconds.