A suspicious message needs a fast, repeatable response. This 2026 guide shows Australian teams how to report phishing email scams to Scamwatch and ReportCyber, keep evidence intact, and contain the damage before a click becomes an account takeover.
Why this matters
Phishing is no longer the obvious message with poor grammar. A fake invoice can mirror a genuine supplier, a password-reset page can closely match a familiar service, and a short message can arrive during a busy payment run. The right response is not for every employee to investigate. It is to stop, preserve the evidence, and report quickly.
ASD’s Australian Cyber Security Centre recorded phishing in 60% of incidents reported to it in FY2024–25. Its Annual Cyber Threat Report says ReportCyber received more than 84,700 cybercrime reports that year, averaging one every 6 minutes. Those numbers make one point clear for 2026: reporting behaviour is a frontline control.
Cyber Aware helps MSPs and their clients practise that behaviour with phishing simulations that record reports as well as clicks. A good programme rewards the person who raises a concern early, including when they clicked first.
What you will need
Collect only evidence that is safe to keep. Do not reply to the message, click its links, open an attachment, call a number in the email, or unsubscribe.
- The original message, left in the mailbox or placed in the designated quarantine folder.
- Sender address, recipient, subject line, delivery time, visible web addresses, phone numbers and payment details.
- Screenshots of the message body and of any page already reached.
- Full message headers, if the mail platform provides them.
- A short fact record: who received it, who interacted with it, and whether credentials, files, data or money were involved.
- The organisation’s approved security contact, report button or service desk route.
Keep the original message available for IT or the managed service provider. A screenshot alone often loses sender and routing details that can help identify matching messages elsewhere.
1. Stop interaction and isolate the decision
Tell the recipient to stop interacting with the email immediately. Do not let them click a link again to “check what it does”, and do not ask a colleague to try it. If a file was opened or a password was entered, say so in the internal report without delay.
This action creates a clean handover point. The response team knows where the evidence came from, and the recipient knows they did the right thing by reporting rather than trying to solve it alone.
Expected outcome: the message remains available for review and no new interaction occurs.
Common mistake: forwarding the phishing message as a fresh email to several people. That can strip technical metadata and increases the chance that someone else opens the attachment.
2. Capture the evidence that changes the response
Record the sender address exactly as displayed, not just the sender name. Note the subject line, time received, names of impersonated people or organisations, the requested action, and any invoice or bank details. If the email claimed a Microsoft 365 password would expire in 72 hours, write that fact; do not replace it with a guess about who sent it.
If a page was opened, take a screenshot and record its address without signing in. If money was transferred, retain payment references, account details and the time of transfer. If credentials were entered, identify the account type and whether multi-factor authentication was used.
For programmes that need one record of training, simulation and reporting outcomes, human risk reporting keeps these signals visible to administrators. That is more useful than a security mailbox that receives reports but never turns them into a pattern.
Expected outcome: the response team receives facts it can use without asking the reporter to reopen the email.
Common mistake: including passwords, authentication codes or sensitive customer records in a broad internal email. Share sensitive information only through the established incident route.
3. Make the internal report first
Use the approved report-phishing button, service desk, security mailbox or incident channel. Include the facts from step 2, then state one of five outcomes: no interaction, link clicked, password entered, attachment opened, or payment sent.
Internal reporting comes first because it activates containment. The team can search for copies, block a sender or domain, revoke sessions, inspect sign-in events, or contact a bank. An external report does not replace these time-sensitive steps.
Set a simple operational standard for 2026: acknowledge a report involving credentials, payments, privileged access or customer data within 15 minutes during business hours. The target creates urgency without asking every employee to become a security analyst.
Expected outcome: ownership moves from the recipient to the response team with enough information to prioritise it.
Common mistake: asking the employee to prove the message is malicious before reporting. The decision to report a concern should take less than 2 minutes.
4. Send scam intelligence to Scamwatch
Scamwatch is the National Anti-Scam Centre’s public reporting service. Use the official Scamwatch report form for scam attempts such as impersonation, credential harvesting, payment diversion, delivery fraud, fake support requests and fraudulent investment offers.
Include the scam channel, sender details, phone numbers, web addresses, payment information, claimed organisation, and any financial loss. Report the attempt even when money was not lost. A scam report can help authorities identify a recurring tactic and warn other Australians.
Scamwatch is not an emergency response desk. Do not wait for a Scamwatch outcome before resetting an exposed password, calling a bank, blocking a malicious sender or escalating internally.
Expected outcome: the scam details contribute to national scam intelligence while the organisation handles immediate containment.
Common mistake: reporting only after a loss. The fraudulent request itself is useful intelligence when it contains a malicious link, impersonation or payment instruction.
5. Report cybercrime or a security incident to ReportCyber
Use the official ReportCyber service when the phishing email caused, or appears likely to cause, a cybercrime or cyber security incident. ReportCyber is the Australian Government’s reporting route for cybercrime, incidents and vulnerabilities.
The report should say what happened, when it happened, which accounts or systems were involved, the likely impact, and what containment actions have already occurred. Use plain facts: “a finance employee entered credentials on a page linked from the email at 10:14 AEST” is more useful than a long theory about the attacker.
ASD asks individuals and organisations that observe suspicious cyber activity, incidents or vulnerabilities to report through ReportCyber or call the Australian Cyber Security Hotline on 1300 CYBER1. The ACSC’s 2024–25 report says it answered more than 42,500 hotline calls, up 16% year on year.
Expected outcome: the incident is recorded through the correct national channel without interrupting containment.
Common mistake: treating a ReportCyber submission as the complete response. The business still needs to reset credentials, inspect sessions, check mailbox rules and assess affected systems.
6. Contain the impact based on what occurred
The response should match the interaction, not follow a generic checklist.
- No interaction: quarantine or block the message, search for matching copies and warn relevant recipients.
- Link clicked: review browser downloads, extensions and sign-in activity; follow the endpoint response process.
- Password entered: reset the password, revoke active sessions, confirm multi-factor authentication and inspect for mailbox forwarding rules or new application access.
- Attachment opened: isolate the device if suspicious behaviour appears and have the security team investigate it.
- Payment sent: contact the bank or payment provider immediately, preserve transaction records and report the crime.
A predictable training routine makes this sequence easier to follow in 2026. Cyber Aware awareness training uses story-driven lessons and quizzes, while simulations provide safe practice with real reporting choices.
Expected outcome: the response team contains the real exposure rather than spending valuable time on a low-risk event.
Common mistake: assuming multi-factor authentication means an account is safe after credentials were entered. Password resets and session revocation still matter.
7. Close the loop
Confirm the outcome to the reporter and log the impersonated brand, requested action and response time. In 2026, track time from delivery to useful report and report rate against click rate; completion alone does not show whether staff act correctly under pressure.
Troubleshooting
The message was deleted
Record the sender, subject, approximate time and any action taken; IT can search mail records.
A supplier message looks genuine
Verify the request through a trusted contact already in the supplier record, never through details in the message.
Payment was sent
Contact the bank immediately, preserve the transaction details and report the incident.
Tools and resources
- ASD’s phishing guidance explains phishing and directs Australians to Scamwatch.
- ASD’s Annual Cyber Threat Report 2024–25, published 14 October 2025, documents Australian incident trends.
- Cyber Aware phishing simulations provide safe reporting practice and record reports alongside clicks.
- Cyber Aware training turns recurring phishing patterns into short, assigned lessons.
FAQ
Should I report a phishing email if I did not click it?
Yes. Report it internally and report scam attempts to Scamwatch even when no one clicked, because others may receive the same message.
Should a business report phishing to Scamwatch or the ACSC?
Use Scamwatch for scam intelligence and ReportCyber for suspected cybercrime or security incidents. Contain the event internally while making those reports.
What information belongs in a phishing report?
Include sender and recipient details, time received, subject line, screenshots, web addresses or phone numbers, and any interaction.
Can I forward a phishing email to IT?
Use the approved report-phishing route where available. Forwarding can remove technical details and expose another recipient to the threat.
What happens after someone enters a password on a phishing page?
Reset the password, revoke active sessions, confirm MFA and investigate account activity immediately.
How often should phishing reporting training run in 2026?
Run short training and varied phishing simulations throughout 2026 rather than relying on one annual module.
One last thing
The strongest metric is not the number of suspicious emails received. It is the time between delivery and a useful report, followed by the percentage of people who report rather than click. Make those actions visible, respond quickly, and phishing training becomes a working control.