Report Phishing Email to Scamwatch and ACSC 2026

Report phishing email scams to Scamwatch and the ACSC in 2026 with evidence steps, fast containment and a staff reporting workflow.

A suspicious message needs a fast, repeatable response. This 2026 guide shows Australian teams how to report phishing email scams to Scamwatch and ReportCyber, keep evidence intact, and contain the damage before a click becomes an account takeover.

Why this matters

Phishing is no longer the obvious message with poor grammar. A fake invoice can mirror a genuine supplier, a password-reset page can closely match a familiar service, and a short message can arrive during a busy payment run. The right response is not for every employee to investigate. It is to stop, preserve the evidence, and report quickly.

ASD’s Australian Cyber Security Centre recorded phishing in 60% of incidents reported to it in FY2024–25. Its Annual Cyber Threat Report says ReportCyber received more than 84,700 cybercrime reports that year, averaging one every 6 minutes. Those numbers make one point clear for 2026: reporting behaviour is a frontline control.

Cyber Aware helps MSPs and their clients practise that behaviour with phishing simulations that record reports as well as clicks. A good programme rewards the person who raises a concern early, including when they clicked first.

What you will need

Collect only evidence that is safe to keep. Do not reply to the message, click its links, open an attachment, call a number in the email, or unsubscribe.

Keep the original message available for IT or the managed service provider. A screenshot alone often loses sender and routing details that can help identify matching messages elsewhere.

1. Stop interaction and isolate the decision

Tell the recipient to stop interacting with the email immediately. Do not let them click a link again to “check what it does”, and do not ask a colleague to try it. If a file was opened or a password was entered, say so in the internal report without delay.

This action creates a clean handover point. The response team knows where the evidence came from, and the recipient knows they did the right thing by reporting rather than trying to solve it alone.

Expected outcome: the message remains available for review and no new interaction occurs.

Common mistake: forwarding the phishing message as a fresh email to several people. That can strip technical metadata and increases the chance that someone else opens the attachment.

2. Capture the evidence that changes the response

Record the sender address exactly as displayed, not just the sender name. Note the subject line, time received, names of impersonated people or organisations, the requested action, and any invoice or bank details. If the email claimed a Microsoft 365 password would expire in 72 hours, write that fact; do not replace it with a guess about who sent it.

If a page was opened, take a screenshot and record its address without signing in. If money was transferred, retain payment references, account details and the time of transfer. If credentials were entered, identify the account type and whether multi-factor authentication was used.

For programmes that need one record of training, simulation and reporting outcomes, human risk reporting keeps these signals visible to administrators. That is more useful than a security mailbox that receives reports but never turns them into a pattern.

Expected outcome: the response team receives facts it can use without asking the reporter to reopen the email.

Common mistake: including passwords, authentication codes or sensitive customer records in a broad internal email. Share sensitive information only through the established incident route.

3. Make the internal report first

Use the approved report-phishing button, service desk, security mailbox or incident channel. Include the facts from step 2, then state one of five outcomes: no interaction, link clicked, password entered, attachment opened, or payment sent.

Internal reporting comes first because it activates containment. The team can search for copies, block a sender or domain, revoke sessions, inspect sign-in events, or contact a bank. An external report does not replace these time-sensitive steps.

Set a simple operational standard for 2026: acknowledge a report involving credentials, payments, privileged access or customer data within 15 minutes during business hours. The target creates urgency without asking every employee to become a security analyst.

Expected outcome: ownership moves from the recipient to the response team with enough information to prioritise it.

Common mistake: asking the employee to prove the message is malicious before reporting. The decision to report a concern should take less than 2 minutes.

4. Send scam intelligence to Scamwatch

Scamwatch is the National Anti-Scam Centre’s public reporting service. Use the official Scamwatch report form for scam attempts such as impersonation, credential harvesting, payment diversion, delivery fraud, fake support requests and fraudulent investment offers.

Include the scam channel, sender details, phone numbers, web addresses, payment information, claimed organisation, and any financial loss. Report the attempt even when money was not lost. A scam report can help authorities identify a recurring tactic and warn other Australians.

Scamwatch is not an emergency response desk. Do not wait for a Scamwatch outcome before resetting an exposed password, calling a bank, blocking a malicious sender or escalating internally.

Expected outcome: the scam details contribute to national scam intelligence while the organisation handles immediate containment.

Common mistake: reporting only after a loss. The fraudulent request itself is useful intelligence when it contains a malicious link, impersonation or payment instruction.

5. Report cybercrime or a security incident to ReportCyber

Use the official ReportCyber service when the phishing email caused, or appears likely to cause, a cybercrime or cyber security incident. ReportCyber is the Australian Government’s reporting route for cybercrime, incidents and vulnerabilities.

The report should say what happened, when it happened, which accounts or systems were involved, the likely impact, and what containment actions have already occurred. Use plain facts: “a finance employee entered credentials on a page linked from the email at 10:14 AEST” is more useful than a long theory about the attacker.

ASD asks individuals and organisations that observe suspicious cyber activity, incidents or vulnerabilities to report through ReportCyber or call the Australian Cyber Security Hotline on 1300 CYBER1. The ACSC’s 2024–25 report says it answered more than 42,500 hotline calls, up 16% year on year.

Expected outcome: the incident is recorded through the correct national channel without interrupting containment.

Common mistake: treating a ReportCyber submission as the complete response. The business still needs to reset credentials, inspect sessions, check mailbox rules and assess affected systems.

6. Contain the impact based on what occurred

The response should match the interaction, not follow a generic checklist.

  1. No interaction: quarantine or block the message, search for matching copies and warn relevant recipients.
  2. Link clicked: review browser downloads, extensions and sign-in activity; follow the endpoint response process.
  3. Password entered: reset the password, revoke active sessions, confirm multi-factor authentication and inspect for mailbox forwarding rules or new application access.
  4. Attachment opened: isolate the device if suspicious behaviour appears and have the security team investigate it.
  5. Payment sent: contact the bank or payment provider immediately, preserve transaction records and report the crime.

A predictable training routine makes this sequence easier to follow in 2026. Cyber Aware awareness training uses story-driven lessons and quizzes, while simulations provide safe practice with real reporting choices.

Expected outcome: the response team contains the real exposure rather than spending valuable time on a low-risk event.

Common mistake: assuming multi-factor authentication means an account is safe after credentials were entered. Password resets and session revocation still matter.

7. Close the loop

Confirm the outcome to the reporter and log the impersonated brand, requested action and response time. In 2026, track time from delivery to useful report and report rate against click rate; completion alone does not show whether staff act correctly under pressure.

Troubleshooting

The message was deleted

Record the sender, subject, approximate time and any action taken; IT can search mail records.

A supplier message looks genuine

Verify the request through a trusted contact already in the supplier record, never through details in the message.

Payment was sent

Contact the bank immediately, preserve the transaction details and report the incident.

Tools and resources

FAQ

Should I report a phishing email if I did not click it?

Yes. Report it internally and report scam attempts to Scamwatch even when no one clicked, because others may receive the same message.

Should a business report phishing to Scamwatch or the ACSC?

Use Scamwatch for scam intelligence and ReportCyber for suspected cybercrime or security incidents. Contain the event internally while making those reports.

What information belongs in a phishing report?

Include sender and recipient details, time received, subject line, screenshots, web addresses or phone numbers, and any interaction.

Can I forward a phishing email to IT?

Use the approved report-phishing route where available. Forwarding can remove technical details and expose another recipient to the threat.

What happens after someone enters a password on a phishing page?

Reset the password, revoke active sessions, confirm MFA and investigate account activity immediately.

How often should phishing reporting training run in 2026?

Run short training and varied phishing simulations throughout 2026 rather than relying on one annual module.

One last thing

The strongest metric is not the number of suspicious emails received. It is the time between delivery and a useful report, followed by the percentage of people who report rather than click. Make those actions visible, respond quickly, and phishing training becomes a working control.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.