How to train staff to identify fake ATO and tax office scams

Train staff to identify fake ATO and tax office scams with official verification, safe simulations, payment controls, reporting and incident response steps.

Fake ATO and tax office scams succeed because they combine authority, fear and a deadline. A message may say that a tax return needs attention, an appointment must be confirmed, a refund is waiting or a criminal penalty is about to start. It may arrive by email, SMS, phone, social media or a fake government website.

This guide explains how to train staff to identify fake ATO and tax office scams in 2026. It covers the behaviours to teach, role-based scenarios, safe phishing exercises, reporting, incident response and the measures that show whether the programme is working. Start with a cyber security gap assessment if the organisation does not yet know who handles payroll, tax records, supplier payments or employee questions about government messages.

TL;DR

Why ATO impersonation scams work

Tax is a high-pressure subject. People expect deadlines, statements, refunds, notices and requests for information. A scammer only needs to make a message fit one of those expectations and add a consequence for waiting. The message can use the ATO name, a myGov reference, a copied logo, a plausible case number or a tax professional’s identity. Familiar branding is not authentication.

The scam can target a person’s money, identity or access. A fake refund form may collect bank and identity details. A fake tax debt notice may demand an immediate transfer. A fake appointment email may lead to a login page that captures myGov credentials. A phone call may keep the person on the line while the scammer creates urgency or asks for a one-time code.

The ATO’s official scam data shows why a current training programme matters. In June 2026, the ATO recorded 1,547 reports of ATO impersonation scams, 12% more than in May. Email accounted for 98.5% of the reported scam channels that month. Training should therefore lead with email, but it should also prepare people for SMS, calls, social media and fake websites.

What the ATO says it will not do

Use the ATO’s own boundaries as the centre of the lesson. The ATO says it will never:

These are strong warning signs, but they are not the only ones. A scam can use a normal-looking request and still be fraudulent. Staff must understand that a message does not become genuine because it avoids the most obvious threat. The safe response is to stop using the message as the route to the ATO and verify independently.

The ATO also says that phone calls from it will show as No Caller ID. Do not turn that into a shortcut for trust: caller ID, sender names and message threads can be imitated, and a person should still verify through the official ATO contact route.

The behaviour to teach

Use a four-step rule that staff can remember while a message is creating pressure: stop, check, report, protect.

Stop

Do not click the link, open the attachment, reply, call the number in the message, share a one-time code or make a payment. Do not stay on a call because the caller says hanging up will cause a penalty. Do not allow a deadline, refund promise or threat of prosecution to replace the normal verification process.

If the message appears in a real conversation thread or uses the name of a real tax professional, stop anyway. A familiar channel can carry a compromised account or a forged message.

Check

Open the ATO website or myGov through a known bookmark, a trusted app or a browser address typed independently. Do not use the link, QR code, attachment or phone number supplied by the suspicious message. If a staff member uses a tax agent, they should contact the agent using details already held in the organisation’s records, not the details in the new message.

The ATO’s verify or report a scam guidance explains how to check a doubtful contact and when to call 1800 008 540. The internal training should point people to that known route, not ask them to decide whether a page looks official.

Report

Give staff one internal reporting button or mailbox and explain what happens after they use it. The report should reach an owner who can assess the message, warn other recipients, protect payroll and finance processes and escalate a suspected identity compromise.

For an ATO impersonation email, the ATO asks people to forward it to ReportScams@ato.gov.au. The organisation’s internal report should happen as well, because external reporting does not tell the payroll or security team whether other employees received the same message.

Protect

If the person clicked, opened an attachment, entered credentials or shared information, they should say so immediately. Close the page, disconnect from a suspicious session where appropriate, contact the incident owner and use a known route to change exposed credentials. If money or sensitive information was shared, call the ATO on 1800 008 540 and contact the bank or payment provider without waiting for the training team to investigate.

The red flags staff should practise

Authority plus urgency

A message claims to be from the ATO, uses a case number and demands action within a short period. Teach staff that authority and urgency are separate signals, not evidence. A genuine tax matter can be checked through official online services or a known professional.

Refund or payment pressure

A refund is available only after a fee, a small verification payment or a bank-detail update. The ATO says it will not ask for a fee to receive a tax refund. Staff should not enter card or bank details through the supplied route.

Threats that do not fit the official process

The caller says police are being sent, a tax file number will be cancelled or the employee must remain on the line. These threats are designed to prevent independent checking. End the interaction, preserve the evidence and use the official ATO route.

Credential or one-time-code requests

A fake myGov or ATO page asks for a password, multi-factor code, identity document, driver licence, Medicare details or full bank information. Staff should not enter information into a page reached from an unsolicited message. A request for a one-time code is a high-risk request even when the page carries familiar branding.

Unexpected attachments

An attachment may claim to be a tax notice, refund statement, appointment form or debt calculation. Do not open it just to see whether it is genuine. Report the message and let the security owner inspect it.

Contact details supplied by the message

The email includes a phone number, reply address, QR code or shortened link that appears to make verification easy. That is the route the scammer controls. The safe route is one the staff member selected independently.

Social and messaging approaches

A message on social media or a chat app claims to be from a tax office representative. The channel does not make the request legitimate. Staff should not move the conversation, send documents or follow a payment instruction.

Role-based training scenarios

General staff: the fake refund email

An employee receives an email saying a tax refund is ready and asks them to confirm bank details through a button. The safe choice is to avoid the button, open the official ATO or myGov route independently and report the email. The exercise should measure whether the person reports it, not whether they can identify every visual difference from the real site.

Payroll: the tax-file-number threat

A message claims that an employee’s tax file number will be cancelled unless payroll uploads a document immediately. Payroll should stop the request, avoid the attachment, contact the employee through a known internal process and escalate the message. The scenario teaches that the payroll team is a security control, not a pass-through for urgent government instructions.

Finance: the tax-debt payment demand

A caller or email asks finance to transfer a tax debt to a personal account, offshore account or cryptocurrency wallet. Finance should refuse the route, verify any real liability through approved tax records or a known tax professional and report the interaction. Use a second approver for unusual payment instructions.

Executives: the arrest threat

A senior leader receives a phone call saying they will be arrested unless they remain on the line and pay immediately. The safe decision is to end the call, tell the incident owner and verify through the official ATO contact route. Executives should practise this scenario because authority pressure is designed to make senior people bypass normal checks.

Customer service: the worried caller

A customer or employee asks whether a text message from the ATO is real. Customer service should not guess, repeat the suspicious link or ask the person to reply to the message. Use a short script: do not engage with the message, open the official ATO route independently and report the concern through the correct channel.

Tax agents and advisers: the impersonated professional

A scammer claims to be a known tax agent and asks for an urgent document, payment or login code. The team should use a contact number already held in the approved adviser record and require the normal document and payment process. A familiar name is not enough to approve a new request.

What the training should cover

Verification through a known route

Show the difference between inspecting a suspicious message and verifying the underlying tax matter. Staff do not need to prove that a domain is fraudulent. They need to reach the ATO or their tax professional without using the suspicious message as the bridge.

Write the approved routes into the policy: the ATO website, myGov access, the organisation’s tax agent record, the payroll system and the security reporting channel. Test each route before the first exercise.

Payment controls

Explain which tax payments the organisation can make, who approves them and where the payment details come from. An email or phone call must not create a new payment destination. For a changed bank detail or urgent payment, use a known callback and a second-person approval.

Data minimisation

Train staff to pause when a message asks for more information than the stated tax process needs. The programme should name sensitive information that must not be sent through an unsolicited email, uploaded to an unverified page or dictated to an unexpected caller.

Credential protection

A fake tax notice is often a credential-theft attempt. Staff should never share myGov credentials or one-time codes with a caller or enter them after following an unexpected link. If credentials were entered, the event must be reported as an incident, not treated as a minor training mistake.

Calm escalation

The safe response needs to be socially easy. Give staff permission to end a threatening call, pause a payment and ask for a second review. Tell them who will respond and what information to preserve. A control that depends on someone feeling comfortable challenging a caller will fail unless leaders reinforce it.

Building safe ATO scam simulations

Use fictional tax-office scenarios that teach verification and reporting without collecting real credentials, identity documents, bank details or one-time codes. Do not copy a current ATO alert so closely that staff or the public could mistake the exercise for a real notice. Do not threaten arrest, account closure or tax-file-number cancellation in a way that creates unnecessary distress.

A safe simulation can show a fake refund email with a non-functional link and a landing page that explains the lesson immediately after a click. It can measure whether the person reports the message, but it should not store a password or payment detail. The exercise should have one primary behaviour and one clear feedback message.

Cyber Aware’s phishing workflow can support controlled practice when the audience, scenario, timing and follow-up are approved. Assign a separate route for live ATO impersonation reports so a real incident cannot be confused with a simulation.

The security awareness training programme should be assigned by role. Payroll, finance and tax advisers need payment and document scenarios. General staff need refund, credential and appointment examples. Executives need authority and phone-pressure practice.

A 30-day rollout

Days 1–7: define the safe routes

Publish the official ATO and myGov access routes, the tax-agent callback process, the internal reporting channel and the incident owner. Confirm who can approve a tax payment, change payroll details or respond to a suspected identity compromise.

Days 8–14: teach the baseline

Assign a short lesson to all staff covering the ATO’s boundaries, unexpected links, attachments, payment pressure and one-time codes. Ask staff to practise finding the official route without using the message. Test the internal reporting channel with a benign email.

Days 15–21: practise by role

Run a safe refund scenario for general staff, a payment scenario for finance and a threatening-call scenario for executives. Review report rate, time to report and whether each group used the approved verification route.

Days 22–30: fix the process

Use human risk reporting to group results by role, manager, channel and scenario. Fix unclear payment approvals, missing tax-agent contacts, slow incident handoffs and reporting gaps before sending another exercise.

What to measure

Do not make completion the headline result. A fully completed module can coexist with an employee who follows a fake refund link. Measure what people do when authority and urgency are combined.

What to do after a click or disclosure

If a person clicked a link but did not enter information, close the page, report the message and tell the incident owner what happened. If an attachment was opened, follow the organisation’s endpoint and incident process rather than assuming nothing happened.

If myGov credentials, passwords, one-time codes, identity documents, bank details or card details were shared, escalate immediately. Use a known route to secure the account, contact the ATO on 1800 008 540 and contact the bank or payment provider if money or payment information was involved. Do not use the number or link from the suspicious message.

Preserve the email, sender address, reply-to address, URL, attachment name, phone number, screenshots, payment receipt and time of the interaction. Do not forward the malicious link to colleagues. Send warnings through the approved internal channel and report the scam to the ATO or Scamwatch as appropriate.

Approaches to avoid

A generic phishing lesson

A generic lesson may teach staff to look for spelling errors but not how to verify a tax notice, end a threatening call or stop a payment. Use ATO-specific scenarios and an approved verification route.

Treating a real tax deadline as proof

A scammer can time a message to a real tax or payroll event. Staff should verify the message even when the timing feels plausible.

Requiring staff to investigate the website

Do not make employees inspect certificates, domain registration or technical indicators before they can report. Give them a safe route to verify the underlying issue and a simple reporting action.

Collecting real secrets in a simulation

A simulated ATO page should never collect a real password, one-time code, identity document or payment detail. Measure the decision and explain the lesson immediately.

Shaming a person who reports

A fast report protects the organisation. Use private coaching for unsafe interaction, but never discourage a person from reporting a message that turns out to be legitimate.

FAQ

How can staff verify whether an ATO message is real?

Do not reply, click or call the number in the message. Open the official ATO or myGov route independently, or call the ATO on 1800 008 540 using the number from the official website. If a tax agent is involved, use contact details already held in the approved record.

Will the ATO ask for a gift card or cryptocurrency payment?

No. The ATO says it will not ask for payment through gift cards, cryptocurrency, cash delivery or personal or offshore accounts. Treat such a request as a scam and report it.

Can the ATO send an appointment email?

An appointment theme can be used in an impersonation scam, so the subject line is not proof. Do not use a supplied link or attachment. Verify through the official ATO route before taking action.

What should payroll do with a tax file number request?

Pause the request, do not open the attachment or upload the document through the message, confirm the need through the approved payroll or tax-agent process and report the suspicious message.

Should staff forward a scam to colleagues?

No. Use the internal reporting route and the relevant official reporting route. A warning should be sent by the security or communications owner without forwarding a live malicious link.

What is the most important metric?

For the first programme, track safe verification and report rate together. The objective is for staff to avoid the suspicious route, raise the concern quickly and give the owner enough evidence to protect others.

Final checklist

Before the next tax or payroll deadline, confirm that the organisation has an official ATO and myGov access route, a known tax-agent contact, a payment approval rule, a reporting channel, an incident owner, a credential-compromise procedure and a message for warning affected staff. Then practise one refund scenario and one phone-pressure scenario without collecting real information.

The strongest ATO scam training does not ask staff to become tax investigators. It gives them permission to stop, a trusted way to check, a clear reporting route and immediate support if they made a mistake.

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.