How to train staff to spot ASIC business name renewal scams

Train staff to spot ASIC business name renewal scams: the sender, fee and timing checks that expose fake renewal notices, plus a simulation plan that makes it stick.

ASIC business name renewal scams are fake or third-party "renewal notices" — emails and letters that look like official ASIC correspondence but route your payment to a scammer, or invoice you for a renewal that is not even due. The fix for staff is a three-second habit: every renewal notice gets checked against ASIC's own register and its known rules before anyone pays. ASIC's own guidance is unambiguous — renewal notices arrive by email only, from an address ending in @asic.gov.au, sent 30 days before your renewal date.

Why this matters

Business name renewal scams work because the real transaction is small and routine. From 1 July 2026, ASIC charges $47 for a one-year renewal and $108 for three years — amounts staff pay without a second thought. Scammers inflate the invoice, add a "processing" fee, or bill for a renewal that is months away. The volume of look-alike correspondence is large enough that ASIC maintains a standing warning page for unsolicited business name renewal and company review notices, and has separately warned about scammers using look-alike domains to phish ASIC customers for usernames, passwords and payments.

The real cost is rarely the $47. A convincing fake notice that captures login details or redirects a payment can cost thousands, and it trains staff that renewal notices are noise — the exact habit attackers exploit.

The three patterns behind these scams

ASIC's own scam pages describe three variants, and every fake notice is a remix of one of them.

The common thread is that all three bypass the register. That is why the single most protective habit — checking the renewal date on ASIC's register before paying anything — defeats every variant.

What a genuine ASIC renewal notice looks like

SignalGenuine ASIC noticeScam or third-party notice
SenderEnds in @asic.gov.au; business name notices from ASIC.Transaction.No-reply@asic.gov.auLook-alike domains, generic Gmail or Hotmail addresses
ChannelEmail onlyLetters, PDFs, texts, phone calls
TimingExactly 30 days before the renewal dateAny date, including renewals not yet due
Fees$47 (1 year) or $108 (3 years) from 1 July 2026, matching asic.gov.auInflated amounts, "service" or "processing" fees
Payment pathYou complete the transaction yourself on ASIC's siteLink or invoice routes payment to a third party
RequestsNever asks for card or bank details by email or phoneAsks for card details, bank details or ASIC login

Any single mismatch is enough to stop and verify. Three or more means do not touch it.

How to train staff to spot ASIC renewal scams

1. Teach the three facts staff can memorise

Keep the baseline short: ASIC emails from @asic.gov.au only, 30 days before renewal only, and the fee comes from the ASIC website only. Everything else — letters, phone calls, invoices, texts — is treated as suspect by default.

2. Make the register the source of truth

Train staff to check the renewal date on ASIC's business name register before acting on any notice. A notice for a renewal that is not due is a scam, full stop. This one check defeats most variants, including the third-party services that invoice months early.

3. Never pay from the email

The payment should always happen through ASIC's own site, reached by typing the address or a bookmark — never through a link in the notice. This habit also blocks credential-harvesting look-alike domains.

4. Route every suspicious notice to one place

Give staff a single action when in doubt: forward it to a named person (bookkeeper, office manager) and do not reply or click. ASIC accepts reports of suspected impersonation scams through its online enquiry form. A clear path means the mail gets checked instead of quietly deleted or, worse, paid.

5. Rehearse it with a simulation

Rules fade; rehearsals stick. A phishing simulation built around an ASIC-style renewal template — inflated fee, wrong sender domain, deadline pressure — shows you who would pay before a real scam does. Cyber Aware's simulations auto-enrol anyone who clicks into a short follow-up lesson, so the coaching happens without anyone chasing it.

6. Cover the neighbours too

ASIC-name scams have cousins: fake ATO notices, fake domain renewal invoices, fake "your ABN will be cancelled" emails. Once staff know the verification pattern for one, name the others explicitly — attackers switch brands precisely because staff learn one at a time.

What to do if a notice was already paid

Why small offices are the target

Attackers do not need access — they need volume and inattention. Receptionists, bookkeepers and office managers pay routine invoices; executives rarely do. If nobody on the team knows the real ASIC process, a fake notice is indistinguishable from a real one. Cyber Aware's security awareness training covers invoice and payment-redirection fraud in short story-driven modules designed for exactly these roles, and human risk reporting shows which learners keep clicking so you know where the next simulation should go.

FAQ

What does a fake ASIC business name renewal look like? It arrives outside ASIC's rules: a letter or invoice rather than email, a sender outside @asic.gov.au, an inflated fee, or a renewal date that does not match the ASIC register.

How much is the real ASIC renewal fee in 2026? From 1 July 2026 it is $47 for one year or $108 for three years. Any notice charging more is either a third-party service you did not ask for or a scam.

Does ASIC ever send renewal notices by post? No. ASIC sends renewal notices by email only, 30 days before the renewal date.

Can ASIC charge my credit card directly by phone? No. ASIC will not ask for card or bank details over email or phone. Payments happen through ASIC's own payment channels.

Who do I report an ASIC impersonation scam to? Report to Scamwatch, and to ASIC through its online enquiry form with the notice attached.

What if the fake notice came from a real third-party service? Some invoice-style notices are genuine registered agents you never hired. You are under no obligation to pay them; check the register, renew through ASIC directly, and tell the sender in writing that you did not engage their service.

Should we blacklist or block these senders? Filtering helps, but attackers rotate domains. The verification habit — sender, timing, fee, register — is the durable control, because it works on the next domain too.

One last thing

Diary the renewal date yourself. Most scams lean on the fact that nobody knows when the real renewal is due — a calendar entry with the $47 amount next to it makes every fake notice obvious on sight.

Related guides

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.