Every June the texts start: a Medicare claim needs your attention, your myGov account will be suspended unless you update your details, a tax refund is waiting on a link. Staff who would never click a link in a strange email will tap one of these messages without a second thought, because it arrives on the phone they carry all day, uses the name of a service they trust, and lands at exactly the time of year when a myGov notification is what they expect. Training staff to spot fake myGov and Medicare scams is about breaking one specific habit: following links to sign in to government services.
TL;DR
- myGov does not send emails or texts with links to sign in - the only safe path is typing my.gov.au or opening the official myGov app.
- The volume is real: Scamwatch logged 1,638 reports of myGov impersonation scams with losses over $105,000 in the first seven months of 2020 alone, and the ATO and myGov impersonation alert is refreshed every tax time.
- The lures are seasonal and predictable: Medicare claim problems, identity verification, tax refunds, suspended payments.
- Train one reflex: never sign in from a link - open my.gov.au or the app yourself and check your account there.
- If details were entered, act within the hour: change the myGov password, call Services Australia's scams and identity theft helpdesk, and report.
Why this matters
myGov is the front door to the services Australians interact with most: Centrelink payments, Medicare claims and the ATO. A compromised myGov account is not a password reset problem - it is identity theft with a government interface. An attacker who signs in can redirect payments, read health and tax records, and change the account's contact details so the real owner stops seeing warnings.
The scale is documented. In the first seven months of 2020, Scamwatch received 1,638 reports of myGov impersonation scams with reported losses over $105,000 - part of more than $1.26 million lost to government impersonation scams overall in that period, with ATO impersonation alone drawing 2,389 reports and over $905,000 in losses. The pattern has not gone away: Scamwatch and the ATO re-issue a joint alert every tax season because the scams return with it. For a business, the risk is personal first - these scams target staff at home - but it does not stay personal. A staff member who reuses their work email for myGov, or reuses passwords between work and government accounts, turns a personal compromise into a corporate one.
Who this is for
MSPs training client workforces, and internal IT or people teams at any Australian business. Every staff member needs this one, because myGov scams target people, not roles - and a workforce trained to spot them protects the business by protecting its people.
What the scams look like
Staff should be able to name these patterns on sight:
- The Medicare claim text. "Your Medicare claim has been processed - you are due a payment" or "There is a problem with your Medicare claim, update your details." The link leads to a fake sign-in. Medicare claims are managed through myGov, so any legitimate notice waits in your myGov inbox.
- The suspension pretext. "Your myGov account will be suspended unless you verify your identity / update your details to keep receiving payments." Urgency plus a threat to payments is the classic government-impersonation structure.
- The tax-time email. "A tax refund is available" or an unexpected message with a link claiming to be from the ATO. Scamwatch and the ATO state plainly: the ATO will never send an unsolicited message with a link, and an email claiming myGov sign-in should be treated as a scam.
- The wrong domain. Scamwatch's warning signs include sender details that do not match the legitimate agency and do not end in '.gov.au'. Display names lie - 'myGov' as a sender name proves nothing; the actual address is what counts.
- The phone call. A caller claiming to be from Services Australia or the ATO, pressing for a code, a password or remote access. Government agencies do not ask for one-time codes over the phone, and they do not threaten immediate arrest - Scamwatch's guidance is explicit that threatening callers are a scam marker.
What all of them share: urgency, a link or a request for codes or details, and a brand that is easy to fake because everyone has an account.
The reflex: never sign in from a link
Email training taught the hover-and-check; government scams need a simpler rule, because the correct action is always the same:
- No link, ever. Do not tap, do not preview. If the message claims to be about myGov, Medicare, Centrelink or tax, open my.gov.au by typing it or use the official myGov app, and check the account there. Anything real appears in the myGov inbox.
- Read the sender, not the name. The display name says myGov; the actual address usually does not end in .gov.au. But train staff not to rely on this check alone - a rule of "the domain looked right" is exactly how a convincing spoof gets through. The no-link rule is the defence; the domain check is the confirmation.
- Codes are never shared. One-time codes, passwords and identity details are never given to anyone - not to 'myGov staff', not on a call the agency supposedly made.
- If you already clicked and typed, say so immediately. Change the myGov password, contact Services Australia's scams and identity theft helpdesk, and check every linked service. Speed turns identity theft into a closed incident.
- Report it. Forward suspicious myGov, Centrelink or Medicare emails to reportascam@servicesaustralia.gov.au, report to Scamwatch, and forward scam texts to your telco's scam-reporting line.
How to train it
- Add a government-impersonation module. Your security awareness training should include the lures above and the no-link reflex, with real screenshots of fake Medicare texts. Short, memorable, repeated.
- Time it to the seasons. The scams spike at tax time (June-October) and around payment events. Schedule a refresher in May so staff are primed before the texts arrive.
- Test with simulations. Run a myGov-style lure through your phishing simulations - the delivery channel differs from corporate phishing, which is exactly why it needs its own test.
- Give staff the reporting script. reportascam@servicesaustralia.gov.au for government emails, Scamwatch for everything, telco forwarding lines for texts. A one-page reference in the intranet beats a paragraph in a policy.
- Cover the home angle. Encourage staff to run the same check with family - parents on Centrelink and grandparents on Medicare are the highest-risk group, and a lesson framed as 'protect your mum' lands harder than a compliance rule.
- Close the work leak. Ask staff to check which email their myGov account uses and whether that password is reused at work. If the answer makes you uncomfortable, that is a human risk reporting finding - measure it.
Common training mistakes
- Teaching only email phishing. The myGov attack is mostly SMS and phone. A programme that tests only the inbox misses the channel where these scams live.
- Trusting SMS display names. 'myGov' as a sender name is trivially faked; the no-link rule is what holds.
- Treating the MFA prompt as proof of safety. Relay-style kits hand users a real prompt while capturing the session - same trap as corporate credential phishing.
- One-and-done. Scams are seasonal; an October briefing has expired by the next June spike. Tie the refresher to the calendar.
- Skipping personal risk. If the training only talks about work accounts, staff mentally file it as someone else's problem. The home framing is what makes it stick.
What to do next
If the client's programme has no government-impersonation coverage, this module is the cheapest gap to close - the lures are documented, the rule is one sentence, and the reporting channels are public. Then measure it like everything else: human risk reporting puts the simulation results next to email risk. If the whole programme needs a business case first, a gap assessment shows where the human layer is thinnest before anyone spends a dollar. For a consumer-facing walkthrough of spotting and reporting myGov scam emails and texts specifically, see our guide on myGov scam emails.
FAQ
Does myGov ever email or text you a link to sign in?
No. myGov messages never contain links to sign in or requests for personal details. Access my.gov.au by typing it or use the official app - the official myGov scams page at my.gov.au lists current known scams and the correct channels.
I got a text about a problem with my Medicare claim - what do I do?
Do not click. Open my.gov.au or the myGov app yourself and check your Medicare claims there. A genuine notice appears in your myGov inbox; a text demanding action through a link is a scam.
The sender looked exactly like myGov - how?
Display names are set by the sender and trivially faked. Scamwatch's warning signs include sender details that do not end in '.gov.au' - but treat the no-link rule as the real defence, because a convincing spoof can pass the domain check.
Where do I report a myGov scam?
Forward suspicious myGov, Centrelink or Medicare emails to reportascam@servicesaustralia.gov.au, report through Scamwatch, and forward scam texts to your telco's scam-reporting line.
I entered my details on a fake myGov page - now what?
Act within the hour: change your myGov password, call Services Australia's scams and identity theft helpdesk, check every linked service for changes, and report to Scamwatch. If the same password was reused anywhere else, change it there too.
How often should we train this?
At least annually, timed just before tax time, plus a myGov-style simulation in the annual campaign. The scams return every June - so should the refresher.
One last thing
Check whether any staff use their work email as their myGov contact address. If a work mailbox is compromised and it also receives myGov password resets, one breach becomes two. Moving myGov to a personal email is a five-minute personal-hygiene ask that closes the bridge between the two.