How to train staff to spot fake myGov and Medicare scams

How to train staff to spot fake myGov and Medicare scams: the no-link rule, the seasonal lures, and what to do after a click.

Every June the texts start: a Medicare claim needs your attention, your myGov account will be suspended unless you update your details, a tax refund is waiting on a link. Staff who would never click a link in a strange email will tap one of these messages without a second thought, because it arrives on the phone they carry all day, uses the name of a service they trust, and lands at exactly the time of year when a myGov notification is what they expect. Training staff to spot fake myGov and Medicare scams is about breaking one specific habit: following links to sign in to government services.

TL;DR

Why this matters

myGov is the front door to the services Australians interact with most: Centrelink payments, Medicare claims and the ATO. A compromised myGov account is not a password reset problem - it is identity theft with a government interface. An attacker who signs in can redirect payments, read health and tax records, and change the account's contact details so the real owner stops seeing warnings.

The scale is documented. In the first seven months of 2020, Scamwatch received 1,638 reports of myGov impersonation scams with reported losses over $105,000 - part of more than $1.26 million lost to government impersonation scams overall in that period, with ATO impersonation alone drawing 2,389 reports and over $905,000 in losses. The pattern has not gone away: Scamwatch and the ATO re-issue a joint alert every tax season because the scams return with it. For a business, the risk is personal first - these scams target staff at home - but it does not stay personal. A staff member who reuses their work email for myGov, or reuses passwords between work and government accounts, turns a personal compromise into a corporate one.

Who this is for

MSPs training client workforces, and internal IT or people teams at any Australian business. Every staff member needs this one, because myGov scams target people, not roles - and a workforce trained to spot them protects the business by protecting its people.

What the scams look like

Staff should be able to name these patterns on sight:

What all of them share: urgency, a link or a request for codes or details, and a brand that is easy to fake because everyone has an account.

The reflex: never sign in from a link

Email training taught the hover-and-check; government scams need a simpler rule, because the correct action is always the same:

  1. No link, ever. Do not tap, do not preview. If the message claims to be about myGov, Medicare, Centrelink or tax, open my.gov.au by typing it or use the official myGov app, and check the account there. Anything real appears in the myGov inbox.
  2. Read the sender, not the name. The display name says myGov; the actual address usually does not end in .gov.au. But train staff not to rely on this check alone - a rule of "the domain looked right" is exactly how a convincing spoof gets through. The no-link rule is the defence; the domain check is the confirmation.
  3. Codes are never shared. One-time codes, passwords and identity details are never given to anyone - not to 'myGov staff', not on a call the agency supposedly made.
  4. If you already clicked and typed, say so immediately. Change the myGov password, contact Services Australia's scams and identity theft helpdesk, and check every linked service. Speed turns identity theft into a closed incident.
  5. Report it. Forward suspicious myGov, Centrelink or Medicare emails to reportascam@servicesaustralia.gov.au, report to Scamwatch, and forward scam texts to your telco's scam-reporting line.

How to train it

  1. Add a government-impersonation module. Your security awareness training should include the lures above and the no-link reflex, with real screenshots of fake Medicare texts. Short, memorable, repeated.
  2. Time it to the seasons. The scams spike at tax time (June-October) and around payment events. Schedule a refresher in May so staff are primed before the texts arrive.
  3. Test with simulations. Run a myGov-style lure through your phishing simulations - the delivery channel differs from corporate phishing, which is exactly why it needs its own test.
  4. Give staff the reporting script. reportascam@servicesaustralia.gov.au for government emails, Scamwatch for everything, telco forwarding lines for texts. A one-page reference in the intranet beats a paragraph in a policy.
  5. Cover the home angle. Encourage staff to run the same check with family - parents on Centrelink and grandparents on Medicare are the highest-risk group, and a lesson framed as 'protect your mum' lands harder than a compliance rule.
  6. Close the work leak. Ask staff to check which email their myGov account uses and whether that password is reused at work. If the answer makes you uncomfortable, that is a human risk reporting finding - measure it.

Common training mistakes

What to do next

If the client's programme has no government-impersonation coverage, this module is the cheapest gap to close - the lures are documented, the rule is one sentence, and the reporting channels are public. Then measure it like everything else: human risk reporting puts the simulation results next to email risk. If the whole programme needs a business case first, a gap assessment shows where the human layer is thinnest before anyone spends a dollar. For a consumer-facing walkthrough of spotting and reporting myGov scam emails and texts specifically, see our guide on myGov scam emails.

FAQ

Does myGov ever email or text you a link to sign in?

No. myGov messages never contain links to sign in or requests for personal details. Access my.gov.au by typing it or use the official app - the official myGov scams page at my.gov.au lists current known scams and the correct channels.

I got a text about a problem with my Medicare claim - what do I do?

Do not click. Open my.gov.au or the myGov app yourself and check your Medicare claims there. A genuine notice appears in your myGov inbox; a text demanding action through a link is a scam.

The sender looked exactly like myGov - how?

Display names are set by the sender and trivially faked. Scamwatch's warning signs include sender details that do not end in '.gov.au' - but treat the no-link rule as the real defence, because a convincing spoof can pass the domain check.

Where do I report a myGov scam?

Forward suspicious myGov, Centrelink or Medicare emails to reportascam@servicesaustralia.gov.au, report through Scamwatch, and forward scam texts to your telco's scam-reporting line.

I entered my details on a fake myGov page - now what?

Act within the hour: change your myGov password, call Services Australia's scams and identity theft helpdesk, check every linked service for changes, and report to Scamwatch. If the same password was reused anywhere else, change it there too.

How often should we train this?

At least annually, timed just before tax time, plus a myGov-style simulation in the annual campaign. The scams return every June - so should the refresher.

One last thing

Check whether any staff use their work email as their myGov contact address. If a work mailbox is compromised and it also receives myGov password resets, one breach becomes two. Moving myGov to a personal email is a five-minute personal-hygiene ask that closes the bridge between the two.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.