A request to pay an invoice, a tax bill or an executive favour in gift cards is a scam every time, no matter how senior the sender looks or how urgent the deadline sounds. This 2026 guide trains staff to spot the pattern, verify unusual payment requests through a known channel and report the attempt.
TL;DR
- No legitimate company or government agency asks for payment in gift cards.
- Scammers impersonate executives or suppliers and demand cards under time pressure.
- The response is pause, verify through a known channel, then report.
- Cyber Aware phishing simulations rehearse the pressure before it is real.
Why this matters
Scamwatch has warned for years that gift cards are a payment method of choice for scammers, with reported losses above $5 million in 2018 alone, and the core advice has not changed since: no legitimate company or government agency will ever ask for payment in gift cards. Apple, Google Play, Amazon and Steam cards remain favourites because the codes are quick to move and hard to trace.
The scam reaches work inboxes in two ways. One message impersonates a senior manager who needs gift cards bought as a surprise for staff, a tactic Scamwatch describes in its guide to spotting and avoiding scams. Another poses as a supplier chasing an invoice and offers a card-based settlement or a new payment link. Both rely on the same mix: authority, urgency and a payment method nobody questions at the register.
Start with security awareness training so verification becomes a reflex rather than a favour someone is too busy to do.
What you'll need
- 20 minutes for the lesson and 10 minutes for the drill.
- Redacted examples of executive gift card requests and fake supplier invoices.
- The finance team's route for verifying payment requests.
- The organisation's list of approved payment methods.
- The current Scamwatch alert on gift card payment demands.
Run the drill as a no-fault exercise. The goal is a fast report, not a named suspect.
Step 1: State the rule without exceptions
Open the lesson with the sentence that ends every debate: no legitimate business or government agency takes gift cards as payment. Tax offices, utilities, banks and IT departments do not work this way, and neither does your own finance team.
Expected outcome: Staff can repeat the rule verbatim. Common mistake: Looking for exceptions, because a plausible exception is exactly what the scam builds.
Step 2: Name the four pressure levers
Gift card scams stack the same four levers: authority, urgency, secrecy and an unusual payment method. The email comes from the top, needs action today, asks the recipient to keep it quiet and pays in cards.
Each lever alone is suspicious. Together they are decisive, and staff should treat any two of them in one request as a reason to report.
Expected outcome: Staff can name all four levers from the example email. Common mistake: Treating urgency alone as harmless because the request looks small.
Step 3: Teach the verify-first response
Any request that changes how money moves gets confirmed through a known channel before anything is bought. Call the manager on the number in the internal directory, not the number in the email. Check the supplier against the account details already on file.
The check costs two minutes. A legitimate request survives it; a scam collapses in the first sentence.
Expected outcome: Staff name the channel they would use before touching the request. Common mistake: Replying to the email to confirm, which warns the scammer and changes nothing.
Step 4: Rehearse the executive scenario
Run a two-minute drill. The learner receives an email that appears to come from the managing director: five $200 cards needed for client thank-yous, in a meeting, cannot take calls, please keep it between us for now. The learner refuses to buy, verifies through the directory and reports the email.
Phishing simulations carry the same levers in a safe format, and varied scenarios stop the lesson from becoming predictable.
Expected outcome: The learner completes verify-then-report without buying anything. Common mistake: Making the simulation so polite that nobody feels the pressure.
Step 5: Cover the supplier variant
Show a fake supplier email that asks for an overdue invoice to be settled in cards or through a new payment link. The lesson is identical to the executive scenario: the payment method is the tell, and finance verifies against the details on file before any payment.
Expected outcome: Staff route the request to finance instead of paying. Common mistake: Treating finance-owned processes as someone else's responsibility.
Step 6: Capture the report
A useful report includes the sender address, the exact request, the deadline and whether any cards or codes were already bought. Speed matters most when codes were purchased, because every hour before the report lowers the chance of stopping redemption.
Make reporting one click from the inbox. Cyber Aware phishing simulations include a report button so the same habit carries into real incidents.
Expected outcome: Reports reach security within minutes, with the details above. Common mistake: Waiting until the deadline passes because no money moved yet.
Step 7: Target the follow-up
Review who receives these requests and who reports them. Executive impersonation lands on assistants, office managers and new starters first. Use human risk reporting to focus refreshers on those roles instead of sending one blanket reminder.
Expected outcome: Refresher content reaches the roles that actually receive the requests. Common mistake: Assuming finance is the only team that needs the lesson.
Troubleshooting
The manager says the request really was theirs
Then the phone call costs nothing. Legitimate requests survive verification, and the rule stays intact for the next one.
Cards were already bought and codes sent
Report immediately through the agreed route and contact the card issuer's fraud line. Recovery odds drop with every hour, so the report is the first action, not the last.
The request came from the executive's real address
Treat the mailbox as spoofed or compromised and verify by phone regardless. The verification rule never depends on the sender looking genuine.
Staff feel embarrassed about almost falling for it
Thank the report publicly. A team that hears praise for reporting is a team that reports the next attempt faster.
Tools and resources
- A one-page card: pause, verify, report.
- Redacted drill emails for the executive and supplier scenarios.
- The current Scamwatch gift card scam alert.
- Cyber security gap assessment for mapping payment verification controls to wider obligations.
What to do next
Run the executive scenario once in the next 30 days and measure how fast the request gets reported rather than paid. Under 10 minutes is a workable 2026 benchmark; use the result to set the next training reminder.
FAQ
Do any companies legitimately accept gift cards as payment?
No. Scamwatch's advice is unambiguous: no legitimate company or government agency will ever ask you to make a payment with any sort of gift card.
Why do scammers want gift cards?
Gift card codes are quick to resell and hard to trace or reverse, which makes them a preferred payment method across many scam types.
What if the request comes from the CEO's real email address?
Treat the mailbox as spoofed or compromised and verify by phone through the internal directory. Real requests survive the call.
Which gift cards appear most often in scams?
Apple and iTunes, Google Play, Amazon and Steam cards appear most often in Australian scam reports.
What should staff do if they already bought cards?
Report immediately, contact the card issuer's fraud line and tell security exactly which codes were sent. Fast reporting gives the best chance of stopping redemption.
How often should gift card scam training run?
Run the drill twice a year and refresh after any real attempt, because a live campaign in your own inbox is the most memorable lesson available.
One last thing
The scam only works inside a channel where nobody asks questions. The moment a request asks for secrecy, the correct move is to pick up the phone.