Scammers impersonating myGov, Medicare and Centrelink are among the most common attacks on Australians, and they spike around tax time every June and July. Services Australia's own scams guidance says scammers pretend to be from myGov, PRODA, Medicare, Child Support or Centrelink by text, email and phone. Here is exactly what a myGov scam looks like, the one habit that defeats all of them, and the correct reporting channels - for you and for your staff.
TL;DR
- myGov will never email or text you a link to sign in - the only safe path is typing my.gov.au yourself or using the official myGov app.
- Common lures: 'problems with your Medicare claim', 'update your details to keep receiving payments', 'tax refund available', 'suspicious activity on your account'.
- Report scams to reportascam@servicesaustralia.gov.au and Scamwatch; if you entered details, call the Services Australia Scams and Identity Theft Helpdesk immediately.
- Businesses should train staff on these lures because employees check personal accounts at work - a phishing simulation using these templates measures your real exposure.
Why this matters
myGov is the one login that connects to Medicare, Centrelink, Child Support and the ATO, so credentials to it are worth real money on criminal markets - they unlock identity documents, payment records and tax details that enable follow-on fraud. The Australian Signals Directorate's Annual Cyber Threat Report has repeatedly flagged identity-based fraud and credential harvesting among the most damaging attack types in Australia. That is why the myGov brand gets used relentlessly: the attack costs the criminal a text message and pays out identity access.
What a myGov scam actually looks like
Variants change weekly, but the mechanics are stable:
- The urgent link. A text or email says your Medicare claim was denied, your payment will stop, or your account was locked - and gives a link to 'sign in'. The link goes to a fake myGov login page that harvests your username, password and the security code.
- The verification request. 'We need to verify your identity' - asking for licence, passport or Medicare card numbers. myGov messages never ask you to provide identity documents in reply.
- The fake app or QR code. A message invites you to install 'myGov' from a link or scan a QR code. The official app comes only from your phone's app store.
- The tax-time refund. Around June-July, messages promising an ATO refund and requiring you to 'confirm your myGov details'. Scamwatch and the ATO issue a joint warning about this pattern every year.
Services Australia states plainly what legitimate myGov messages will never do: ask you to click a link to sign in, enter bank details, provide identity documents, or share your password, PIN or security codes.
The one habit that defeats every variant
Never navigate to myGov through a link in a message. Type my.gov.au into the browser yourself, or use the official myGov app. That single habit is scam-proof: even a perfectly forged email becomes harmless because it never gets clicked. This is exactly the behaviour-based framing that sticks in security awareness training - not 'look for typos', but 'never sign in from a link'.
What to do if you clicked
Act in this order:
- If you entered your password, change it immediately on the real my.gov.au, then check linked accounts - Medicare, Centrelink, ATO.
- If you entered any other details or moved money, call your bank straight away to stop transactions.
- Call the Services Australia Scams and Identity Theft Helpdesk - they can secure your accounts and check for misuse.
- Contact IDCARE (Australia's national identity and cyber support service) if identity documents were exposed - 1800 595 160.
- Turn on the strongest sign-in security myGov offers - myGov supports passkeys, which phishing cannot steal.
How to report it
- Forward suspicious myGov, Centrelink or Medicare emails to reportascam@servicesaustralia.gov.au
- Report through Scamwatch (scamwatch.gov.au), run by the National Anti-Scam Centre - reports feed the alerts that warn everyone else
- Report scam texts by forwarding to your telco's scam-reporting line (Telstra 0476 888 888, Optus 7226, Vodafone 7226)
- The official myGov scams page at my.gov.au/en/about/privacy-and-security/security/mygov-scams lists current known scams and the correct channels
Why businesses should care
Your staff check personal myGov messages on work laptops and work phones. A credential harvested from a personal myGov account does not breach your company directly, but the same fake-login habit is what an attacker uses against your own systems - and payroll staff are specifically targeted with fake 'ATO' and 'payroll' portals. Businesses that run phishing simulations with realistic Australian templates - myGov, ATO, Australia Post, toll notices - see which staff click before a criminal does, and coach instead of hoping.
KnowBe4's 2025 benchmarking of 14.5 million users found roughly one in three employees click a simulated phishing link before any training, falling to about 4% after twelve months of consistent training and simulation. The difference between those two numbers is the difference between hoping and measuring.
FAQ
Does myGov ever ask you to click a link to sign in? No. Services Australia says myGov messages never contain links to sign in or requests for personal details. Access my.gov.au directly or use the official app.
Is the myGov text about a Medicare claim real? Treat every such text as fake until proven otherwise. Do not click; open my.gov.au or the app yourself and check your claims there. Genuine notices appear in your myGov inbox.
What email do I report a myGov scam to? Forward it to reportascam@servicesaustralia.gov.au, and file a report at scamwatch.gov.au so the National Anti-Scam Centre can warn others.
I gave a scammer my myGov password - what now? Change the password on the real site immediately, call the Services Australia Scams and Identity Theft Helpdesk, contact your bank if you shared any financial details, and call IDCARE if identity documents were exposed.