Recognising scams and reporting them in Australia
The last step is the one people reach in a hurry, usually after something has already happened. It covers the shapes these approaches take, what to do in the first hour, and which service handles which situation.
The shapes, rather than the scripts
Individual scam scripts change constantly; the structures underneath them are stable, and recognising a structure works even when the details are unfamiliar.
An unexpected message with a link that needs you to sign in. A delivery could not be completed, a toll is unpaid, an account has been suspended, a refund is waiting. The link leads to a convincing copy of a sign-in page and harvests what you type. The structural tell is that the message arrived unprompted and wants a credential.
Someone who contacts you claiming to be an organisation you trust. A bank's fraud team, a telecommunications provider, a government department, a software company's support desk. They may know real details about you, because those details were in a breach somewhere. The tell is direction: they contacted you, and they want either access or a payment.
Pressure applied to a payment. Urgency, secrecy, or an unusual method — gift cards, cryptocurrency, a transfer to a "safe account". No legitimate organisation asks a customer to move money to protect it.
A relationship that develops and then needs money. Romance and friendship approaches build over weeks before any request appears, which is what makes them effective. The request is always for money or for help moving money.
An investment opportunity with unusual returns and a personal contact. Frequently accompanied by a professional-looking dashboard that shows gains, and by difficulty when you try to withdraw.
A warning on a web page telling you your device is infected, with a number to ring. Nothing has scanned anything. This is an advertisement, and the phone number is the product. Close the tab.
What no legitimate organisation will do
- Ask for your full password, or for a one-time code sent to you.
- Ring you out of the blue and ask for remote access to your computer.
- Ask you to move money to a different account for safekeeping.
- Demand payment in gift cards, vouchers or cryptocurrency.
- Refuse to let you hang up and ring back on the published number.
The first hour after something has gone wrong
- Stop the money first. If a payment was made or card details were given, ring your bank immediately on the number on your card or in its app. Banks have processes for recalling recent transfers, and the chance of recovery is highest in the first hours.
- Change the password on the affected account, then on your email. Email first if there is any chance it was involved, because whoever controls the email can reset everything else. Use a new, unique passphrase rather than a variation of the old one.
- Check the second factor. Look at the account's security settings for authenticator apps, phone numbers or recovery addresses that you did not add, and remove them. An attacker who leaves their own second factor behind keeps access after a password change.
- Sign out of everything, everywhere. Most major services have a control that ends all other sessions. Use it.
- If someone had remote access to the device, treat the device as untrusted. Disconnect it from the network, run a full scan from the security product installed on it, and change passwords from a different device rather than that one. If anything sensitive was on it, seek qualified help before returning it to normal use.
- Write down what happened while it is fresh. Dates, times, amounts, names used, phone numbers, addresses of sites, and screenshots. Reports are markedly more useful with this, and so is any claim you make later.
- Report it. The table below sets out where, depending on what happened.
- Tell the people around you. The same approach is rarely aimed at one person in a household or a workplace, and the shame that keeps people quiet is what lets the next attempt succeed.
Which Australian service handles what
| Situation | Where it goes |
|---|---|
| A scam approach, whether or not you lost money | Scamwatch, run by the National Anti-Scam Centre, which collects scam reports and publishes warnings about current approaches. |
| Cybercrime — hacking, ransomware, a compromised account or device | The Australian Cyber Security Centre, which operates the national cybercrime reporting service and publishes step-by-step advice on responding. |
| Cyberbullying, image-based abuse, or serious online harm | The eSafety Commissioner, Australia's online safety regulator, which takes complaints and can seek removal of material. |
| An organisation mishandled or lost your personal information | Complain to the organisation first; if it is not resolved, the Office of the Australian Information Commissioner handles privacy complaints and oversees the notifiable data breaches scheme. |
| A business misled you about a product, price or subscription | The Australian Competition and Consumer Commission, which explains consumer rights and takes reports about misleading conduct. |
| Your identity documents have been misused | IDCARE, the national identity and cyber support service for Australia and New Zealand, which provides free case management for individuals. |
| An immediate threat to someone's safety | Triple Zero (000). Reporting services are not emergency services. |
Reporting is worth the twenty minutes
People often decide it is pointless, particularly when the amount was small or nothing was lost at all. It is not: reports are how current approaches get identified, published as warnings, and acted on. Scamwatch's warnings pages exist because people filed reports about approaches that had not been seen before, and a report filed today is what makes tomorrow's warning possible for somebody else.
Helping someone else after it happens
If you are the person in the family who gets rung when something goes wrong, the first useful thing is not technical. People who have been scammed are frequently embarrassed, and delay is the thing that costs them most. Take the report without commentary, get to the bank quickly, and leave the analysis of how it happened until afterwards.
Then work through the list above with them rather than for them, on their device and with their accounts, so they can repeat it. Set up the second factor together on the email account, install the password manager if they will use one, and put your number in the bank's app on their phone so the next call is easier to make.
The end of the path
You now have the six pieces: what this software does, what your devices already provide, how to compare what is on offer, how to install it without creating new problems, the habits that carry most of the load, and the reporting routes if something happens anyway. None of it depends on buying anything, which was the point of writing it in this order.
If you want to check a term you have not met, the glossary collects everything used across these pages. If you want to know who publishes this and how it is funded, the about page and the affiliate disclosure set it out in full.