myGov Scam Emails: Fake Refund, Account Lock and Message Alerts

An email claiming that your myGov account has been suspended can feel serious. The message may mention unusual activity, a tax refund, a new Medicare or Centrelink notice, or a deadline for verifying your identity.

Do not sign in through the email. myGov advises users to access the service through the official app or by typing my.gov.au into the browser. Fake messages use lookalike links to steal passwords, identity documents, banking details, and one-time security codes.

Example of a fake myGov account suspended phishing email
A fake myGov suspension email uses government-style branding, a short deadline and an “Unlock My Account” button to send the recipient to phishing.

Overview

myGov is the Australian Government’s online portal for accessing linked services such as the Australian Taxation Office, Medicare, Centrelink, Child Support, and other participating agencies.

A stolen myGov login can therefore expose far more than one website. Depending on the services linked to the account, an attacker may find tax information, identity data, payment records, health-related correspondence, and contact details.

Scammers impersonate myGov in email, text messages, telephone calls, sponsored ads, and fake search results. They often copy the dark blue branding, Australian Government crest, “secure message” language, and familiar references to tax or benefits.

Official myGov guidance says genuine notifications direct users to sign in through the official app or by entering my.gov.au themselves. Unexpected messages should not be trusted simply because the sender name displays myGov.

A real notification can tell you that a new message is available, but the safest response is always the same: leave the email, open myGov independently, and see whether the account contains the claimed notice.

What the fake suspension email may say

Subject: Your myGov Account Has Been Suspended

We detected unusual activity on your account.

Your access to linked services has been temporarily suspended. Verify your identity within 24 hours to avoid permanent deactivation.

UNLOCK MY ACCOUNT

The email may address the recipient by name or include a reference number. Those details can come from data breaches and do not prove that the sender has access to myGov.

Common variations of the email

  • “Your myGov Account Has Been Suspended”
  • “New Secure Message Available in myGov”
  • “ATO Tax Refund Ready for Deposit”
  • “Confirm Your Bank Details for a Refund”
  • “Medicare Rebate Pending Verification”
  • “Centrelink Payment Has Been Placed on Hold”
  • “Unusual Sign-In Detected on Your myGov Account”
  • “Your Digital Identity Will Expire Today”
  • “Action Required: Update Your myGov Profile”
  • “You Have an Unread Government Document”
  • “Final Notice Before Account Deactivation”
  • “myGov Security Upgrade: Reconfirm Your Details”

SMS versions may use a shortened link and only a few words, such as “myGov: Your refund could not be deposited. Update account details now.” The limited space hides the absence of an official domain.

Information the scammers are trying to collect

  • myGov email address or username and password
  • One-time SMS or authenticator codes
  • Tax File Number
  • Medicare card and Centrelink information
  • Passport or driver licence images
  • Date of birth, address and telephone number
  • Bank account and credit card details
  • Answers to identity-verification questions

Collecting several of these items gives an attacker enough material to impersonate the victim in later calls, attempt account recovery, redirect payments, or apply for services under a stolen identity.

Warning signs inside the message

  • The link does not end in my.gov.au. Words such as myGov can appear anywhere in a fraudulent address.
  • The message threatens immediate loss of access. A short deadline is meant to replace verification with panic.
  • A refund requires card details or a fee. Government payments are not released by paying a verification charge to an email link.
  • The page asks for an authentication code. A code can authorize the attacker’s real login and should never be relayed to another person.
  • The attachment supposedly contains a secure message. Unexpected attachments can carry malware or open a fake sign-in form.
  • The sender uses a non-government domain. The display name and crest are easy to copy.
  • The message asks for passport or licence scans by email. Sensitive documents should not be sent in response to an unsolicited notification.

How The Operation Works

1. The scam selects a government event people expect

Tax time, benefit changes, Medicare reimbursements, and security announcements create natural opportunities for impersonation. Campaigns can be scheduled when a large part of the public is already expecting government communication.

The scammers may know only an email address or phone number. Mass distribution ensures that some messages reach people with an active claim, recent tax return, or upcoming payment.

2. The message turns uncertainty into urgency

A vague phrase such as “new secure message” makes the recipient curious without revealing details that could be checked. A suspension or refund story adds a cost to waiting.

The deadline is artificial. It encourages the recipient to use the supplied button rather than independently opening the real account.

3. A lookalike site copies the myGov sign-in page

The landing page can reproduce colors, logos, accessibility links, privacy wording, and a familiar sign-in form. It may be hosted on a domain containing words such as secure, services, gov, digital, or Australia.

The padlock in the browser only indicates encryption between the visitor and that site. Fraudulent sites can obtain HTTPS certificates too.

4. Credentials are relayed to the attacker

After the victim enters a username and password, the kit records them. A message such as “session expired” or “details incorrect” can prompt a second attempt and help confirm the password.

The operator may immediately try those details on the real myGov service. Fast action matters because the next stage can happen while the victim is still viewing the fake page.

5. The fake page asks for the security code

When the real service sends a one-time code, the phishing site asks the victim to enter it for “identity confirmation.” The attacker uses that code to complete a separate login.

A one-time code protects an account only when it remains between the account holder and the official service. Giving it to a page reached through an unexpected message defeats that protection.

6. A verification form harvests identity documents

The next page may request a Tax File Number, Medicare details, date of birth, licence number, passport, selfie, or proof of address. The form claims these items are needed to unlock the account or process the refund.

Those records can support identity theft even if the attacker never maintains access to myGov. Document images can be reused in applications and social-engineering calls.

7. The refund story collects banking information

A fake refund page asks for an account name, BSB, account number, or card information. Some versions place a small “authorization” charge on the card or subscribe the victim to an unrelated service.

Government branding makes the request feel administrative, but the destination is controlled by criminals. Verify payments through the account, not the message.

8. Compromised accounts enable further changes

An intruder may attempt to change recovery details, access linked services, obtain tax records, or redirect correspondence. They may also use the information to impersonate the victim when contacting agencies or financial institutions.

The victim can then receive follow-up calls from someone claiming to investigate the first incident. A legitimate-looking caller ID does not prove identity because numbers can be spoofed.

Why the URL is more important than the page design

A convincing myGov replica can be created from public images. The browser address identifies where information is actually being sent. Read from the domain ending backward and confirm the registered domain is exactly my.gov.au.

Do not rely on a Google ad or search result for urgent account recovery. Open the official myGov app or type the address yourself, particularly after receiving a threat or refund promise.

How the refund version changes the emotional pressure

The suspension message uses fear, but a refund message uses opportunity. It claims the ATO, Medicare, or another service has approved money that cannot be deposited until banking details are confirmed.

A specific amount and recent-looking date can make the refund feel connected to a tax return or medical expense. The campaign may be sent during tax season or after public announcements about payments, increasing the chance of a coincidental match.

The fake page first requests a myGov login and then displays an invented refund dashboard. It may ask for a BSB and account number, card details, or a small identity-verification payment. Supplying a card does not direct a government refund. It gives the operator a payment method.

How the secure-message version hides the subject

A genuine-style notification may say only that a new message is available. Scammers use the same lack of detail because curiosity encourages a click and there is no false tax amount to challenge.

The email can claim that privacy rules prevent it from displaying the notice. That explanation makes the hidden content feel responsible while directing the recipient to a counterfeit login page.

The safe response does not depend on the subject. Open myGov independently. If the notification is real, the same message will be waiting in the account. If it is not there, do not return to the email to try another link.

Account recovery is part of the attack surface

Phishing forms sometimes ask for email access, recovery answers, identity documents, and one-time codes because the attacker wants to change myGov recovery settings. Securing only the myGov password may be insufficient if the connected email remains exposed.

Review both accounts for unfamiliar sessions, changes, forwarding, and recovery methods. If a scammer called while the form was open, also check whether any screen-sharing or support application was installed.

What To Do If You Clicked or Shared Details

  1. Close the page and stop communication. Do not continue uploading documents or call a number displayed by the site.
  2. Change the myGov password from the official service. Use the app or type my.gov.au. Create a strong password not used anywhere else.
  3. Review sign-in activity and account details. Check for unfamiliar access, changed recovery information, newly linked services, and altered bank or contact details.
  4. Secure the associated email account. Change its password, review forwarding rules, sign out unknown sessions, and enable multifactor authentication.
  5. Contact myGov or Services Australia through official channels. Explain exactly what credentials, codes, or documents were submitted and ask for account-protection steps.
  6. Contact financial institutions if banking data was exposed. Ask the bank to monitor or restrict the account and replace a compromised card when appropriate.
  7. Protect identity documents. If a licence, passport, Medicare card, or Tax File Number was disclosed, follow the issuing agency’s identity-compromise guidance.
  8. Check linked-service records. Review ATO, Medicare, Centrelink, and other relevant activity for changes or claims you do not recognize.
  9. Scan the device if a file or application was opened. Update the system, remove unknown software, and run a trusted security scan.
  10. Report the scam. myGov says suspicious messages can be sent to reportascam@servicesaustralia.gov.au. Keep screenshots, headers, links, and transaction evidence.

Services Australia provides a Scams and Identity Theft Help Desk for people affected by identity fraud. Obtain the current contact details from an official government page rather than from the suspicious message.

Keep a written timeline of what was entered and when. Include security codes, document images, banking details, changes noticed in linked services, and calls received afterward. A clear timeline helps myGov, Services Australia, banks, and identity-support services respond without relying on memory during a stressful incident.

Warn other members of the household if the message referred to a shared address, family payment, or linked benefit. Scammers often reuse the same details against relatives once one person responds.

The Bottom Line

myGov phishing messages imitate account locks, refunds, secure notices, Medicare rebates, and Centrelink payments. Their purpose is to move the recipient from a trusted government name to a site controlled by the attacker.

Do not sign in, upload documents, or enter a code through an unexpected email or text. Open the official app or type my.gov.au, then check the claim inside the account. That simple separation between message and service prevents most versions of the scam.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

How to Remove Contus.sbs Pop-ups (Virus Removal Guide)

Next

How to Remove Gembujabbercaseroobox.com Pop-ups (Virus Removal Guide)