Fake CommBank Car Giveaway Ads Steal Banking Logins

A sponsored post promises that CommBank customers can enter a draw for a new car. The bank’s colors are familiar, the prize is easy to understand, and the entry button appears to lead to NetBank.

There is no complicated investment pitch and no stranger asking for money in a private message. The ad offers a simple competition from a brand millions of Australians already recognize.

The car is bait. The form behind it is built to capture the information that protects a real bank account.

Sponsored social media ad promoting a fake CommBank customer car giveaway

Overview

The advertisement invents a customer-only vehicle prize

In September 2026, Commonwealth Bank warned about social media advertisements that impersonated CommBank and promoted fake vehicle giveaways. The ads claimed eligible customers could enter a competition to win a new car.

The promise is designed to feel plausible rather than impossible. Banks run legitimate promotions, social platforms carry sponsored competitions, and a customer may already use NetBank every week. That familiarity can suppress the pause that an unknown prize sender would normally trigger.

CommBank’s alert is direct: the advertisements were not authorized by the bank. A real logo, polished car image, or sponsored placement does not connect the promotion to CommBank.

The entry page is a banking-login trap

People who click are taken to a fake NetBank page. The page asks for login details, personal information, or other sensitive data under the pretext of entering the competition.

The scammer does not need to collect a large entry fee. Online banking credentials, card details, contact information, and security answers are more valuable because they can support account takeover, identity theft, and follow-up calls from fake bank staff.

A copied NetBank page can look especially convincing after the bank changes its real design. CommBank separately warned that scammers may imitate the updated NetBank appearance in fake login pages distributed through emails and text messages.

The campaign uses paid reach and trusted branding

Sponsored social posts can reach people who never followed a suspicious page. The platform inserts the advertisement into an ordinary feed, where it sits beside legitimate businesses and updates from friends.

The operators can replace the page, domain, vehicle, deadline, or prize amount while keeping the same basic funnel. Reports may remove one advertisement, but another account can reuse the artwork and fake login page.

  • A sponsored social ad claims CommBank customers can win a vehicle.
  • The offer creates urgency with a short entry window or limited places.
  • The button opens a page that imitates NetBank.
  • The form requests banking login or personal information to enter.
  • Stolen details can support account access and convincing follow-up calls.
  • The advertiser, social page, domain, and prize can rotate quickly.
Fake NetBank competition page requesting customer login details for a vehicle prize

Why a Bank Car Giveaway Can Feel Believable

The prize fits the image of a large bank promotion

A new car is exciting, but it is not so bizarre that everyone rejects it. Financial institutions sponsor events, advertise customer benefits, and run competitions. The scam borrows that real marketing context.

The post may also describe the draw as a reward for loyalty, an anniversary celebration, or an exclusive customer benefit. Those phrases turn an unknown advertisement into something that feels connected to an existing relationship.

Eligibility explains why the page asks for an account

The fake promotion needs a reason to request sensitive information. Saying that only CommBank customers qualify gives the login form a false purpose: “sign in so we can confirm eligibility.”

A legitimate competition should publish clear terms, eligibility rules, promoter identity, draw dates, permit details where required, and a privacy explanation. It should not require a full online banking login simply to prove that someone is a customer.

A sponsored label can look like platform approval

People often assume paid advertisements have been thoroughly verified. In reality, “Sponsored” describes how the post reached the feed. It does not certify the advertiser’s identity or guarantee that every destination remains safe.

Scammers can compromise existing pages, create lookalike profiles, or use shell pages that remain quiet until an ad campaign begins. The visible account name deserves the same scrutiny as the linked website.

Company and Checkout Checks

The social page is not Commonwealth Bank

Check the page’s creation date, name history, follower count, location, earlier posts, and transparency details. A bank-themed name and profile image can be copied, while a newly created page may have no genuine customer history.

Do not use a verification badge alone as proof. Compromised accounts can retain old signals of trust. Navigate to CommBank’s official site or app independently and look for the same promotion there.

The web address is not NetBank

A fake login can reproduce colors, labels, security messages, and button placement. The registered domain remains the most important clue. Extra words, hyphens, unusual endings, and a brand name placed inside a longer address do not make a site official.

CommBank advises customers to access NetBank through the CommBank app or by typing the official address themselves. Do not use a social advertisement as the doorway to online banking.

The competition support channel cannot be verified

Fraudulent promotions may provide a Messenger account, generic email, or comment reply as “support.” That person can reassure the victim, explain away security warnings, and request one-time codes.

Use the phone number on the back of the bank card, secure messaging inside the official app, or the contact page reached through commbank.com.au. Ask whether the named competition exists before entering anything.

The login form is the hidden checkout

The page may advertise a free entry, but the victim is asked to pay with credentials and identity data. NetBank details can be worth far more than a small competition fee.

No genuine giveaway needs an online banking password, card PIN, or one-time security code. If a later caller asks for a code to “confirm the prize,” the request is part of the theft, not verification.

How the CommBank Car Giveaway Scam Works

Step 1: A sponsored post announces the vehicle prize

The victim sees a professionally styled ad featuring a new car and CommBank branding. The copy says customers can enter, check eligibility, or claim a place in a limited draw.

Comments may appear enthusiastic, but reactions and testimonials can be fabricated, purchased, or posted by accounts controlled by the same network.

Step 2: Urgency turns curiosity into a click

The advertisement may show a deadline, a limited number of entries, or a countdown. The goal is to keep the person inside the social feed’s fast rhythm and prevent independent verification.

The prize image does most of the emotional work. A user who can already imagine winning the car may treat the entry form as routine administration.

Step 3: The link opens a copied NetBank page

The destination uses the bank’s visual identity and familiar login wording. It may display security icons, an encrypted-connection claim, or a customer notice to make the page feel official.

The padlock only shows that the connection to that particular domain is encrypted. It does not confirm that Commonwealth Bank owns the site.

Step 4: The form collects credentials and identity data

The fake page requests a client number, password, name, phone number, address, card information, or other details. Each field is framed as an eligibility or entry requirement.

The information may be sent to the operator as soon as a field is completed, so closing the page before pressing the final button does not guarantee that nothing was captured.

Step 5: A fake verification step captures a security code

If the attackers attempt a real login, the bank may send a one-time code or approval notification. The fake page or a follow-up caller can ask the victim to repeat that code as part of “confirming the entry.”

The notification text usually states what the code authorizes. Reading it fully can expose the deception. A competition entry should never require approval for a new device, transfer, digital wallet, or password change.

Step 6: The scammers exploit the account or identity

With enough information, criminals may attempt account access, change contact details, register a device, make payments, or call while impersonating the bank’s fraud team.

Personal information can also fuel later scams. A caller who knows the victim’s name, bank, phone number, and recent “competition entry” can sound unusually credible.

Fake banking verification screen requesting a one-time security code after a prize entry

How to Verify a Real Competition

Close the social post and start again from a trusted place. Open the official bank app, type commbank.com.au into the browser, or use the contact number printed on the card. Search the bank’s promotions and security alerts for the exact prize name.

Read the full competition terms. They should identify the promoter, eligibility, opening and closing times, prize details, draw procedure, notification method, privacy handling, and any required permit information. Missing or copied terms are a serious warning.

Search for a public announcement from the bank’s verified channels, but do not rely on one social profile. A scam page can copy an entire post history or operate from a compromised account.

Take a screenshot before reporting a suspicious promotion. Advertising pages and destination domains can disappear quickly, and the saved evidence helps the bank and platform connect later copies to the same campaign.

Warning Signs in the Ad and Entry Page

  • The promotion exists only as a sponsored social post.
  • The page was created recently or changed names several times.
  • The ad claims only a few entries remain.
  • The destination domain is not CommBank’s official domain.
  • The form requests a NetBank password to enter a giveaway.
  • A code is described as prize confirmation even though the bank message says login or payment.
  • The terms do not clearly identify the promoter and draw process.
  • Support is available only through social messages or an unrelated email address.

One clue is enough to stop. You do not need to prove who owns the page before refusing to enter banking details.

What to Do if You Have Fallen Victim to This Scam

  1. Contact CommBank immediately. Call the official number on the back of the card, use secure messaging in the app, or visit a branch. Explain exactly which details and codes you entered.
  2. Change the NetBank password from a clean device. Use the official app or type the bank address yourself. Do not return through the advertisement or browser history entry for the fake page.
  3. Review devices and security settings. Ask the bank to remove unfamiliar sessions, devices, payees, contact changes, digital wallets, and transfer instructions.
  4. Freeze affected cards and payments. If card data was entered, lock the card through the official app and ask the fraud team whether replacement is required.
  5. Preserve evidence. Save screenshots of the advertisement, social page, domain, forms, messages, transaction alerts, and the time you entered information.
  6. Check email and phone accounts. Change reused passwords, enable strong MFA, and protect the email address that receives bank notifications.
  7. Scan with Malwarebytes. If the page downloaded a file, requested an app, or opened repeated redirects, run a current Malwarebytes scan for known malicious software and browser changes.
  8. Block malicious advertising with AdGuard. AdGuard can reduce exposure to known scam domains and harmful ads. It cannot validate a competition, so independent bank verification is still necessary.
  9. Report the ad. Report it to the social platform and forward details to CommBank’s fraud or hoax reporting channel. Australian victims can also report to Scamwatch and ReportCyber where appropriate.
  10. Expect follow-up impersonation. A scammer may call as the bank, police, or prize team. Hang up and start a new call using a verified number.

Do not move money to a “safe account” and do not hand cash, cards, or a PIN to a courier. A real bank will secure the account through official processes, not secret transfers.

Frequently Asked Questions

Is the CommBank car giveaway real?

The social advertisements described in CommBank’s September 2026 alert were fraudulent and unauthorized. Verify any different promotion through the official app or website.

Why does the fake page ask me to log in?

The scam uses supposed customer eligibility as an excuse to collect NetBank credentials and personal information. A giveaway entry does not require a banking password.

Can a sponsored social media ad still be a scam?

Yes. Sponsored means the advertiser paid for distribution. It does not guarantee the identity behind the ad or the safety of every linked page.

What if I entered details but did not submit the form?

Assume the information may have been captured as you typed. Contact the bank, change credentials, and report exactly which fields were completed.

Does a padlock prove the NetBank page is genuine?

No. A padlock confirms encryption to the displayed domain. Scammers can obtain encryption certificates for their own fake domains.

Where should I report the advertisement?

Report it to the social platform and CommBank through official contact details. If money or identity information was lost, report to the relevant Australian fraud and cybercrime services.

The Bottom Line

The CommBank car giveaway scam turns an attractive social media prize into a banking credential trap. The vehicle, customer eligibility, and NetBank-style page are all parts of the same false story.

Do not log in to banking through a giveaway ad. Close the post, open CommBank independently, and verify the promotion before a free entry costs control of a real account.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Fake Claude Desktop Ads Install Password-Stealing Malware

Next

EvilTokens Emails Hijack Microsoft 365 Without a Password