Australian Federal Police Crypto Scam Exposed: The Fake ReportCyber Call

A caller says the Australian Federal Police has found your name in a cryptocurrency data breach. They quote a real-looking case number, tell you to check ReportCyber, and promise another specialist will help secure your wallet.

The details feel unusually convincing because parts of the process can be real. That is exactly what makes the Australian Federal Police crypto scam so dangerous.

Fake Australian Federal Police investigation notice using an AFP logo and case reference

Overview

The Scam Builds Real Evidence Around a False Investigation

Most impersonation scams manufacture every detail. This campaign is more sophisticated because the criminal may submit an unauthorized ReportCyber report using the target’s real name, email address, and phone number.

ReportCyber is Australia’s legitimate national reporting channel. Its notification and case reference can therefore be genuine, even though the target never filed the report and the story attached to it was created by a criminal.

The scammer uses that genuine system event as borrowed authority. A real email does not prove the caller is a police officer, and a valid reference does not prove the allegations inside an unauthorized report are true.

Two Callers Create a Fake Chain of Custody

The first caller claims to be from the AFP or another police service. They say the target appeared in a data breach involving cryptocurrency, financial crime, or a compromised exchange account.

A second caller then claims to represent the victim’s cryptocurrency exchange, wallet provider, or security team. Both callers know the same case number, which makes the handoff feel coordinated and official.

In reality, the two roles can be played by members of the same operation. Their goal is to move crypto to a wallet controlled by the scammers or obtain the seed phrase that controls the victim’s existing wallet.

“Cold Storage” Is the Phrase That Hides the Theft

Cold storage is a real security concept. It usually means keeping private keys offline, away from internet-connected devices. The scammer abuses that familiar term to disguise an irreversible transfer.

The wallet address provided by the caller is not a police evidence account, an exchange vault, or a protected copy of the victim’s funds. It is simply a destination the criminal can control.

  • The target may already own cryptocurrency or a hardware wallet.
  • Stolen personal data makes the approach feel targeted.
  • A false ReportCyber report creates a genuine case reference.
  • A caller claims to be an AFP officer investigating a breach.
  • The target may be asked to confirm a real email or one-time PIN.
  • A second caller impersonates a cryptocurrency platform.
  • The same reference number links the two fictional roles.
  • The target is told to reveal a seed phrase or move crypto to “cold storage.”

The scam does not rely only on a badly written email or an obviously fake website. Criminals can use stolen personal information to submit a false report through Australia’s legitimate ReportCyber service.

That action can generate a genuine reference number and a real notification. The scammer then quotes the same number on the phone, making it seem that the caller must have access to an official police investigation.

The case is still fraudulent. The AFP and Cyber.gov.au warn that police will not ask for a wallet seed phrase, access to a crypto account, or a transfer into supposed “cold storage.”

Cyber.gov.au warning about scammers impersonating police to steal cryptocurrency and wallet seed phrases

Why the ReportCyber Reference Looks So Convincing

People are taught to verify unexpected calls. The scammers anticipate that advice and build an apparent verification step into the fraud.

ReportCyber allows a person to submit certain cybercrime reports on behalf of someone else. Criminals exploit that feature by entering information taken from a prior breach and naming the intended victim in the report.

The resulting email can come from legitimate government infrastructure. The reference number may also work in the real portal. Those facts verify only that a report was submitted, not who submitted it or whether its contents are accurate.

The criminal calls quickly, before the target has time to contact police independently. They may ask the victim to enter an email address in the ReportCyber portal and confirm that the case exists.

When the number appears, the caller seems validated. This is a form of process hijacking: the scammer does not need to forge the entire government service when they can misuse a real feature to manufacture supporting evidence.

The safest response is to end the call and contact ReportCyber or the Australian Cyber Security Hotline independently. Tell them that a report may have been submitted in your name without permission.

What the AFP Will Never Ask You to Do

Police may contact people during real investigations, and a cryptocurrency exchange may perform genuine security reviews. Neither situation requires blind obedience to the number displayed on an incoming call.

Cyber.gov.au states that the AFP and legitimate law enforcement officers will not ask you to transfer money or cryptocurrency, access your wallet, reveal a seed phrase, buy crypto, purchase gift cards, or remain on the line under pressure.

A seed phrase is the master recovery secret for a self-custody wallet. Anyone who receives it can recreate the wallet and control its assets. No legitimate investigator, exchange employee, or support agent needs those words.

An exchange may ask a customer to verify identity inside the official app or website. It should not instruct the customer to send assets to an address supplied during an unsolicited telephone call.

Police can preserve evidence through legal processes. They do not create an emergency “safe wallet” and ask a citizen to conduct the transfer personally as a security test.

If a caller says secrecy is required, that family members are involved, or that speaking to the bank will compromise the case, end the conversation. Those instructions protect the scammer, not an investigation.

How the Australian Federal Police Crypto Scam Works

Step 1: Stolen Data Identifies a Valuable Target

The campaign works best when the criminal already knows the target owns cryptocurrency. That information can come from breached customer lists, leaked marketing databases, malware, social media, previous scams, or records sold between criminal groups.

A name, telephone number, email address, exchange name, and approximate account value allow the caller to sound informed. The target may assume that only police or the real platform could know those details.

Personal information is not authentication. Data that was private yesterday may already be circulating among several criminal operations today.

Step 2: A False Report Is Filed in the Victim’s Name

The scammer uses the stolen information to submit a cybercrime report through ReportCyber. The report may claim that the target’s exchange account, wallet, email, or identity is connected to a breach.

A case reference is generated. The target may receive a legitimate notification because the criminal entered the victim’s real email address.

This step costs the scammer little but dramatically improves the story. It turns a cold call into a conversation supported by a government-generated event.

Step 3: A Fake AFP Officer Calls About the Case

The first caller introduces themselves as an AFP officer, investigator, or member of a cybercrime unit. Caller ID can be spoofed to display a familiar Australian number or even the name of an agency.

The caller says someone was arrested, an exchange was compromised, or the target appeared in a financial data breach. They may warn that the account is being watched by criminals.

The tone can be calm and professional rather than openly threatening. A patient caller with a badge number and case reference is often more persuasive than someone who immediately demands money.

Step 4: A Real Email or PIN Is Used as Proof

The caller asks the target to find the ReportCyber email, quote the case reference, or verify a one-time PIN. The message may be genuine because the scammer triggered it.

A one-time PIN should never be read to an unsolicited caller. Depending on the service, the code may confirm identity, allow access, or reveal that the victim is actively following instructions.

The important question is not whether the email exists. It is whether the target authorized the report and whether the caller can be verified through an independently obtained official number.

Step 5: A Fake Exchange Specialist Takes Over

The “officer” says a representative from the cryptocurrency platform will call next. The second caller quotes the same reference and may know details from the first conversation.

This handoff imitates cooperation between police and industry. It also divides the persuasion into two voices, giving the victim the impression that separate organizations agree about the emergency.

Do not call back using a number supplied by either person. Open the exchange’s official app, use its verified support route, and ask whether the account actually has a security case.

Scamwatch alert about police and digital currency exchange impersonation scams

Step 6: Crypto Is Moved to a Fake Safe Wallet

The second caller says the current wallet is exposed and the funds must be placed in “cold storage,” a “secure account,” an “evidence wallet,” or a “temporary protection address.”

The victim sends the assets themselves, so the transaction may initially look authorized to an exchange. Blockchain transfers are usually difficult to reverse once confirmed.

Another version asks for the wallet seed phrase, a screen-sharing session, exchange password, API key, or approval of a withdrawal. Each route gives the attacker control over the assets.

Step 7: The Transfer Is Followed by Silence or a New Fee

After the funds move, the callers may disappear. Others continue the performance and claim that tax, insurance, compliance, or network fees must be paid before the protected balance can be returned.

No additional payment releases crypto already controlled by the scammer. It only increases the loss and confirms that the victim remains responsive.

Later, a supposed investigator, law firm, blockchain analyst, or recovery service may offer to trace the assets for an advance fee. That can be the same group using details from the original fraud.

Company, Address, and Fulfillment Checks

An AFP Logo and Case Number Do Not Identify the Caller

Logos, letterheads, badge numbers, email signatures, and caller ID names can be copied or spoofed. A valid ReportCyber reference confirms a submission, not the identity of the person speaking.

End the call and contact the agency through a number found on its official website. A genuine officer can be verified without asking you to keep the original caller on the line.

The Domain Must Match the Government Service

Read the complete sender address and destination domain. Lookalike spellings, shortened links, free email accounts, and unrelated cloud forms do not become official because an AFP crest is displayed above them.

Even a genuine ReportCyber email must be treated as notice of a submitted report, not proof that its claims are true. Confirm whether the report was authorized.

The Police Caller and Exchange Caller May Be One Crew

Two voices do not create independent verification. The second scammer can receive the case number, personal data, and talking points through a shared chat or call-center system.

Contact the exchange inside its official app. Ask whether it initiated the call, whether withdrawals are pending, and whether any new device, API key, address, or security method was added.

The Wallet Destination Must Have a Verifiable Owner

A blockchain address is not self-identifying. Words such as “AFP cold storage” or “exchange safety wallet” exist only in the caller’s story unless the institution verifies that destination through an authenticated channel.

Police do not require citizens to transfer crypto to an investigative wallet. An exchange does not need a seed phrase to secure an account it already operates.

Warning Signs That Expose the Fake Investigation

  • You are contacted about a ReportCyber report you did not submit.
  • The caller already knows data that may have come from a breach.
  • An AFP badge number or case reference is offered as complete proof.
  • You are asked to read out a one-time PIN.
  • The caller insists you stay on the line while checking the case.
  • A second “exchange specialist” quotes the same reference number.
  • Your wallet is said to be unsafe, but the official app shows no warning.
  • You are told to move crypto into cold storage supplied by the caller.
  • A seed phrase, private key, password, or screen-sharing session is requested.
  • You are warned not to contact family, your bank, or official support.
  • Gift cards, crypto, or extra fees are described as part of the investigation.
  • The callers become aggressive when you try to verify them independently.

The real system can be misused, so a genuine email is not enough. The decisive test is the requested action. Police and legitimate exchanges do not secure assets by taking your seed phrase or directing an unsolicited transfer.

What to Do if You Have Fallen Victim to This Scam

  1. Stop communication and do not send another transaction. End the call, block the numbers, and ignore claims that one more payment will reverse or release the earlier transfer.
  2. Contact the cryptocurrency exchange immediately. Use the official app or website. Ask it to freeze withdrawals, revoke active sessions, flag destination addresses, preserve logs, and contact the receiving platform if the funds went to another exchange.
  3. Replace a wallet whose seed phrase was exposed. On a clean device, create a new wallet with a completely new seed phrase and move any remaining assets before the criminal does. Never reuse or digitally send the compromised words.
  4. Revoke every connected access path. Remove unknown API keys, wallet approvals, browser extensions, devices, recovery methods, and authorized applications. Change unique passwords for the exchange and email account, then enable strong multifactor authentication.
  5. Call ReportCyber independently. If a report was submitted without permission, contact the Australian Cyber Security Hotline at 1300 CYBER1 using the number from Cyber.gov.au. Include the false CIRS reference in a new report.
  6. Notify the bank or payment provider. If fiat money, cards, or bank transfers were involved, report the fraud immediately. Ask whether pending payments can be stopped and whether the accounts need replacement or enhanced monitoring.
  7. Preserve evidence before accounts disappear. Save the false notice, email headers, caller numbers, voicemails, case reference, wallet addresses, transaction hashes, exchange chats, screen-sharing records, and exact timeline.
  8. Get identity support. Contact IDCARE if personal information was exposed. Monitor email, credit, mobile service, government accounts, and financial statements because the same breached data may support another impersonation attempt.
  9. Scan devices used during the call. Run a full Malwarebytes scan if you installed remote-access software, a wallet extension, an app, or a file. Remove unfamiliar tools and update the device before creating new credentials.
  10. Add protection against malicious links and ads. AdGuard can block some known phishing domains and malicious advertising. It cannot judge a convincing telephone story, so continue verifying agencies and exchanges through independent channels.
  11. Report the scam through official channels. Report to Cyber.gov.au, Scamwatch, and the cryptocurrency platform. If there is an immediate threat or continuing account theft, contact police using a verified number.
  12. Refuse paid recovery promises. No stranger can guarantee a blockchain reversal. Do not send an advance fee, seed phrase, private key, or remote access to someone who found you through a complaint or social media post.

Frequently Asked Questions

Can a scammer create a real ReportCyber reference?

Yes. Criminals can submit a false report using stolen personal information. The resulting reference may be genuine even though the target did not authorize the report and the caller is not police.

Will the AFP ask me to move cryptocurrency to cold storage?

No. Official guidance states that the AFP will not ask people to transfer money or crypto, access a wallet, reveal seed phrases, buy crypto, or remain on the line under pressure.

Does a real government email prove the caller is genuine?

No. It may prove only that someone submitted a report. End the call and verify the report and caller through contact details found independently on an official government website.

What should I do if I revealed my seed phrase?

Treat the wallet as permanently compromised. Create a new wallet with a new seed phrase on a clean device, transfer remaining assets, and never use the old wallet for future storage.

Can a cryptocurrency transfer be reversed?

Usually not by the sender alone. Fast reporting may help an exchange freeze assets that reach a controlled account, so contact the platform immediately and provide transaction hashes and destination addresses.

Why does the scam use two different callers?

The handoff creates the illusion that police and the exchange independently confirmed the emergency. The callers can belong to the same operation and share every case detail.

The Bottom Line

The Australian Federal Police crypto scam turns a real reporting system into part of the deception. A genuine ReportCyber email and valid-looking reference can sit inside a completely false investigation.

Ignore the performance and focus on the requested action. Police and legitimate exchanges will not ask for a seed phrase or direct your assets into a wallet supplied during an unsolicited call.

Hang up, verify independently, and act quickly if any access or funds were exposed. Speed matters, but sending more money never fixes the original transfer.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

AI Passive Income System Scam Exposed: Fake Earnings Offer Investigation

Next

Autophagy Neuropathy Cure Scam Exposed: Fake AI Doctors and Nerve Pills