{"id":401129,"date":"2026-08-13T03:06:55","date_gmt":"2026-08-13T03:06:55","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=401129"},"modified":"2026-08-13T03:06:55","modified_gmt":"2026-08-13T03:06:55","slug":"mygov-scam-emails","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/mygov-scam-emails\/","title":{"rendered":"myGov Scam Emails: Fake Refund, Account Lock and Message Alerts"},"content":{"rendered":"<p>An email claiming that your myGov account has been suspended can feel serious. The message may mention unusual activity, a tax refund, a new Medicare or Centrelink notice, or a deadline for verifying your identity.<\/p><div id=\"mwtad3670182734\" class=\"gas_fallback-ad_309684--placement_400588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Do not sign in through the email. myGov advises users to access the service through the official app or by typing <code>my.gov.au<\/code> into the browser. Fake messages use lookalike links to steal passwords, identity documents, banking details, and one-time security codes.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/mygov-account-suspended-scam-email.png\" alt=\"Example of a fake myGov account suspended phishing email\" title=\"\"><figcaption class=\"wp-element-caption\">A fake myGov suspension email uses government-style branding, a short deadline and an \u201cUnlock My Account\u201d button to send the recipient to phishing.<\/figcaption><\/figure>\n<div id=\"mwtad1545933403\" class=\"gas_fallback-ad_309747-ad_309691-placement_400589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<div id=\"mwtad568398998\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"> \r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"7312657698\"><\/ins>\r\n <\/div><p>myGov is the Australian Government&#8217;s online portal for accessing linked services such as the Australian Taxation Office, Medicare, Centrelink, Child Support, and other participating agencies.<\/p>\n<p>A stolen myGov login can therefore expose far more than one website. Depending on the services linked to the account, an attacker may find tax information, identity data, payment records, health-related correspondence, and contact details.<\/p>\n<p>Scammers impersonate myGov in email, text messages, telephone calls, sponsored ads, and fake search results. They often copy the dark blue branding, Australian Government crest, \u201csecure message\u201d language, and familiar references to tax or benefits.<\/p>\n<p>Official myGov guidance says genuine notifications direct users to sign in through the official app or by entering <code>my.gov.au<\/code> themselves. Unexpected messages should not be trusted simply because the sender name displays myGov.<\/p>\n<p>A real notification can tell you that a new message is available, but the safest response is always the same: leave the email, open myGov independently, and see whether the account contains the claimed notice.<\/p>\n<h3>What the fake suspension email may say<\/h3>\n<blockquote class=\"wp-block-quote\">\n<p><strong>Subject: Your myGov Account Has Been Suspended<\/strong><\/p>\n<p>We detected unusual activity on your account.<\/p>\n<p>Your access to linked services has been temporarily suspended. Verify your identity within 24 hours to avoid permanent deactivation.<\/p>\n<p><strong>UNLOCK MY ACCOUNT<\/strong><\/p>\n<\/blockquote>\n<p>The email may address the recipient by name or include a reference number. Those details can come from data breaches and do not prove that the sender has access to myGov.<\/p>\n<h3>Common variations of the email<\/h3>\n<ul>\n<li>\u201cYour myGov Account Has Been Suspended\u201d<\/li>\n<li>\u201cNew Secure Message Available in myGov\u201d<\/li>\n<li>\u201cATO Tax Refund Ready for Deposit\u201d<\/li>\n<li>\u201cConfirm Your Bank Details for a Refund\u201d<\/li>\n<li>\u201cMedicare Rebate Pending Verification\u201d<\/li>\n<li>\u201cCentrelink Payment Has Been Placed on Hold\u201d<\/li>\n<li>\u201cUnusual Sign-In Detected on Your myGov Account\u201d<\/li>\n<li>\u201cYour Digital Identity Will Expire Today\u201d<\/li>\n<li>\u201cAction Required: Update Your myGov Profile\u201d<\/li>\n<li>\u201cYou Have an Unread Government Document\u201d<\/li>\n<li>\u201cFinal Notice Before Account Deactivation\u201d<\/li>\n<li>\u201cmyGov Security Upgrade: Reconfirm Your Details\u201d<\/li>\n<\/ul>\n<p>SMS versions may use a shortened link and only a few words, such as \u201cmyGov: Your refund could not be deposited. Update account details now.\u201d The limited space hides the absence of an official domain.<\/p>\n<h3>Information the scammers are trying to collect<\/h3>\n<ul>\n<li>myGov email address or username and password<\/li>\n<li>One-time SMS or authenticator codes<\/li>\n<li>Tax File Number<\/li>\n<li>Medicare card and Centrelink information<\/li>\n<li>Passport or driver licence images<\/li>\n<li>Date of birth, address and telephone number<\/li>\n<li>Bank account and credit card details<\/li>\n<li>Answers to identity-verification questions<\/li>\n<\/ul>\n<p>Collecting several of these items gives an attacker enough material to impersonate the victim in later calls, attempt account recovery, redirect payments, or apply for services under a stolen identity.<\/p>\n<h3>Warning signs inside the message<\/h3>\n<ul>\n<li><strong>The link does not end in <code>my.gov.au<\/code>.<\/strong> Words such as myGov can appear anywhere in a fraudulent address.<\/li>\n<li><strong>The message threatens immediate loss of access.<\/strong> A short deadline is meant to replace verification with panic.<\/li>\n<li><strong>A refund requires card details or a fee.<\/strong> Government payments are not released by paying a verification charge to an email link.<\/li>\n<li><strong>The page asks for an authentication code.<\/strong> A code can authorize the attacker&#8217;s real login and should never be relayed to another person.<\/li>\n<li><strong>The attachment supposedly contains a secure message.<\/strong> Unexpected attachments can carry malware or open a fake sign-in form.<\/li>\n<li><strong>The sender uses a non-government domain.<\/strong> The display name and crest are easy to copy.<\/li>\n<li><strong>The message asks for passport or licence scans by email.<\/strong> Sensitive documents should not be sent in response to an unsolicited notification.<\/li>\n<\/ul>\n<div id=\"mwtad4049912778\" class=\"gas_fallback-ad_309748-ad_309691-placement_400590\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How The Operation Works<\/h2>\n<h3>1. The scam selects a government event people expect<\/h3>\n<p>Tax time, benefit changes, Medicare reimbursements, and security announcements create natural opportunities for impersonation. Campaigns can be scheduled when a large part of the public is already expecting government communication.<\/p>\n<p>The scammers may know only an email address or phone number. Mass distribution ensures that some messages reach people with an active claim, recent tax return, or upcoming payment.<\/p>\n<h3>2. The message turns uncertainty into urgency<\/h3>\n<p>A vague phrase such as \u201cnew secure message\u201d makes the recipient curious without revealing details that could be checked. A suspension or refund story adds a cost to waiting.<\/p>\n<p>The deadline is artificial. It encourages the recipient to use the supplied button rather than independently opening the real account.<\/p>\n<h3>3. A lookalike site copies the myGov sign-in page<\/h3>\n<p>The landing page can reproduce colors, logos, accessibility links, privacy wording, and a familiar sign-in form. It may be hosted on a domain containing words such as secure, services, gov, digital, or Australia.<\/p>\n<p>The padlock in the browser only indicates encryption between the visitor and that site. Fraudulent sites can obtain HTTPS certificates too.<\/p>\n<h3>4. Credentials are relayed to the attacker<\/h3>\n<p>After the victim enters a username and password, the kit records them. A message such as \u201csession expired\u201d or \u201cdetails incorrect\u201d can prompt a second attempt and help confirm the password.<\/p>\n<p>The operator may immediately try those details on the real myGov service. Fast action matters because the next stage can happen while the victim is still viewing the fake page.<\/p>\n<h3>5. The fake page asks for the security code<\/h3>\n<p>When the real service sends a one-time code, the phishing site asks the victim to enter it for \u201cidentity confirmation.\u201d The attacker uses that code to complete a separate login.<\/p>\n<p>A one-time code protects an account only when it remains between the account holder and the official service. Giving it to a page reached through an unexpected message defeats that protection.<\/p>\n<h3>6. A verification form harvests identity documents<\/h3>\n<p>The next page may request a Tax File Number, Medicare details, date of birth, licence number, passport, selfie, or proof of address. The form claims these items are needed to unlock the account or process the refund.<\/p>\n<p>Those records can support identity theft even if the attacker never maintains access to myGov. Document images can be reused in applications and social-engineering calls.<\/p>\n<h3>7. The refund story collects banking information<\/h3>\n<p>A fake refund page asks for an account name, BSB, account number, or card information. Some versions place a small \u201cauthorization\u201d charge on the card or subscribe the victim to an unrelated service.<\/p>\n<p>Government branding makes the request feel administrative, but the destination is controlled by criminals. Verify payments through the account, not the message.<\/p>\n<h3>8. Compromised accounts enable further changes<\/h3>\n<p>An intruder may attempt to change recovery details, access linked services, obtain tax records, or redirect correspondence. They may also use the information to impersonate the victim when contacting agencies or financial institutions.<\/p>\n<p>The victim can then receive follow-up calls from someone claiming to investigate the first incident. A legitimate-looking caller ID does not prove identity because numbers can be spoofed.<\/p>\n<h3>Why the URL is more important than the page design<\/h3>\n<p>A convincing myGov replica can be created from public images. The browser address identifies where information is actually being sent. Read from the domain ending backward and confirm the registered domain is exactly <code>my.gov.au<\/code>.<\/p>\n<p>Do not rely on a Google ad or search result for urgent account recovery. Open the official myGov app or type the address yourself, particularly after receiving a threat or refund promise.<\/p>\n<h3>How the refund version changes the emotional pressure<\/h3>\n<p>The suspension message uses fear, but a refund message uses opportunity. It claims the ATO, Medicare, or another service has approved money that cannot be deposited until banking details are confirmed.<\/p>\n<p>A specific amount and recent-looking date can make the refund feel connected to a tax return or medical expense. The campaign may be sent during tax season or after public announcements about payments, increasing the chance of a coincidental match.<\/p>\n<p>The fake page first requests a myGov login and then displays an invented refund dashboard. It may ask for a BSB and account number, card details, or a small identity-verification payment. Supplying a card does not direct a government refund. It gives the operator a payment method.<\/p>\n<h3>How the secure-message version hides the subject<\/h3>\n<p>A genuine-style notification may say only that a new message is available. Scammers use the same lack of detail because curiosity encourages a click and there is no false tax amount to challenge.<\/p>\n<p>The email can claim that privacy rules prevent it from displaying the notice. That explanation makes the hidden content feel responsible while directing the recipient to a counterfeit login page.<\/p>\n<p>The safe response does not depend on the subject. Open myGov independently. If the notification is real, the same message will be waiting in the account. If it is not there, do not return to the email to try another link.<\/p>\n<h3>Account recovery is part of the attack surface<\/h3>\n<p>Phishing forms sometimes ask for email access, recovery answers, identity documents, and one-time codes because the attacker wants to change myGov recovery settings. Securing only the myGov password may be insufficient if the connected email remains exposed.<\/p>\n<p>Review both accounts for unfamiliar sessions, changes, forwarding, and recovery methods. If a scammer called while the form was open, also check whether any screen-sharing or support application was installed.<\/p>\n<div id=\"mwtad1058098616\" class=\"gas_fallback-ad_309749-ad_309691-placement_400591\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What To Do If You Clicked or Shared Details<\/h2>\n<ol>\n<li><strong>Close the page and stop communication.<\/strong> Do not continue uploading documents or call a number displayed by the site.<\/li>\n<li><strong>Change the myGov password from the official service.<\/strong> Use the app or type <code>my.gov.au<\/code>. Create a strong password not used anywhere else.<\/li>\n<li><strong>Review sign-in activity and account details.<\/strong> Check for unfamiliar access, changed recovery information, newly linked services, and altered bank or contact details.<\/li>\n<li><strong>Secure the associated email account.<\/strong> Change its password, review forwarding rules, sign out unknown sessions, and enable multifactor authentication.<\/li>\n<li><strong>Contact myGov or Services Australia through official channels.<\/strong> Explain exactly what credentials, codes, or documents were submitted and ask for account-protection steps.<\/li>\n<li><strong>Contact financial institutions if banking data was exposed.<\/strong> Ask the bank to monitor or restrict the account and replace a compromised card when appropriate.<\/li>\n<li><strong>Protect identity documents.<\/strong> If a licence, passport, Medicare card, or Tax File Number was disclosed, follow the issuing agency&#8217;s identity-compromise guidance.<\/li>\n<li><strong>Check linked-service records.<\/strong> Review ATO, Medicare, Centrelink, and other relevant activity for changes or claims you do not recognize.<\/li>\n<li><strong>Scan the device if a file or application was opened.<\/strong> Update the system, remove unknown software, and run a trusted security scan.<\/li>\n<li><strong>Report the scam.<\/strong> myGov says suspicious messages can be sent to <code>reportascam@servicesaustralia.gov.au<\/code>. Keep screenshots, headers, links, and transaction evidence.<\/li>\n<\/ol>\n<p>Services Australia provides a Scams and Identity Theft Help Desk for people affected by identity fraud. Obtain the current contact details from an official government page rather than from the suspicious message.<\/p>\n<p>Keep a written timeline of what was entered and when. Include security codes, document images, banking details, changes noticed in linked services, and calls received afterward. A clear timeline helps myGov, Services Australia, banks, and identity-support services respond without relying on memory during a stressful incident.<\/p>\n<p>Warn other members of the household if the message referred to a shared address, family payment, or linked benefit. Scammers often reuse the same details against relatives once one person responds.<\/p>\n<div id=\"mwtad1300643581\" class=\"gas_fallback-ad_309750-ad_309691-placement_400592\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4041237300\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Bottom Line<\/h2>\n<p>myGov phishing messages imitate account locks, refunds, secure notices, Medicare rebates, and Centrelink payments. Their purpose is to move the recipient from a trusted government name to a site controlled by the attacker.<\/p>\n<p>Do not sign in, upload documents, or enter a code through an unexpected email or text. Open the official app or type <code>my.gov.au<\/code>, then check the claim inside the account. That simple separation between message and service prevents most versions of the scam.<\/p>\n<div id=\"mwtad3814057783\" class=\"gas_fallback-ad_176819-ad_309691-placement_400595\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Fake myGov emails claim an account is suspended, a refund is waiting or a secure message arrived, then steal credentials, codes and identity documents.<\/p>\n","protected":false},"author":51,"featured_media":401128,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49,2842,2849],"tags":[3339,3338,3320,3340,3337],"class_list":["post-401129","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","category-impersonation-scams","category-other-scams","tag-ato-refund-scam","tag-australian-government-scam","tag-email-scams","tag-mygov-phishing","tag-mygov-scam","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/401129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=401129"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/401129\/revisions"}],"predecessor-version":[{"id":401621,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/401129\/revisions\/401621"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/401128"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=401129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=401129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=401129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}