{"id":406717,"date":"2026-08-30T16:06:42","date_gmt":"2026-08-30T16:06:42","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=406717"},"modified":"2026-08-30T16:06:42","modified_gmt":"2026-08-30T16:06:42","slug":"australian-federal-police-crypto-scam-reportcyber","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/australian-federal-police-crypto-scam-reportcyber\/","title":{"rendered":"Australian Federal Police Crypto Scam Exposed: The Fake ReportCyber Call"},"content":{"rendered":"<p>A caller says the Australian Federal Police has found your name in a cryptocurrency data breach. They quote a real-looking case number, tell you to check ReportCyber, and promise another specialist will help secure your wallet.<\/p><div id=\"mwtad2146448614\" class=\"mwtadhigh-1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"7453445881\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The details feel unusually convincing because parts of the process can be real. That is exactly what makes the Australian Federal Police crypto scam so dangerous.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"361\" height=\"548\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-406713 lazyload\" alt=\"Fake Australian Federal Police investigation notice using an AFP logo and case reference\" loading=\"lazy\" title=\"\" sizes=\"auto, (max-width: 361px) 100vw, 361px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fake-afp-investigation-notice.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fake-afp-investigation-notice.png 361w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fake-afp-investigation-notice-198x300.png 198w\"><\/figure>\n<div id=\"mwtad2865295216\" class=\"mwtadheader-1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2917133959\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The Scam Builds Real Evidence Around a False Investigation<\/h3>\n<p>Most impersonation scams manufacture every detail. This campaign is more sophisticated because the criminal may submit an unauthorized ReportCyber report using the target&#8217;s real name, email address, and phone number.<\/p><div id=\"mwtad1163630866\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>ReportCyber is Australia&#8217;s legitimate national reporting channel. Its notification and case reference can therefore be genuine, even though the target never filed the report and the story attached to it was created by a criminal.<\/p>\n<p>The scammer uses that genuine system event as borrowed authority. A real email does not prove the caller is a police officer, and a valid reference does not prove the allegations inside an unauthorized report are true.<\/p>\n<h3>Two Callers Create a Fake Chain of Custody<\/h3>\n<p>The first caller claims to be from the AFP or another police service. They say the target appeared in a data breach involving cryptocurrency, financial crime, or a compromised exchange account.<\/p><div id=\"mwtad1904004826\" class=\"mwtadp2 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>A second caller then claims to represent the victim&#8217;s cryptocurrency exchange, wallet provider, or security team. Both callers know the same case number, which makes the handoff feel coordinated and official.<\/p>\n<p>In reality, the two roles can be played by members of the same operation. Their goal is to move crypto to a wallet controlled by the scammers or obtain the seed phrase that controls the victim&#8217;s existing wallet.<\/p>\n<h3>\u201cCold Storage\u201d Is the Phrase That Hides the Theft<\/h3>\n<p>Cold storage is a real security concept. It usually means keeping private keys offline, away from internet-connected devices. The scammer abuses that familiar term to disguise an irreversible transfer.<\/p><div id=\"mwtad4258040634\" class=\"mwtadp3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The wallet address provided by the caller is not a police evidence account, an exchange vault, or a protected copy of the victim&#8217;s funds. It is simply a destination the criminal can control.<\/p>\n<ul>\n<li>The target may already own cryptocurrency or a hardware wallet.<\/li>\n<li>Stolen personal data makes the approach feel targeted.<\/li>\n<li>A false ReportCyber report creates a genuine case reference.<\/li>\n<li>A caller claims to be an AFP officer investigating a breach.<\/li>\n<li>The target may be asked to confirm a real email or one-time PIN.<\/li>\n<li>A second caller impersonates a cryptocurrency platform.<\/li>\n<li>The same reference number links the two fictional roles.<\/li>\n<li>The target is told to reveal a seed phrase or move crypto to \u201ccold storage.\u201d<\/li>\n<\/ul>\n<p>The scam does not rely only on a badly written email or an obviously fake website. Criminals can use stolen personal information to submit a false report through Australia&#8217;s legitimate ReportCyber service.<\/p>\n<div id=\"mwtad2300690268\" class=\"mwtadp4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>That action can generate a genuine reference number and a real notification. The scammer then quotes the same number on the phone, making it seem that the caller must have access to an official police investigation.<\/p>\n<p>The case is still fraudulent. The AFP and Cyber.gov.au warn that police will not ask for a wallet seed phrase, access to a crypto account, or a transfer into supposed \u201ccold storage.\u201d<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-406714 lazyload\" alt=\"Cyber.gov.au warning about scammers impersonating police to steal cryptocurrency and wallet seed phrases\" loading=\"lazy\" title=\"\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/cyber-gov-afp-crypto-scam-warning-1024x576.jpg\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/cyber-gov-afp-crypto-scam-warning-1024x576.jpg 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/cyber-gov-afp-crypto-scam-warning-300x169.jpg 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/cyber-gov-afp-crypto-scam-warning.jpg 1265w\"><\/figure>\n<div id=\"mwtad2176359190\" class=\"mwtadheader-2 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9284335404\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the ReportCyber Reference Looks So Convincing<\/h2>\n<p>People are taught to verify unexpected calls. The scammers anticipate that advice and build an apparent verification step into the fraud.<\/p>\n<div id=\"mwtad2933071134\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9971336976\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>ReportCyber allows a person to submit certain cybercrime reports on behalf of someone else. Criminals exploit that feature by entering information taken from a prior breach and naming the intended victim in the report.<\/p>\n<p>The resulting email can come from legitimate government infrastructure. The reference number may also work in the real portal. Those facts verify only that a report was submitted, not who submitted it or whether its contents are accurate.<\/p>\n<p>The criminal calls quickly, before the target has time to contact police independently. They may ask the victim to enter an email address in the ReportCyber portal and confirm that the case exists.<\/p>\n<p>When the number appears, the caller seems validated. This is a form of process hijacking: the scammer does not need to forge the entire government service when they can misuse a real feature to manufacture supporting evidence.<\/p>\n<p>The safest response is to end the call and contact ReportCyber or the Australian Cyber Security Hotline independently. Tell them that a report may have been submitted in your name without permission.<\/p>\n<div id=\"mwtad3134206070\" class=\"mwtadheader-3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5345090394\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the AFP Will Never Ask You to Do<\/h2>\n<p>Police may contact people during real investigations, and a cryptocurrency exchange may perform genuine security reviews. Neither situation requires blind obedience to the number displayed on an incoming call.<\/p>\n<p>Cyber.gov.au states that the AFP and legitimate law enforcement officers will not ask you to transfer money or cryptocurrency, access your wallet, reveal a seed phrase, buy crypto, purchase gift cards, or remain on the line under pressure.<\/p>\n<p>A seed phrase is the master recovery secret for a self-custody wallet. Anyone who receives it can recreate the wallet and control its assets. No legitimate investigator, exchange employee, or support agent needs those words.<\/p>\n<p>An exchange may ask a customer to verify identity inside the official app or website. It should not instruct the customer to send assets to an address supplied during an unsolicited telephone call.<\/p>\n<p>Police can preserve evidence through legal processes. They do not create an emergency \u201csafe wallet\u201d and ask a citizen to conduct the transfer personally as a security test.<\/p>\n<p>If a caller says secrecy is required, that family members are involved, or that speaking to the bank will compromise the case, end the conversation. Those instructions protect the scammer, not an investigation.<\/p>\n<div id=\"mwtad2768256345\" class=\"mwtadheader-4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Australian Federal Police Crypto Scam Works<\/h2>\n<h3>Step 1: Stolen Data Identifies a Valuable Target<\/h3>\n<p>The campaign works best when the criminal already knows the target owns cryptocurrency. That information can come from breached customer lists, leaked marketing databases, malware, social media, previous scams, or records sold between criminal groups.<\/p>\n<p>A name, telephone number, email address, exchange name, and approximate account value allow the caller to sound informed. The target may assume that only police or the real platform could know those details.<\/p>\n<p>Personal information is not authentication. Data that was private yesterday may already be circulating among several criminal operations today.<\/p>\n<h3>Step 2: A False Report Is Filed in the Victim&#8217;s Name<\/h3>\n<p>The scammer uses the stolen information to submit a cybercrime report through ReportCyber. The report may claim that the target&#8217;s exchange account, wallet, email, or identity is connected to a breach.<\/p>\n<p>A case reference is generated. The target may receive a legitimate notification because the criminal entered the victim&#8217;s real email address.<\/p>\n<p>This step costs the scammer little but dramatically improves the story. It turns a cold call into a conversation supported by a government-generated event.<\/p>\n<h3>Step 3: A Fake AFP Officer Calls About the Case<\/h3>\n<p>The first caller introduces themselves as an AFP officer, investigator, or member of a cybercrime unit. Caller ID can be spoofed to display a familiar Australian number or even the name of an agency.<\/p>\n<p>The caller says someone was arrested, an exchange was compromised, or the target appeared in a financial data breach. They may warn that the account is being watched by criminals.<\/p>\n<p>The tone can be calm and professional rather than openly threatening. A patient caller with a badge number and case reference is often more persuasive than someone who immediately demands money.<\/p>\n<h3>Step 4: A Real Email or PIN Is Used as Proof<\/h3>\n<p>The caller asks the target to find the ReportCyber email, quote the case reference, or verify a one-time PIN. The message may be genuine because the scammer triggered it.<\/p>\n<p>A one-time PIN should never be read to an unsolicited caller. Depending on the service, the code may confirm identity, allow access, or reveal that the victim is actively following instructions.<\/p>\n<p>The important question is not whether the email exists. It is whether the target authorized the report and whether the caller can be verified through an independently obtained official number.<\/p>\n<h3>Step 5: A Fake Exchange Specialist Takes Over<\/h3>\n<p>The \u201cofficer\u201d says a representative from the cryptocurrency platform will call next. The second caller quotes the same reference and may know details from the first conversation.<\/p>\n<p>This handoff imitates cooperation between police and industry. It also divides the persuasion into two voices, giving the victim the impression that separate organizations agree about the emergency.<\/p>\n<p>Do not call back using a number supplied by either person. Open the exchange&#8217;s official app, use its verified support route, and ask whether the account actually has a security case.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-406715 lazyload\" alt=\"Scamwatch alert about police and digital currency exchange impersonation scams\" loading=\"lazy\" title=\"\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/scamwatch-afp-crypto-impersonation-alert-1024x576.jpg\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/scamwatch-afp-crypto-impersonation-alert-1024x576.jpg 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/scamwatch-afp-crypto-impersonation-alert-300x169.jpg 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/scamwatch-afp-crypto-impersonation-alert.jpg 1265w\"><\/figure>\n<h3>Step 6: Crypto Is Moved to a Fake Safe Wallet<\/h3>\n<p>The second caller says the current wallet is exposed and the funds must be placed in \u201ccold storage,\u201d a \u201csecure account,\u201d an \u201cevidence wallet,\u201d or a \u201ctemporary protection address.\u201d<\/p>\n<p>The victim sends the assets themselves, so the transaction may initially look authorized to an exchange. Blockchain transfers are usually difficult to reverse once confirmed.<\/p>\n<p>Another version asks for the wallet seed phrase, a screen-sharing session, exchange password, API key, or approval of a withdrawal. Each route gives the attacker control over the assets.<\/p>\n<h3>Step 7: The Transfer Is Followed by Silence or a New Fee<\/h3>\n<p>After the funds move, the callers may disappear. Others continue the performance and claim that tax, insurance, compliance, or network fees must be paid before the protected balance can be returned.<\/p>\n<p>No additional payment releases crypto already controlled by the scammer. It only increases the loss and confirms that the victim remains responsive.<\/p>\n<p>Later, a supposed investigator, law firm, blockchain analyst, or recovery service may offer to trace the assets for an advance fee. That can be the same group using details from the original fraud.<\/p>\n<div id=\"mwtad1351706922\" class=\"mwtadheader-6-2 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2830607691\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>An AFP Logo and Case Number Do Not Identify the Caller<\/h3>\n<p>Logos, letterheads, badge numbers, email signatures, and caller ID names can be copied or spoofed. A valid ReportCyber reference confirms a submission, not the identity of the person speaking.<\/p>\n<p>End the call and contact the agency through a number found on its official website. A genuine officer can be verified without asking you to keep the original caller on the line.<\/p>\n<h3>The Domain Must Match the Government Service<\/h3>\n<p>Read the complete sender address and destination domain. Lookalike spellings, shortened links, free email accounts, and unrelated cloud forms do not become official because an AFP crest is displayed above them.<\/p>\n<p>Even a genuine ReportCyber email must be treated as notice of a submitted report, not proof that its claims are true. Confirm whether the report was authorized.<\/p>\n<h3>The Police Caller and Exchange Caller May Be One Crew<\/h3>\n<p>Two voices do not create independent verification. The second scammer can receive the case number, personal data, and talking points through a shared chat or call-center system.<\/p>\n<p>Contact the exchange inside its official app. Ask whether it initiated the call, whether withdrawals are pending, and whether any new device, API key, address, or security method was added.<\/p>\n<h3>The Wallet Destination Must Have a Verifiable Owner<\/h3>\n<p>A blockchain address is not self-identifying. Words such as \u201cAFP cold storage\u201d or \u201cexchange safety wallet\u201d exist only in the caller&#8217;s story unless the institution verifies that destination through an authenticated channel.<\/p>\n<p>Police do not require citizens to transfer crypto to an investigative wallet. An exchange does not need a seed phrase to secure an account it already operates.<\/p>\n<div id=\"mwtad2051459923\" class=\"mwtadheader-6 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3648031192\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Warning Signs That Expose the Fake Investigation<\/h2>\n<ul>\n<li>You are contacted about a ReportCyber report you did not submit.<\/li>\n<li>The caller already knows data that may have come from a breach.<\/li>\n<li>An AFP badge number or case reference is offered as complete proof.<\/li>\n<li>You are asked to read out a one-time PIN.<\/li>\n<li>The caller insists you stay on the line while checking the case.<\/li>\n<li>A second \u201cexchange specialist\u201d quotes the same reference number.<\/li>\n<li>Your wallet is said to be unsafe, but the official app shows no warning.<\/li>\n<li>You are told to move crypto into cold storage supplied by the caller.<\/li>\n<li>A seed phrase, private key, password, or screen-sharing session is requested.<\/li>\n<li>You are warned not to contact family, your bank, or official support.<\/li>\n<li>Gift cards, crypto, or extra fees are described as part of the investigation.<\/li>\n<li>The callers become aggressive when you try to verify them independently.<\/li>\n<\/ul>\n<p>The real system can be misused, so a genuine email is not enough. The decisive test is the requested action. Police and legitimate exchanges do not secure assets by taking your seed phrase or directing an unsolicited transfer.<\/p>\n<div id=\"mwtad3082486498\" class=\"mwtadheader-7 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Stop communication and do not send another transaction.<\/strong> End the call, block the numbers, and ignore claims that one more payment will reverse or release the earlier transfer.<\/li>\n<li><strong>Contact the cryptocurrency exchange immediately.<\/strong> Use the official app or website. Ask it to freeze withdrawals, revoke active sessions, flag destination addresses, preserve logs, and contact the receiving platform if the funds went to another exchange.<\/li>\n<li><strong>Replace a wallet whose seed phrase was exposed.<\/strong> On a clean device, create a new wallet with a completely new seed phrase and move any remaining assets before the criminal does. Never reuse or digitally send the compromised words.<\/li>\n<li><strong>Revoke every connected access path.<\/strong> Remove unknown API keys, wallet approvals, browser extensions, devices, recovery methods, and authorized applications. Change unique passwords for the exchange and email account, then enable strong multifactor authentication.<\/li>\n<li><strong>Call ReportCyber independently.<\/strong> If a report was submitted without permission, contact the Australian Cyber Security Hotline at 1300 CYBER1 using the number from Cyber.gov.au. Include the false CIRS reference in a new report.<\/li>\n<li><strong>Notify the bank or payment provider.<\/strong> If fiat money, cards, or bank transfers were involved, report the fraud immediately. Ask whether pending payments can be stopped and whether the accounts need replacement or enhanced monitoring.<\/li>\n<li><strong>Preserve evidence before accounts disappear.<\/strong> Save the false notice, email headers, caller numbers, voicemails, case reference, wallet addresses, transaction hashes, exchange chats, screen-sharing records, and exact timeline.<\/li>\n<li><strong>Get identity support.<\/strong> Contact IDCARE if personal information was exposed. Monitor email, credit, mobile service, government accounts, and financial statements because the same breached data may support another impersonation attempt.<\/li>\n<li><strong>Scan devices used during the call.<\/strong> Run a full Malwarebytes scan if you installed remote-access software, a wallet extension, an app, or a file. Remove unfamiliar tools and update the device before creating new credentials.<\/li>\n<li><strong>Add protection against malicious links and ads.<\/strong> AdGuard can block some known phishing domains and malicious advertising. It cannot judge a convincing telephone story, so continue verifying agencies and exchanges through independent channels.<\/li>\n<li><strong>Report the scam through official channels.<\/strong> Report to Cyber.gov.au, Scamwatch, and the cryptocurrency platform. If there is an immediate threat or continuing account theft, contact police using a verified number.<\/li>\n<li><strong>Refuse paid recovery promises.<\/strong> No stranger can guarantee a blockchain reversal. Do not send an advance fee, seed phrase, private key, or remote access to someone who found you through a complaint or social media post.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Can a scammer create a real ReportCyber reference?<\/h3>\n<p>Yes. Criminals can submit a false report using stolen personal information. The resulting reference may be genuine even though the target did not authorize the report and the caller is not police.<\/p>\n<h3>Will the AFP ask me to move cryptocurrency to cold storage?<\/h3>\n<p>No. Official guidance states that the AFP will not ask people to transfer money or crypto, access a wallet, reveal seed phrases, buy crypto, or remain on the line under pressure.<\/p>\n<h3>Does a real government email prove the caller is genuine?<\/h3>\n<p>No. It may prove only that someone submitted a report. End the call and verify the report and caller through contact details found independently on an official government website.<\/p>\n<h3>What should I do if I revealed my seed phrase?<\/h3>\n<p>Treat the wallet as permanently compromised. Create a new wallet with a new seed phrase on a clean device, transfer remaining assets, and never use the old wallet for future storage.<\/p>\n<h3>Can a cryptocurrency transfer be reversed?<\/h3>\n<p>Usually not by the sender alone. Fast reporting may help an exchange freeze assets that reach a controlled account, so contact the platform immediately and provide transaction hashes and destination addresses.<\/p>\n<h3>Why does the scam use two different callers?<\/h3>\n<p>The handoff creates the illusion that police and the exchange independently confirmed the emergency. The callers can belong to the same operation and share every case detail.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The Australian Federal Police crypto scam turns a real reporting system into part of the deception. A genuine ReportCyber email and valid-looking reference can sit inside a completely false investigation.<\/p>\n<p>Ignore the performance and focus on the requested action. Police and legitimate exchanges will not ask for a seed phrase or direct your assets into a wallet supplied during an unsolicited call.<\/p>\n<p>Hang up, verify independently, and act quickly if any access or funds were exposed. Speed matters, but sending more money never fixes the original transfer.<\/p>\n<div id=\"mwtad3732442875\" class=\"mwtadfinal mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3077074880\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The Australian Federal Police crypto scam uses fake ReportCyber cases, real reference numbers, and cold storage calls to steal wallets and seed phrases.<\/p>\n","protected":false},"author":51,"featured_media":406713,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-406717","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/406717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=406717"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/406717\/revisions"}],"predecessor-version":[{"id":407317,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/406717\/revisions\/407317"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/406713"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=406717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=406717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=406717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}