{"id":424904,"date":"2026-10-08T08:37:47","date_gmt":"2026-10-08T08:37:47","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=424904"},"modified":"2026-10-08T08:37:47","modified_gmt":"2026-10-08T08:37:47","slug":"ato-income-statement-remote-access-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/ato-income-statement-remote-access-scam\/","title":{"rendered":"ATO Income Statement Scam: Fake Tax Emails Hide a Remote Access Download"},"content":{"rendered":"<p>Your income statement is ready. The email looks like another small tax task, the sort you might clear between a work message and a bill.<\/p><div id=\"mwtad1883290153\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Then the next page asks you to download something. That unexpected detour is at the center of the ATO income statement scam.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/malwaretips-ato-malware-scam-1.png\" class=\"wp-image-424905\" width=\"1536\" height=\"1024\" style=\"aspect-ratio: 1536 \/ 1024\" alt=\"Illustrative fake ATO email offering an income statement through an unsolicited link\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/malwaretips-ato-malware-scam-1.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/malwaretips-ato-malware-scam-1-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/malwaretips-ato-malware-scam-1-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure>\n<div id=\"mwtad174640218\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The ATO has confirmed this remote-access download campaign<\/h3>\n<p>The Australian Taxation Office&#8217;s September 2026 warning describes scam emails about a new payment update or an income statement that recipients supposedly need to review.<\/p><div id=\"mwtad517876276\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The included link leads to a page offering a file to view or download. The next click downloads malicious remote desktop connection software.<\/p>\n<p>This is a confirmed scam campaign, not a billing dispute or speculation about an unusual email. The tax agency itself has warned people about the mechanism.<\/p>\n<p>The ATO is being impersonated. A message that borrows its name does not make the agency responsible for the download or the person behind it.<\/p><div id=\"mwtad524995684\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>A routine document becomes an unexpected software request<\/h3>\n<p>The hook is ordinary enough to fit a busy inbox. An income statement sounds like something you might need for a return, accountant, or financial record.<\/p>\n<p>The danger appears when the supposed document route introduces software that can allow someone else access to your device.<\/p>\n<p>A file download is not automatically an installation or a completed intrusion. What happened after the download matters when deciding how to respond.<\/p><div id=\"mwtad4268683180\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<ul>\n<li>An unsolicited email claiming a tax statement or payment update is available.<\/li>\n<li>A button or link directing you away from your usual ATO access.<\/li>\n<li>A landing page offering to view or download the supposed file.<\/li>\n<li>An unexpected program or connection-related file instead of the document you expected.<\/li>\n<li>An instruction to open, install, allow, or connect something to finish viewing it.<\/li>\n<\/ul>\n<h3>The right response depends on how far you went<\/h3>\n<p>Someone who only read the email has a different exposure from someone who ran a download and opened banking on the affected computer.<\/p>\n<p>Do not panic, but do not dismiss a software request as a harmless document error. Establish the sequence and protect any accounts that may have been exposed.<\/p>\n<div id=\"mwtad1342764751\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The agency&#8217;s <a href=\"https:\/\/www.ato.gov.au\/online-services\/scams-cyber-safety-and-identity-protection\/scam-alerts\" target=\"_blank\" rel=\"noopener\">live scam alert<\/a> confirms the campaign. It does not name one universal filename, malware family, or outcome for every recipient.<\/p>\n<p>Our screen examples are reconstructions using fictional addresses and filenames. They illustrate the document-to-download switch, rather than identifying an official portal or a captured malicious file.<\/p>\n<div id=\"mwtad4166450279\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Moment a Tax Document Stops Being a Tax Document<\/h2>\n<p>A familiar workflow can make an unfamiliar instruction feel necessary. You wanted to view a statement, so the page tells you what supposedly comes next.<\/p>\n<p>Perhaps a button says the file needs a secure viewer. Perhaps the browser downloads something whose name sounds related to your income record.<\/p>\n<p>The request deserves a pause. An administrative task should not persuade you to grant access to an unknown person merely because a page calls the process secure.<\/p>\n<p>The word secure is part of the presentation. It does not establish who operates the page, where the file came from, or what running it will do.<\/p>\n<p>Even a clean layout can hide the mismatch. A document tile, loading indicator, and blue button can make a download look like normal troubleshooting.<\/p>\n<p>Follow the promised result instead of the design. You expected tax information, not a new application, remote session, or permission to control the computer.<\/p>\n<p>That distinction is particularly useful on a work device. A rushed employee may install a supposed viewer before asking why an external email requires it.<\/p>\n<p>If something seems missing, stop at that point. Do not keep trying different buttons or devices until one successfully opens the suspicious file.<\/p>\n<div id=\"mwtad1369618764\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the ATO Income Statement Scam Works<\/h2>\n<h3>Step 1: The email presents a believable tax update<\/h3>\n<p>The impersonator says a statement is ready or a payment update has been added to your ATO profile. The message offers a convenient route to review it.<\/p>\n<p>Unlike a dramatic arrest threat, this lure can succeed without frightening you. It simply gives you a small task that looks worth completing.<\/p>\n<p>People handling tax paperwork may already expect notifications. The scammer benefits when their message happens to arrive among genuine administrative emails.<\/p>\n<p>Receiving it does not prove a change occurred in your account. The underlying update remains a claim until you check through your established government-service access.<\/p>\n<h3>Step 2: The link moves you into a separate viewing page<\/h3>\n<p>The email&#8217;s link opens a page that invites you to view or download a file. The ATO has identified this intermediate stage in its warning.<\/p>\n<p>The page may look more convincing because you reached it while pursuing a plausible document. You have already invested attention in the task.<\/p>\n<p>Do not assume that a page showing your expected document title belongs to the ATO. The title can be supplied by whoever created the page.<\/p>\n<p>Nor does a padlock authenticate the operator. It can show an encrypted connection while you are still communicating with the wrong website.<\/p>\n<h3>Step 3: The supposed file triggers a remote-access download<\/h3>\n<p>This is the confirmed switch: the viewing or download link delivers remote desktop connection software rather than the safe document route the message implied.<\/p>\n<p>Do not open the file to find out what it is. Record the visible filename and download time without executing it.<\/p>\n<p>The exact file type can vary. A familiar-looking name or extension is not sufficient to establish safety, and this article does not identify one universal payload.<\/p>\n<p>A browser or operating-system warning is a reason to stop. The website cannot make the warning irrelevant by claiming installation is required.<\/p>\n<p>In our illustrative page, the fictional viewer filename makes the switch visible. It is not a detection signature for this campaign.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/malwaretips-ato-malware-scam-2.png\" class=\"wp-image-424906\" width=\"1536\" height=\"1024\" style=\"aspect-ratio: 1536 \/ 1024\" alt=\"Illustrative document portal replacing an income statement with a viewer software download\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/malwaretips-ato-malware-scam-2.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/malwaretips-ato-malware-scam-2-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/malwaretips-ato-malware-scam-2-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure>\n<h3>Step 4: Running or approving the file may enable access<\/h3>\n<p>Downloading stores a file; opening it or approving a connection may take the incident further. The software and permissions determine what access becomes possible.<\/p>\n<p>Remote-access tools are also used legitimately. The fraud here is persuading you to accept an unknown connection under the false explanation of reviewing tax information.<\/p>\n<p>Do not enter credentials, open banking, or show identity documents while an unverified session may be active. Stop using the device for sensitive tasks.<\/p>\n<p>If another person appears to move the pointer or control windows, disconnect the device from the network and contact trusted technical help.<\/p>\n<p>Absence of visible movement is not proof that nothing happened. A quiet screen cannot confirm which programs ran or what permissions were granted.<\/p>\n<h3>Step 5: The incident can extend beyond the missing statement<\/h3>\n<p>Device access can expose information unrelated to tax. What becomes accessible depends on the session, software, open applications, and actions taken.<\/p>\n<p>This does not mean every recipient loses money or every downloaded file immediately compromises every account. Avoid guessing beyond the evidence.<\/p>\n<p>Focus on what was actually open and entered. Banking, email, password managers, and work applications deserve attention if they were used during the suspicious session.<\/p>\n<p>Later contact may offer help restoring the statement or fixing a tax-profile error. Do not use that same sender to investigate their own download.<\/p>\n<div id=\"mwtad3351997949\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Which Checks Actually Help Before You Click?<\/h2>\n<h3>Open the government service through your normal route<\/h3>\n<p>Use a trusted bookmark, official app, or address you independently entered. Review the ATO service linked through myGov rather than following the email&#8217;s shortcut.<\/p>\n<p>If a statement or payment needs attention, handle it there. Ask your registered tax agent about unfamiliar correspondence through contact details you already know.<\/p>\n<p>You are checking whether the claimed update exists, not trying to prove the email genuine from its color scheme.<\/p>\n<h3>Inspect the action, not just the sender name<\/h3>\n<p>Expand sender details and inspect the destination where possible, without following it. An unrelated domain or unexpected download route strengthens the warning.<\/p>\n<p>However, a plausible display name is weak evidence. A scam can contain genuine agency addresses in its signature while its button leads somewhere else.<\/p>\n<p>The most useful question is simple: why would viewing this tax record require me to run unfamiliar software from an unsolicited email?<\/p>\n<h3>Verify uncertain contact directly with the ATO<\/h3>\n<p>The agency publishes <a href=\"https:\/\/www.ato.gov.au\/online-services\/scams-cyber-safety-and-identity-protection\/verify-or-report-an-ato-scam\" target=\"_blank\" rel=\"noopener\">verification and reporting guidance<\/a>, including its scam contact number, 1800 008 540.<\/p>\n<p>Get the contact details independently. Do not call a help number on the download page to ask whether you should install its file.<\/p>\n<p>If the message reached a business mailbox, send the evidence to your IT or security team through your normal reporting process.<\/p>\n<h2>Clicked, Downloaded, or Installed: Keep Those Separate<\/h2>\n<p>It is easy to say you clicked the scam when you are upset. A clearer description helps a responder decide what needs urgent attention.<\/p>\n<p>Start with the email. Did you only read it, or did you follow its link? Did the browser save a file automatically?<\/p>\n<p>Then identify what you did with that file. Did you leave it in Downloads, double-click it, approve a prompt, or enter an access code?<\/p>\n<p>Finally, note any accounts used afterward. Did you type an email password, open online banking, access work files, or approve an authentication notification?<\/p>\n<p>Do not recreate those steps on the suspicious website just to improve your explanation. Use the existing downloads list, messages, and memory of the event.<\/p>\n<p>A technical helper may need to examine the device. Let them explain their method before giving access, particularly if they contacted you after the scam.<\/p>\n<p>Trusted assistance should come from your established support provider or workplace team. A new unsolicited rescue offer is not automatically safer than the original email.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li>\n<p><strong>Stop interacting with the viewing page.<\/strong> Close it and cancel any pending download or installation. Do not approve further prompts because the statement still will not open.<\/p>\n<p>If you only read the email, report it and remove it. There is no reason to assume a completed remote session from the email alone.<\/p>\n<\/li>\n<li>\n<p><strong>Isolate a device that ran suspicious software.<\/strong> Disconnect its network connection and avoid logging into additional accounts until you receive trusted technical advice.<\/p>\n<p>Do not reconnect simply to speak with the alleged tax-support team. Use a separate trusted device or phone to contact genuine assistance.<\/p>\n<\/li>\n<li>\n<p><strong>Give your technician or IT team the sequence.<\/strong> Explain the link, download, opening action, permission prompts, visible session behavior, and accounts accessed.<\/p>\n<p>Ask them to assess remote-access software and persistence, rather than assuming deleting one downloaded file ends an already installed connection.<\/p>\n<\/li>\n<li>\n<p><strong>Secure exposed accounts from a different trusted device.<\/strong> Change compromised passwords through the official services, review sessions, and remove unfamiliar recovery information.<\/p>\n<p>If this involved a workplace account, let the security team coordinate recovery. They may need to revoke sessions or examine activity beyond your individual computer.<\/p>\n<\/li>\n<li>\n<p><strong>Tell financial providers if banking was exposed.<\/strong> Explain whether the suspicious session could view the account, whether you entered credentials, and whether any transactions changed.<\/p>\n<p>Ask about immediate protections and disputed payments. Do not describe an authorized transfer as something else; accurate details help the fraud team assess it.<\/p>\n<\/li>\n<li>\n<p><strong>Contact the actual ATO.<\/strong> Report exposure of tax identity information, myGov access, or payments through its verified scam channel.<\/p>\n<p>For an untouched scam email, the agency lists ReportScams@ato.gov.au. If you shared sensitive information or paid, call the independently verified number promptly.<\/p>\n<\/li>\n<li>\n<p><strong>Inspect and protect the affected device.<\/strong> Malwarebytes can assist with detecting malware and unwanted software on supported systems after suspicious execution.<\/p>\n<p>A clean scan alone does not prove every session and account is safe. Pair device assessment with account recovery and the technician&#8217;s findings.<\/p>\n<p>AdGuard can help limit known malicious browsing destinations and redirects. It cannot remove an established remote session or recover information already exposed.<\/p>\n<\/li>\n<li>\n<p><strong>Preserve useful evidence without spreading the payload.<\/strong> Save the email, destination text, filename, timestamps, screenshots, and any payment records privately.<\/p>\n<p>For Australian cybercrime, use <a href=\"https:\/\/www.cyber.gov.au\/report\" target=\"_blank\" rel=\"noopener\">ReportCyber<\/a> through the official website. Follow responder instructions before forwarding a suspicious executable or reopening a file.<\/p>\n<\/li>\n<li>\n<p><strong>Watch for another request framed as cleanup.<\/strong> Reject demands for a fee, access code, or new download to restore a statement or reimburse losses.<\/p>\n<p>Continue checking your genuine tax records independently. Solving the device incident should not send you back into the same unverified email conversation.<\/p>\n<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Has the ATO confirmed the income statement malware scam?<\/h3>\n<p>Yes. Its September 2026 alert describes tax-themed emails leading to a view\/download page that delivers malicious remote desktop connection software.<\/p>\n<h3>Is the payment update version a different warning?<\/h3>\n<p>The agency includes both payment-update and income-statement wording in the same malware warning. The shared danger is the unexpected remote-access download.<\/p>\n<h3>Does saving the file mean someone controls my computer?<\/h3>\n<p>Not automatically. Saving, opening, installing, and approving a connection are different actions. Report the actual sequence so trusted support can assess your exposure.<\/p>\n<h3>Can I fix the problem by deleting the download?<\/h3>\n<p>If it was never opened, removal can stop accidental execution. If it ran or installed software, deleting the original download may leave the installed component unaffected.<\/p>\n<h3>Should I log into myGov on the affected device?<\/h3>\n<p>Not while an unverified remote session or suspicious installation may be active. Use a different trusted device to verify correspondence and protect any exposed account.<\/p>\n<h3>What if I clicked but did not enter information or run anything?<\/h3>\n<p>Close the page and check whether a file was downloaded. Report the email and keep software current. A page visit alone does not establish a completed compromise.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The ATO income statement scam turns an ordinary tax update into a remote-access download. That software detour is the warning you should not ignore.<\/p>\n<p>Check statements through your established ATO access. If you ran the download, stop sensitive activity, isolate the device, and coordinate recovery through trusted support.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Your income statement is ready. The email looks like another small tax task, the sort you might clear between a work message and a bill. Then the next page asks you to download something. That &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"ATO Income Statement Scam: Fake Tax Emails Hide a Remote Access Download\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/ato-income-statement-remote-access-scam\/#more-424904\" aria-label=\"Read more about ATO Income Statement Scam: Fake Tax Emails Hide a Remote Access Download\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":424905,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-424904","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/424904","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=424904"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/424904\/revisions"}],"predecessor-version":[{"id":424907,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/424904\/revisions\/424907"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/424905"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=424904"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=424904"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=424904"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}