Loading
Detectives warn of tax time cybercrime

September 7th, 2024Detectives warn of tax time cybercrime

Detectives from the Cybercrime Squad are urging Victorians to be vigilant of scammers targeting myGov sign in details to commit tax fraud.

Detectives from the Cybercrime Squad are urging Victorians to be vigilant of scammers targeting myGov sign in details to commit tax fraud.

Scammers are attempting to fraudulently access linked government services during the annual rush to complete tax returns, before either generating fraudulent payments in the victim’s name, or redirecting tax refunds to be paid into their own accounts.

Since 30 June of this year, Victoria Police has received over 300 reports, with a total reported loss of at least $2M so far.

Scammers use a variety of methods to compromise their victims’ identities, including sending phishing email and SMS scams to impersonate government agencies.

These scams can contain links to fake myGov websites. Victims will be prompted to enter their details, unknowingly giving criminals access to their genuine myGov accounts linked to their ATO accounts. Once they have access, scammers are able to pose as the victim in order to commit fraud.

Scammers will use the cover of events such as annual tax time to lure potential victims. Common phrases currently being used by scammers include:

  • ‘You are due to receive an ATO Direct refund’
  • ‘You have a new message in your myGov inbox – click here to view’
  • ‘You need to update your details to allow your Tax return to be processed’
  • ‘We need to verify your incoming tax deposit’
  • ‘ATO Refund failed due to incorrect BSB/Account number’
  • ‘Your income statement is ready, click on the link to view’

Once the offenders have gained access to an account, they are able to pose as the victim in order to commit fraud.

Since 30 June of this year, Victoria Police has received:

  • 180 reports of government payment redirection,
  • 66 reports of unauthorised online account access (ATO or myGov),
  • 48 reports of myGov SMS impersonation, and
  • 15 reports of identity takeover (myGov account)

The 309 reports thus far equal a total reported loss of $2,056,841.

There are a number of steps users can take to protect themselves:

  • Never click on a hyperlink that has been texted or emailed. The ATO and myGov won’t send you an SMS or email with a link to access online services – always access these directly by typing ato.gov.au or my.gov.au into your browser.
  • Use a Digital ID, such as myGovID, to access ATO online services through myGov and set your online access strength to the highest level you can achieve
  • Enable multi-factor authentication where possible.
  • Consider setting up a passkey such as facial or fingerprint recognition.

If you suspect someone is using your tax information illegally or has stolen your personal identity documents, contact the ATO as soon as possible on 1800 467 033. They will explain the safeguards that need to be applied to keep your ATO account safe.

Call Services Australia’s Scams and Identity Theft Helpdesk on 1800 941 126 if you’ve:

  • opened a link in a suspicious text message, email or social media message that pretending to be from Services Australia or myGov.
  • given someone your myGov sign in details or other personal information.
  • visited a website or downloaded a fake app that that pretended to be Services Australia or myGov.

Report any suspicious contact claiming to be from the ATO to ReportScams@ato.gov.au.

There’s more information about myGov scams and what to do if you have been affected by one at myGov scams | myGov

Scams that are not impersonating the ATO, myGov or a Services Australia brand can be reported to Report a scam | Scamwatch

Detective Senior Sergeant John Cheyne, Cybercrime Squad: “We’re encouraging everyone to be hypervigilant when it comes to scams such as these. Never click on a link sent to you that is purporting to be from the Australian Taxation Office or myGov, they will never ask you to access any online services via a link.

“Make sure you access your accounts through legitimate apps or via independent searches.

“We’re also finding that victims are ignoring what are actually legitimate texts from organisations indicating their accounts have been accessed, thinking they are scams. If you receive a text like this, log in to your account via a legitimate app or an independent search and make sure everything is as it should be. Change your password and phone the ATO helpline if necessary.

“We’d also recommend you conduct a bi-yearly health check of your accounts. Check your credit score or log in to your myGov account to make sure no edits have been made throughout the year that weren’t done by you.

“Account compromises such as these are often not identified until months after they’ve occurred, when the victim next logs in to their account.

“We encourage anyone who has been subject to a scam such as this to speak to police.”

Anyone with any information on scam activity is urged to contact Crime Stoppers on 1800 333 000 or make a confidential report at www.crimestoppersvic.com.au

Global sting sees Australian offenders arrested for cybercrime and phishing attacks

April 27th, 2024Global sting sees Australian offenders arrested for cybercrime and phishing attacks

Five individuals have been arrested across Australia, and 32 overseas, following an international police takedown of a cybercrime platform used by cybercriminals to steal personal credentials from victims around the world, including more than 94,000 people in Australia.

Five individuals have been arrested across Australia, and 32 overseas, following an international police takedown of a cybercrime platform used by cybercriminals to steal personal credentials from victims around the world, including more than 94,000 people in Australia.

Australian offenders are allegedly among 10,000 cybercriminals globally who have used the platform, known as LabHost, to trick victims into providing their personal information, such as online banking logins, credit card details and passwords, through persistent phishing attacks sent via texts and emails.

As a result of the Australian arm of the investigation, led by the AFP’s Joint Policing Cybercrime Coordination Centre (JCP3), more than 200 officers from the AFP and state and territory police were yesterday (17 April, 2024) involved in executing 22 search warrants across five states. This included 14 in Victoria, two in Queensland, three in NSW, one in South Australia and two in Western Australia.

A Melbourne man and an Adelaide man, who police will allege were LabHost users, were arrested during the warrants and charged with cybercrime-related offences. Three Melbourne men were also arrested by Victoria Police and charged with drug-related offences.

In addition to the takedown of the LabHost’s domain, the JPC3 took down 207 criminal servers. These servers were used to host fraudulent phishing websites created by LabHost, established with the sole intention of facilitating criminal offences against ordinary, hardworking Australians.

Phishing is a technique used by criminals to trick victims into providing personal information, such as their banking logins, credit card details and passwords, often through fraudulent links sent to them via texts and emails, in order to commit criminal offences or steal their money.

The AFP alleges LabHost was marketed as a ‘one-stop-shop’ for phishing, enabling cybercriminals to replicate more than 170 fraudulent websites of reputable banks, government entities and other major organisations, to trick unsuspecting victims into believing they were the legitimate websites.

Once cybercriminals had replicated a website, they would use LabHost to send texts and emails to victims, prompting them to login to their accounts via the fraudulent link.

When victims followed the link, cybercriminals could obtain a range of sensitive information, such as one-time pins, usernames and passwords, security questions and passphrases.

Cybercriminals could then use victims’ personal information to access legitimate enterprises, such as financial institutions, where they could steal funds from victims’ bank accounts.

LabHost originated in Canada in 2021, targeting North America, and expanded to the United Kingdom (UK) and Ireland, before going global. Australian criminals are believed to be among its top three user countries.

At the time of the global police takedown, LabHost had more than 40,000 phishing domains and more than 10,000 global active cybercriminals using its technology to exploit victims.

Cybercriminals could sign up to LabHost for as little as $270 per month. In exchange, cybercriminals were provided with complete ‘phishing kits’, including the infrastructure to host phishing websites, email and text content generation and campaign overview services, enabling them to effectively exploit their victims.

The Australian arm of the investigation, codenamed Operation Nebulae, has allegedly identified more than 100 suspects in Australia who use LabHost to target Australian victims.

Globally, the Europol-coordinated investigation resulted in 70 simultaneous search warrants executed in multiple countries, to take down the platform’s alleged administrators, users and infrastructure. This included the arrest of 37 offenders, including four individuals based in the UK linked to the running of the site, including the original developer of the platform.

Global activity will continue over the coming weeks and further arrests and website domain takedowns are anticipated in Australia and overseas.

A number of devices were seized during the warrants in Australia and will undergo forensic examination.

AFP Acting Assistant Commissioner Cyber Command Chris Goldsmid said phishing had become a serious threat, with Scamwatch last year receiving more than 108,000 reports of phishing attacks, totaling nearly $26 million in losses.

“LabHost alone had the potential to cause $28 million in harm to the Australians through the sale of stolen Australian credentials,” Acting Assistant Commissioner Goldsmid.

“In addition to financial losses, victims of phishing attacks are subject to ongoing security risks and criminal offending, including identity takeovers, extortion and blackmail.

“LabHost is yet another example of the borderless nature of cybercrime and the takedown reinforces the powerful outcomes that can be achieved through a united, global law enforcement front.

“Australians who have used LabHost to steal data should not expect to remain anonymous. Authorities have obtained a vast amount of evidence during this investigation and we are working to identify anyone who has used this platform to target innocent victims.”

Back to top