Impersonation scams in Australia: How to stay secure

Impersonation scams can sometimes involve several scammers playing different roles. Know how to identify these scams and take action to protect yourself.   

Summary

Impersonation scams are becoming increasingly sophisticated, as one customer, Michael, discovered when he was asked to transfer funds as part of a fake ‘sting’ operation. Learn how to spot them and take steps to protect yourself now as part of Cyber Security Action Month.

A real-life impersonation scam in action

The approach: Earlier this year, a CFS customer – who we'll call Michael to protect the customer's privacy – received a call from a someone claiming to represent a major technology brand, who told him an unauthorised transaction of $350 had been processed against the customer's account1. Michael was transferred to a ‘supervisor’ and then to an individual claiming to be a government official.

 

The hook: These scammers convinced Michael he was assisting authorities with a confidential investigation. They instructed Michael to withdraw and transfer funds as part of a government ‘sting’ operation designed to identify and apprehend offenders.

 

The urgency: The scammers used intimidation including threats of police action to manipulate Michael into complying with their instructions.

 

The ask: Acting on their instructions, Michael called the CFS contact centre and requested a withdrawal of $170,000 from his super account, advising that the funds were required to help his son purchase a property. The withdrawal was processed and paid to the customer's existing nominated bank account.

 

Michael then attempted to move funds through multiple channels, including a Western Union transfer, deposits into a Bitcoin ATM and the purchase of gift cards.

 

The exit: Michael’s suspicions were only raised when Western Union questioned the transfer he was attempting to make. His financial adviser later contacted CFS with concerns that Michael had been the victim of a scam.

 

The outcome: Through recovery efforts, $140,000 of the withdrawn funds were successfully recovered and returned to the customer’s super account.

 

These events resulted in a net loss of $30,000 from Michael’s super. They also caused Michael considerable emotional trauma.

What makes impersonation scams so convincing in 2026

Unfortunately, Michael is not alone in being taken in by a convincing scammer. Impersonation scams are fairly common in Australia in 2026, and scammers are often very good at telling their cover story.

 

They may pose as trusted organisations – such as government agencies, banks, technology companies and more – in order to steal your personal information or gain access to your accounts to steal your money.

 

In the first six months of this year, 5,262 reports of bank impersonation scams alone were made to Scamwatch, with associated losses totalling more than $3.2 million2.

 

The techniques scammers use to appear legitimate are becoming increasingly sophisticated, and may include:

  • AI-generated voice cloning that can sound like a family member,
  • cloned websites that copy the layout and branding of legitimate institutions, and
  • fake entries that may appear at the top of sponsored search results online.

A call from a scammer may feel real because the scammer already knows something about you.

 

Details harvested from past data breaches including names, dates of birth, employer details and even partial account numbers, help scammers to provide information you wouldn’t expect them to know.

 

Knowing what to look for can help you spot a scam before it causes harm.

Current impersonation scams targeting Australians

Impersonation scams in Australia include some recognisable categories. Common Australian examples include:

  • scam calls from companies reporting fake unauthorised payments,
  • ATO scam calls demanding immediate tax payments,
  • myGov SMS phishing scams with fake login links,
  • bank 'fraud alert' impersonation scams urging you to transfer funds to a 'safe account'.

They may use different channels to approach you, and different cover stories, but the underlying goal is the same: to pressure you into handing over or transferring money, revealing personal information, or providing access to your account before you have time to verify who you are really speaking with.

Unsolicited contact from a company or organisation, followed by pressure to act urgently, is a red flag for a scam.

Below are some common varieties of impersonation scams active in Australia in 2026, the channels they often use, claims they may make, and some of the signs to watch for. 

Scam Type
Typical contact method
Claims may include
Telltale signs to watch for
Scam Type

ATO or Services Australia impersonation

Typical contact method

Phone call, SMS, email

Claims may include

You owe a tax debt or face arrest

Telltale signs to watch for

The ATO never demands immediate payment, particularly via gift card or cryptocurrency

Scam Type

Retailer or service provider impersonation

Typical contact method

Phone call, email, SMS

Claims may include

An unauthorised transaction has been made on your account, act now to recover it

Telltale signs to watch for

Retailers and tech companies will not contact you demanding immediate action over an unauthorised transaction

Scam Type

Bank impersonation

Typical contact method

Phone call with spoofed number, email, SMS

Claims may include

Your account has been compromised

Telltale signs to watch for

Banks do not ask for your full PIN, password or a one-time password over the phone and generally advise you never to share these with anyone 

Scam Type

Super fund impersonation

Typical contact method

Phone call, email

Claims may include

Your super balance is at risk, act now

Telltale signs to watch for

Legitimate organisations should never pressure you to act immediately to transfer funds

Scam Type

Technology company impersonation

Typical contact method

Pop-up alert, phone call

Claims may include

Your device is infected

Telltale signs to watch for

Microsoft and Apple do not make unsolicited support calls

Scam Type

Investment platform impersonation

Typical contact method

Email, cloned website link

Claims may include

Exclusive investment opportunity

Telltale signs to watch for

Investment opportunities that sound too good to be true and pressure to move your investments. Check a company is licensed by ASIC and search for known scammers via MoneySmart’s Investor alert list before engaging

Visit ScamWatch for all scam alerts

Check out scam tips, news and alerts through the Australian Government’s Scamwatch website. 

You can also subscribe to Scamwatch email alerts to keep up to date with the latest scams. 

Warning signs to watch for right now

The cover stories may change, but some common tactics emerge repeatedly in impersonation scams reported in Australia:

  • Urgency such as such threats of arrest, account closure, or loss of benefits unless you act within minutes.
  • Requests for remote device access through screen-sharing software you did not install yourself.
  • Unsolicited contact asking for personal or account details.
  • Requests for one-time passwords or multi-factor authentication codes, which no legitimate organisation will ever ask you to read out.
  • Links sent via SMS or email that lead to a login page or request a one-time code.
  • Requests to move money or super to a 'safe account', which is never a genuine process.
  • Caller ID that appears genuine but the caller cannot verify account details you did not share.

If you notice any of these, pause the conversation. A legitimate caller will not object to you ending the call and ringing back on an official number.

Take a second. Stay secure. Take four steps to protect yourself

October 2026 is Cyber Security Action Month in Australia, previously known as Cyber Security Awareness Month. This year's theme is 'Take a second. Stay secure' – with the goal of encouraging you to take four steps now to help protect yourself not only this month, but year-round.

 

Each step is simple, takes only a few minutes and can help reduce your risk of becoming a scam victim.

1. Install software updates to keep your devices secure

Software updates patch the security vulnerabilities that scammers exploit. Devices running outdated operating systems, browsers, or apps are far more exposed to malware, phishing kits, and account-takeover tools. Set your phone, tablet, and computer to install updates automatically where possible, and restart devices promptly when an update is pending. The same principle applies to the apps you use for banking, super, and email, where delayed updates can leave known weaknesses open for weeks.

2. Use a unique and strong passphrase on every account

A passphrase is a sequence of four or more random words strung together, such as 'blue kettle morning river'. It is longer, more memorable, and far harder to crack than a short password with symbols. Reusing passwords is one of the most common reasons accounts are compromised: if one site is breached, scammers try the same credentials on your email, bank, and super portal through automated credential stuffing. A reputable password manager helps you generate and store a unique passphrase for every account, including your FirstNet login.

3. Always set up multi-factor authentication

Multi-factor authentication, often shortened to MFA, requires a second piece of evidence in addition to your password, such as a code from an authenticator app or a prompt on your phone. Even if a scammer obtains your password, MFA adds a barrier that is harder to breach. It’s worth enabling MFA on every financial account you hold. Where you have the choice, an authenticator app is more secure than SMS-based codes, because SMS can be intercepted through SIM-swap attacks.

4. Report scams

Reporting matters. It helps authorities detect patterns, warn the public, and disrupt scam infrastructure before more people are affected. Report scams to Scamwatch and to the Australian Signals Directorate's ReportCyber service.

 

If you suspect your CFS account may have been affected, contact us directly rather than clicking on any link in an unsolicited message. 

How CFS protects your account

CFS applies multi-factor authentication on the FirstNet member portal, uses secure communications for sensitive transactions, and provides members with technical security help on FirstNet to support safe account use.

 

Keeping your contact details current is an important part of this, because genuine alerts, verification messages, and account notifications rely on the mobile number and email address you have registered. Confirm your details

 

You can also review how we handle personal information in our privacy policy, and complete identity verification securely when joining CFS to help protect your account from the outset.

Help to stay safe online

Our Staying safe online hub is updated regularly with tips on how to keep your accounts safe and some of the warning signs to watch out for when it comes to scams.

Frequently asked questions

An impersonation scam is when a scammer pretends to be a trusted organisation or person, such as the ATO, your bank, a super fund, or a technology company, to trick you into handing over personal details, account access, or money. They use phone calls, SMS, email, and cloned websites to appear genuine.

A genuine super fund will never call you out of the blue and ask you to transfer or roll over your balance urgently. If you receive an unsolicited call claiming to be from your fund, hang up and call the fund back using the number on their official website or app, not the number the caller gave you.

Stop contact with the scammer immediately and do not send any further money or information. Report the scam to Scamwatch at scamwatch.gov.au and to the Australian Signals Directorate via ReportCyber. If you believe your CFS account may be affected, contact us directly.

Yes. Multi-factor authentication adds a second layer of protection so that even if a scammer obtains your password, they cannot access your account without the second verification step. Enabling MFA on your CFS FirstNet account and other financial accounts can significantly improve account security and reduce the risk of unauthorised access, although it does not eliminate all scam and cyber security risks.

A passphrase is a sequence of four or more random words that is longer and harder to crack than a typical short password. Because its length makes it more resistant to automated guessing attacks, a unique passphrase on every account is one of the most effective steps you can take to protect your financial information.

Related articles

¹ Names and financial details have been changed to protect the customer's privacy.

 

²  The devastating impact behind bank impersonation scams, ASIC media release, 24 August 2026. 

Disclaimer

Avanteos Investments Limited ABN 20 096 259 979, AFSL 245531 (AIL) is the trustee of the Colonial First State FirstChoice Superannuation Trust ABN 26 458 298 557 and issuer of FirstChoice range of super and pension products. Colonial First State Investments Limited ABN 98 002 348 352, AFSL 232468 (CFSIL) is the responsible entity and issuer of products made available under FirstChoice Investments and FirstChoice Wholesale Investments.

 

Information on this webpage is provided by AIL and CFSIL. It may include general advice but does not consider your individual objectives, financial situation, needs or tax circumstances. You can find the target market determinations (TMD) for our financial products at https://www.cfs.com.au/tmd which include a description of who a financial product might suit. You should read the relevant Product Disclosure Statement (PDS) and Financial Services Guide (FSG) carefully, assess whether the information is appropriate for you, and consider talking to a financial adviser before making an investment decision. You can get the PDS and FSG at www.cfs.com.au or by calling us on 13 13 36.