CFOtech Australia - Technology news for CFOs & financial decision-makers
Australia
Proofpoint warns of myGov & invoice scams in Australia

Proofpoint warns of myGov & invoice scams in Australia

Mon, 17th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Proofpoint has warned Australians about two scam formats currently targeting taxpayers and finance teams, linking the alert to rising scam losses across the country.

One tactic uses phishing emails that impersonate myGov and direct users to a fake login page designed to capture credentials. The other involves false invoices sent in the name of known suppliers or vendors, with a claimed discount used to pressure staff into paying quickly.

Australians lost AUD $2.18 billion to scams in 2025, according to the ACCC's National Anti-Scam Centre. That was 8% more than the previous year and highlights concern about the growing realism of online fraud.

The myGov impersonation scam is timed to coincide with tax season, when people may expect official messages about returns or refunds. The fake sign-in page can be used to gain access to tax records, refund details and personal identification information.

By contrast, the invoice scam targets organisations rather than individual taxpayers. A scammer poses as a supplier and sends a fake invoice with a discount offer intended to encourage finance staff to pay without carrying out normal checks.

The common thread is impersonation of a trusted brand or contact combined with urgency. Both approaches are designed to push victims into acting before they verify whether a message or request is genuine.

AI-driven fraud

The warning comes as businesses and consumers face more convincing scam attempts built with artificial intelligence tools. These can remove many of the signs that once helped people identify fraudulent emails or messages, such as poor grammar, awkward wording or obvious inconsistencies.

For companies, that shift has sharpened attention on business email compromise, where attackers use email impersonation to divert payments or obtain sensitive information. Finance teams can be especially exposed when handling large volumes of invoices or trying to reduce costs, as those conditions can make an unusual payment request appear routine.

Adrian Covich, Vice President, Systems Engineering, APJ at Proofpoint, said the rise of artificial intelligence in cybercrime had changed both how scams are carried out and how difficult they are to detect.

"The integration of artificial intelligence into cybercrime has fundamentally shifted the threat landscape, turning what were once easily identifiable scams into highly sophisticated attacks that cost the Australian economy billions. According to the ACCC's National Anti-Scam Centre, Australians lost $2.18 billion to scams in 2025. For Australian businesses, this evolution is most acutely felt through the rise of business email compromise (BEC). By preying on finance teams hunting for savings amidst a high volume of administrative work, attackers create a false sense of urgency that tricks employees into bypassing verification protocols and authorising payments directly into criminal accounts. However, despite this, Australian businesses must recognise that scams are fundamentally a people problem, exploiting human behaviour and trust at scale. A human-centric approach to security requires combining continuous, context-driven employee education with behaviour-based controls and robust threat intelligence to detect malicious intent and block fraudulent requests before a transaction can occur," Covich said.

Seasonal pressure

The tax-related example reflects how scammers often tailor their approach to moments when certain communications are expected. During tax season, people may be more inclined to open a message that appears to come from a government service and less likely to pause if they believe a refund or important update is waiting.

At the same time, end-of-financial-year administration can create similar pressure inside companies. Large invoice backlogs, payment deadlines and cost scrutiny can make a discount offer look plausible, particularly if the request appears to come from an established supplier relationship.

Cyber security groups have increasingly argued that technical defences alone are not enough to address such threats because the final step in many scams still depends on human action. That can include clicking a link, entering credentials, changing bank details or approving a transfer.

These examples show how fraud attempts are becoming harder to distinguish from legitimate communications. The trend points to a wider problem for Australian organisations and households as attackers refine old scam models with more persuasive language, better timing and more credible impersonation.