Synthworks OnlineComparison library

Reference

Reporting a scam or incident in Australia

Four public bodies handle different parts of this, at no cost, and approaching the right one first saves time that matters. This page describes what each actually does and where the boundaries between them fall.

Software is bought before; these services exist after

A security subscription is a preventive measure. Once money has moved, an account has been taken over, or personal information has been exposed, the useful resources are public and free. They are also easy to confuse with one another, because their names overlap and their remits do not.

What follows is a plain description of each body's role, drawn from what each publishes about itself. Nothing here is legal advice, and none of these organisations recovers money as a matter of course — what they do is take reports, publish guidance, and in some cases act on specific categories of harm.

Australian public bodies relevant after a security or scam incident, and what each is responsible for.
BodyRemitApproach it when
Australian Cyber Security Centre The Commonwealth's cyber security agency. Publishes guidance for individuals, families and small businesses, and receives cybercrime and cyber incident reports. A device or account has been compromised, or you need step-by-step guidance on securing something.
Scamwatch Run by the National Anti-Scam Centre at the ACCC. Collects scam reports and publishes current warnings and advice. You have encountered or fallen for a scam — a fake invoice, an investment approach, a remote-access call, a fraudulent store.
eSafety Commissioner Australia's independent regulator for online safety, with formal schemes covering cyberbullying of children, adult cyber abuse and image-based abuse. The harm is about conduct toward a person rather than money — harassment, abuse, or intimate images shared without consent.
Office of the Australian Information Commissioner The national privacy regulator. Oversees the Privacy Act 1988 and the Notifiable Data Breaches scheme, and handles privacy complaints. An organisation has mishandled your personal information, or you are unhappy with how it responded to a breach.
ACCC Administers the Australian Consumer Law and competition law, and houses the National Anti-Scam Centre. The issue is a consumer one — a misleading claim, a refusal to honour a consumer guarantee, a disputed subscription charge.

The first hour

Order matters more than completeness when something has just happened. Reports can be filed afterwards; access cannot always be recovered afterwards.

  1. Stop the transaction if money is moving. Contact your bank or card issuer immediately and tell them what has happened. Banks have processes for disputed and fraudulent transactions, and those processes have time limits.
  2. Take back the account. Change the password on the affected account from a device you trust, then change it anywhere the same password was used. Sign out other sessions if the service offers that control.
  3. Turn on multi-factor authentication for email first. Email is the recovery channel for nearly everything else, which makes it the account with the most leverage.
  4. Remove anything that was installed. If you were talked into installing remote-access software during a phone call, uninstall it and disconnect the device from the network until you have checked it.
  5. Write down the sequence while it is fresh. Times, amounts, addresses, phone numbers, what was said. Every report you file afterwards asks for this.
  6. Then report. Scamwatch for scams, the ACSC for compromise of a device or account, eSafety for abuse or image-based harm.

Recognising the approaches that work

Scam techniques change constantly in their details and very little in their structure. Three structural features show up across nearly all of them, and noticing the structure is more durable than memorising the current examples.

Manufactured urgency
A deadline that leaves no time to verify. An account that will be closed, a payment that must be made now, a refund that expires. Urgency exists to stop you checking, which makes it the single most reliable warning sign.
A change to the channel
An approach that begins on one platform and moves to another — a marketplace listing that moves to a messaging app, a call that asks you to install software, an email that asks you to ring a number. The move is usually a move away from a platform with protections.
An unusual payment method
Gift cards, cryptocurrency, direct bank transfers to a new account, or a request to reroute a payment to changed details. These are chosen because they are difficult to reverse.

The counter-measure is the same in each case, and it does not require software: stop, and verify through a channel you found yourself. Ring the organisation on the number from the organisation's own website or the back of your card, not the number in the message. No legitimate organisation is harmed by you calling them back.

What no web page can tell you

A website cannot detect malware on your device. A page that displays a scan, a progress bar, an alert claiming threats were found, or a warning that your device is infected is running an animation, not an inspection. Those displays are a sales technique and, in some cases, the scam itself — the "support number" they display leads to the people who built the page. Close the tab. If you want to check a device, use software installed on it, not a page it visited.

If personal information has been exposed

Under the Notifiable Data Breaches scheme, organisations covered by the Privacy Act 1988 must notify affected individuals and the OAIC when a breach is likely to result in serious harm. If you receive such a notification, it should describe what was exposed and what to do — and what to do usually depends on the type of information rather than the size of the breach.

Passwords call for immediate changes, starting with any account where the password was reused. Identity documents are more serious and more procedural: the organisation notifying you should explain the replacement route for the specific document. Contact details alone mean expecting a rise in targeted approaches that reference real information about you, which is precisely why the verification habit above matters. If an organisation's response to a breach is inadequate, the complaint route runs through the organisation first and the OAIC second.

Reporting for someone else

A good share of these incidents are discovered by a family member rather than by the person affected, and that changes the practical sequence. The account holder generally has to make the call to their own bank, so the useful contribution is usually preparation rather than substitution: assemble the record of what happened, sit with them while they ring, and write down who they spoke to and when.

Scam reports to Scamwatch can be made about an incident that happened to someone else, which is worth knowing when the person affected is not in a state to do it. Where an older relative has been targeted repeatedly, the pattern itself is worth reporting, because the warnings published from those reports are what other households read before the same approach reaches them.

Where this fits in the library

None of the above requires a purchase, and putting it on a site funded by paid links is deliberate: the free measures are the ones that do most of the work, and a library that omitted them in favour of a product page would not be worth reading. What software can and cannot contribute is set out in what each type of protection does, and the vocabulary used across these pages is defined in security terms.