Fake ATO texts, emails and phone calls are hitting Perth inboxes harder than ever right now, and business owners are squarely in the crosshairs. In June 2026, the ATO received 1,547 reports of ATO impersonation scams, which is a 12% increase from May, with no reports of payments made to scammers. Scamwatch has issued a fresh nationwide alert warning that criminals are cloning ATO and myGov branding to steal login details and money. If you run a small business in Perth, here's what's actually happening and the five things to check this week.
Why business owners are a bigger target than individuals
Tax deadlines concentrate urgency, complexity, and last-minute activity, a perfect environment for opportunistic attackers, and for Australian small businesses, limited IT staffing, fewer process controls, and frequently outsourced accounting create an attractive, high-return target. Unlike an individual waiting on a personal tax refund, a business owner is juggling BAS lodgements, payroll finalisation, supplier payments and a bookkeeper or accountant who emails them constantly — which gives scammers dozens of believable angles to work with.
The scam messages aren't just fake ATO texts anymore. Phishing campaigns at End-of-Financial-Year commonly impersonate the Australian Taxation Office, accountants, payroll providers, or cloud accounting services such as Xero and MYOB. The attackers don't stop at July, either. Because Perth businesses often lodge quarterly BAS, review payroll obligations, or finalise reports right through the second half of the year, this style of attack keeps working well past the EOFY rush.
What the current scam actually looks like
Scamwatch and the ATO describe a familiar but increasingly convincing pattern. Criminals design these communications to look real, using official logos, branding, and language to deceive people, and may then use stolen personal information — including myGov sign-in details — to commit fraud in someone's name. In practice, that means:
- Fake "final notice" or "ATO audit" emails and SMS designed to create panic and urgency
- Cloned myGov or ATO login pages that harvest usernames, passwords and one-time codes the moment you type them in
- Phone calls (vishing) where a caller claims to be from the ATO and asks you to "verify" your TFN or bank details
- Business Email Compromise (BEC) — a message that looks like it's from your accountant, bookkeeper or a supplier, asking you to urgently update bank details or pay an invoice
That last one is the most expensive for businesses. Because EOFY generates many legitimate changes and large-value transactions, invoice diversion and payment-redirection fraud are particularly effective, with attackers altering supplier bank details or submitting fake invoices at the point when finance teams are most rushed.
The red flags the ATO wants you watching for
The official guidance is worth pinning above your bookkeeper's desk. Genuine warning signs include an unsolicited message with a link that claims to be from the ATO — the ATO will never do this — where the email or text includes a link asking you to sign into your myGov account, and where the sender's details do not match the legitimate agency and do not end in '.gov.au'. If any of those apply to a message your business receives, treat it as fake until proven otherwise.
The ATO's advice is to stop and not rush into clicking links in unexpected messages or sharing passwords, one-time codes or financial information, then check by contacting the ATO using the official app or website or calling 1800 008 540 to verify if the contact is real. If you've already shared money or personal information, protect your accounts and report it straight away.
Five things to do this week
- Brief your finance and admin staff. Anyone who touches invoices, payroll or BAS should know that a change to bank details or an urgent payment request needs a phone call to a known number — not a reply to the email — before it's actioned.
- Turn on multi-factor authentication everywhere it's offered — myGov, your accounting software, and your business email. A stolen password is far less useful to a scammer if they also need a one-time code from your phone.
- Check sender addresses, not just display names. Cloned ATO and accountant emails often look perfect until you check the actual sending domain.
- Don't click links in unexpected tax-related messages. Go directly to ato.gov.au or myGov by typing the address yourself, or use the ATO app.
- Have a second set of eyes on bank detail changes. A simple rule — no supplier or payroll bank account changes without a verbal confirmation — stops most invoice fraud dead.
If your team isn't sure what a genuine phishing attempt looks like versus a real ATO or accountant email, it's worth a short read of our guide on how to identify phishing emails and how to check if a link in an email is secure before the next BAS deadline lands.
If you think your business has already been caught out
Act fast. Contact your bank immediately if money has been sent, change any passwords that may have been compromised, and report the scam to the ATO and Scamwatch so others can be warned. If a staff member's email or myGov account may have been accessed, assume any linked accounts (banking, super, payroll software) could be at risk too and lock them down.
For accounting, bookkeeping and professional services firms in particular, this is also a good moment to review who in the business can actually change supplier bank details, and whether your email platform is filtering out spoofed sender addresses before they reach a mailbox at all. Our email protection service is built specifically to catch this kind of lookalike and BEC attempt before it lands in an inbox.
The takeaway for Perth business owners
ATO and myGov impersonation scams aren't a once-a-year EOFY problem anymore — they're a steady, rising background threat that specifically exploits the busy, deadline-driven nature of running a small business. A quick team briefing, MFA on your key accounts, and an "always verify by phone" rule for bank detail changes will block the vast majority of what's currently doing the rounds.
If you'd like a second opinion on whether your business email and accounting systems are set up to catch these scams before they reach staff, Computer Mechanics has been supporting Perth businesses with practical, no-nonsense IT and security advice since 1997. We work closely with Perth accounting and bookkeeping firms on exactly this kind of risk — get in touch if you'd like us to take a look at your setup.


