![]()
Welcome to this month’s edition of Cyber Insights.
In this issue, we revisit the ATO scam doing the rounds this tax time, plus a look at recent data breaches and staying safe on public Wi-Fi while you travel.
![]()
In this scam, you receive an email, text message or phone call that appears to come from the Australian Taxation Office (ATO) or myGov. With tax time in full swing, scammers are ramping up fake messages. These messages might warn you of an overdue payment, offer a tax refund waiting to be claimed, or claim there is an urgent need to “verify your identity”. Some of these fake emails even include screenshots of the myGovID app to make them look genuine.
The message pressures you to act quickly, which is exactly the point. If you click the link, you are taken to a convincing fake myGov login page that asks for your personal information and banking details. Two of the biggest warning signs are a link that asks you to sign in to your myGov account, and sender details that don’t quite match a real government agency. Genuine government email addresses always end in .gov.au, and the ATO has confirmed it will never send an email or text message with a link to a login page.
This scam is dangerous because your myGov and ATO login details unlock several linked government services at once, including Medicare, Centrelink and your tax records. Once scammers have this access, they can steal your identity, redirect your tax refund, or use your details for further fraud.
Follow these tips to avoid falling victim to this scam:
- Don’t rush. Never click links in unexpected tax or myGov messages, and never share passwords, one-time codes or banking details by email or text.
- Check any message by contacting the ATO directly on 1800 008 540, or by logging in through the official app or ato.gov.au, not through a link in the message.
- If you have already shared your information, contact the ATO immediately on 1800 008 540.
![]()
ALS Global
ALS Global is a testing, inspection and laboratory services provider listed on the Australian Securities Exchange (ASX). The company disclosed a cyber incident to the ASX on 11 June 2026, after identifying the attack in May. ALS Global described it as “temporary disruption to parts of the group’s operations.” The Aur0ra group, a gang that uses ransomware (software that locks your files until you pay to get them back) and was first observed in April 2026, claimed responsibility. It published allegedly stolen data on its dark web leak site (a hidden part of the internet often used by criminals to sell stolen data) on 19 June 2026.
The leaked data reportedly includes administrator passwords, a password manager emergency kit, banking details, salary documents and certificate files, along with the home directories of up to 500 employees. These directories are said to contain cached login details, personal information, passport scans, bank account details, payroll information and workplace injury records. Client laboratory results and internal research may also have been affected. ALS Global has engaged cybersecurity experts, strengthened its controls, increased monitoring, and notified the Australian Cyber Security Centre and regulators. Read more here
Melbourne International Film Festival (via Ferve Ticketing)
Attackers gained unauthorised access to the Melbourne International Film Festival’s (MIFF) third-party ticketing platform, run by Ferve (Vallez Pty Ltd). Initial access was identified on 29 May 2026, with further access identified the following day. Some customers then received unusual, unauthorised emails and text messages sent through the hacked system. This prompted MIFF to confirm the impact publicly on 1 June and take the ticketing system offline while it secured the platform.
MIFF confirmed that 26,782 customer records were affected, including names, email addresses, phone numbers and customer ID numbers. The attacker behind the breach also claimed that residential addresses had been taken, though MIFF has not confirmed this as part of the impacted data. No payment card details or account passwords were exposed. MIFF mobilised an incident response team and notified the Australian Cyber Security Centre. Read more here
![]()
Heading off for the winter school holidays or a work trip? Before you connect to the free Wi-Fi at the airport lounge, your hotel or the local cafe, it pays to stop and think. Public Wi-Fi networks are convenient, but they are often unsecured. This means anyone else on the same network, including a scammer sitting a few tables away, may be able to see what you are doing online. Cybercriminals also set up fake networks with names like “Free Airport Wi-Fi” to trick travellers into connecting. This gives them a direct line to your login details, emails and banking apps. You don’t need to avoid public Wi-Fi altogether. You just need a few simple habits to stay safe while you’re away from your usual home or office network.
Staying Safe on Public Wi-Fi While You Travel
Follow the tips below to protect your information while travelling:
- Confirm the exact network name with staff before connecting. Scammers often set up lookalike networks such as “Hotel_Guest_WiFi”, hoping you’ll connect to theirs instead.
- Avoid logging into your bank, checking your email or entering passwords while on public Wi-Fi. Use your phone’s mobile data for anything sensitive, or wait until you’re back on a trusted network.
- Turn off automatic Wi-Fi and Bluetooth connection on your phone and laptop before you travel, so your device doesn’t join unknown networks without you knowing.
- Turn on two-factor authentication (an extra security code sent to your phone or app) for your email, banking and cloud storage accounts. This means a stolen password alone isn’t enough to get in.
- Log out of accounts and forget the Wi-Fi network on your device once you’ve finished, rather than staying connected in the background.
If you would like to discuss your cybersecurity needs, book a complimentary consultation here
Frequently Asked Questions
Genuine government agencies only use email addresses ending in .gov.au, and the ATO has confirmed it will never send an email or text with a link to a login page. If a message pressures you to act urgently, asks you to "verify your identity," or includes a login link, treat it as a scam. Always check your ATO or myGov account by typing the address directly into your browser or using the official app, not by clicking a link in a message.
Contact the ATO immediately on 1800 008 540 if you've entered your details on a suspicious page or shared a password, one-time code, or banking information. Acting quickly gives you the best chance of limiting the damage, since myGov and ATO logins can unlock several linked services at once, including Medicare and Centrelink.
No. Not every breach involves a sophisticated attack. This month's confirmed cases show that simple administrative errors, such as accidentally exposed login credentials, can expose just as much sensitive information as a targeted cyberattack. It's a reminder that basic access controls and configuration checks matter just as much as defending against outside threats.
Public Wi-Fi is convenient but often unsecured, meaning others on the same network could potentially see your activity. Scammers also set up fake networks with genuine-sounding names to trick people into connecting. It's safest to confirm the exact network name with staff, avoid logging into banking or email while connected, and use mobile data for anything sensitive instead.
Turn on two-factor authentication (2FA) for your email, banking and cloud storage accounts before you go. This means that even if a password is stolen over public Wi-Fi or through a scam, it isn't enough on its own for someone to get in.