Add Think Technology as a trusted source EOFY Cyber Attacks Targeting Australian Businesses | TTA

EOFY cyber attacks are rising – here is what Australian businesses need to watch for

Tax Time EOFY

Every year around tax time, cyber criminals step up their activity against Australian businesses. The end of financial year (EOFY) creates the perfect conditions: high transaction volumes, time pressure, and staff exchanging financial documents with accountants, suppliers, and banks. That combination makes it easier for a fake invoice or fraudulent payment request to slip through unnoticed. If your business handles accounts payable, payroll, or client funds, this is the period to be most alert.

The scale of the problem is significant. The Australian Taxation Office (ATO) received 1,386 reports of ATO impersonation scams in May 2026 alone, an 11% increase from April. Scammers stole more than $152.6 million from Australian businesses through business email compromise (BEC) in 2024, up 66% on the previous year. These are not abstract risks, they are hitting Queensland businesses of all sizes.

How EOFY attacks have changed

The fake ATO email with poor spelling is still out there, but it is no longer the main threat. Attacks in 2026 are built to blend into normal business workflows. Criminals now send requests to update supplier bank details, share documents through familiar platforms, or pose as payroll staff asking finance teams to process urgent changes. AI-written phishing emails mean the old grammar and spelling tells are gone. A fraudulent message can look indistinguishable from a genuine one.

Common EOFY attack types to watch for include:

  • Phishing emails impersonating the ATO, myGov, accountants, Xero, or MYOB with urgent language such as “lodgement failed” or “final notice”.
  • Business email compromise (BEC) where criminals spoof an executive or supplier to redirect a payment or change bank account details.
  • Fake invoices submitted when finance teams are most rushed and least likely to stop and verify.
  • SMS and phone scams (smishing and vishing) impersonating banks or the ATO and asking for tax file numbers or immediate authorisation.
  • Ransomware timed to coincide with EOFY, when businesses are most likely to pay quickly to recover critical financial records.

Who is most at risk

Accountants, lawyers, and health professionals face a higher-than-average risk at EOFY because of the volume of client transactions and the sensitivity of the data they hold. Small and medium businesses are also disproportionately targeted because they often have fewer process controls and smaller IT teams. Criminals know that a sole trader or a 20-person firm is less likely to have a formal payment verification process than a large enterprise.

Finance and payroll staff carry particular exposure. They are the people most likely to receive a supplier invoice, a bank detail change request, or an urgent funds transfer instruction. Under deadline pressure, even careful staff can make mistakes. Training your team to pause and verify, especially on any request involving money or bank details, is one of the most effective controls you can put in place.

Practical steps to reduce your exposure

You do not need a large IT budget to reduce EOFY cyber risk meaningfully. The most effective protections are process-based, not just technical.

  • Verify payment changes by phone. Any request to update supplier bank details should be confirmed by calling the supplier directly on a number you already have, not one in the email.
  • Set a two-person approval rule. Require a second sign-off on any payment above a set threshold. This one control stops a large proportion of BEC fraud.
  • Turn on multi-factor authentication (MFA). The Australian Cyber Security Centre (ACSC) lists MFA as a core control in the Essential Eight framework. Even if credentials are stolen through phishing, MFA stops an attacker from accessing the account.
  • Brief your accounts team now. A five-minute conversation at the start of the EOFY period about what to watch for is more effective than a security policy document nobody reads.
  • Check your email security settings. DMARC, DKIM, and SPF records help stop spoofed emails from reaching staff inboxes in the first place.

Email security is the front line

Email-based attacks remain the primary way criminals reach Australian businesses. Phishing and spoofing emails are designed to look like something you would normally expect to receive, a supplier invoice, a parcel delivery notice, or a message from your accountant. The link or attachment in the email does the damage.

A dedicated email security solution scans traffic at the gateway before it reaches your inbox. That means malicious links, credential-harvesting attachments, and spoofed sender addresses get caught before staff see them. For businesses on Microsoft 365Microsoft Defender for Office 365 adds a strong additional layer of protection inside the platform itself.

Cyber security is no longer purely an IT concern. Every employee who handles email, invoices, or client data plays a role in keeping your business safe. The goal is to build a team that knows what to look for and feels comfortable raising concerns without hesitation. For more on building that culture, our article on security training that sticks covers the practical approach we use with Queensland clients.

Report it if something goes wrong

If your business receives a suspicious email or believes it has been targeted, report it to the ACSC via ReportCyber. If a payment has already been made, contact your bank immediately, the sooner you act, the better the chance of recovery.

Frequently asked questions

Why do cyber attacks increase at EOFY?

EOFY concentrates financial activity into a short window. Businesses are processing invoices, closing accounts, running payroll and lodging tax returns all at once. Staff are busy and under time pressure. Criminals exploit that pressure because rushed employees are more likely to approve a payment or open an attachment without stopping to verify it first.

What is business email compromise (BEC)?

BEC is a type of fraud where a criminal impersonates a trusted contact, usually a supplier, executive, or accountant, to trick someone in your business into transferring money or changing bank account details. No malware is involved. The attack relies entirely on deception through email. In 2024, Australian businesses lost more than $152.6 million to BEC attacks.

How do I know if an email is a phishing attempt?

Modern phishing emails can be very convincing. Look for mismatched sender email addresses, unexpected urgency, requests for payment or bank detail changes, and links that go to unfamiliar domains. If anything feels off about a financial request, call the sender on a number you already have and confirm verbally before taking action.

Does MFA actually stop EOFY attacks?

MFA is one of the most effective single controls against account takeover. Even if a criminal steals a password through a phishing email, MFA prevents them from accessing the account without the second factor. The ACSC includes MFA in its Essential Eight baseline for a reason. Every business email account should have MFA turned on.

Where do I report an EOFY scam or cyber attack?

Report cyber incidents and suspicious emails to the ACSC via ReportCyber at cyber.gov.au. If you suspect ATO impersonation, report it directly to the ATO. If money has been transferred fraudulently, contact your bank immediately and then report to police. Acting fast significantly improves the chances of recovering funds.

Where to from here?

If you are not confident your email security, MFA settings, or staff awareness are where they need to be ahead of EOFY, we can help. TTA works with businesses across Brisbane and South-East Queensland to put practical protections in place, without overcomplicating it. Get in touch and we can walk through where your biggest exposures are.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.