Keep an eye out for business scams this EOFY

Tax time is the busiest period for scammers targeting Australian businesses. The attacks arrive by email, SMS, phone, and social mediaand they are more convincing than ever. The Australian Taxation Office (ATO) received nearly 7,500 impersonation scam reports in July 2025 alone, and scam activity keeps rising through the June-to-August window every year. In May 2026, the ATO recorded 1,386 impersonation reports, up 11% from April.
The pattern is familiar to us at TTA. Every EOFY, businesses that are rushing to lodge BAS statements, finalise payroll, and reconcile with suppliers become easier targets. The urgency of tax time is exactly what scammers count on. This article covers the four most common scam types, how to spot them, and what to do if one gets through.
Email phishing scams
Phishing emails used to be easy to spot: bad grammar, obvious logo errors, and generic greetings. That has changed. AI tools now let scammers generate polished, personalised messages at scale. Campaigns at EOFY commonly impersonate the ATO, myGov, payroll providers, and accounting platforms like Xero and MYOB. A recent ATO scam posed as a DocuSign notification, claiming to hold a tax refund until the recipient signed a document, then routing them to a fake myGov login page.
Watch for these signs in any unexpected email claiming to be from the ATO or a government body:
- The sender domain is not @ato.gov.au. Scammers use domains like @ato.com.au or slight variations to look official.
- The email is not addressed to you by name, or it uses a generic greeting like “Dear Taxpayer”.
- It creates urgency: words like “final notice”, “ATO audit”, or “lodgement failed” push you to act before you think.
- It asks you to click a link to log in, sign a document, or confirm personal details.
- It contains an attachment you were not expecting.
If you receive a suspicious email claiming to be from the ATO, do not click any links, open attachments, or download files. Forward the full email to [email protected] and delete all copies from your inbox. The ATO will never send an unsolicited message asking you to return personal information by email or SMS. Any genuine ATO correspondence will be in your myGov inbox, which you can check by logging in directly at my.gov.au.
Invoice and payment redirection scams
Business Email Compromise (BEC) and payment redirection fraud are the most financially damaging scam type for Australian businesses. According to the ACCC, payment redirection scams cost Australian businesses $152.6 million in 2024, and were the most reported scam type among small and micro businesses. The Australian Signals Directorate puts the average cost of a successful cyberattack at $56,600 for a small business and $97,200 for a medium business, factoring in direct loss, disruption, and recovery.
The approach is straightforward. A scammer intercepts an email thread between your business and a supplier, or spoofs a supplier’s email address. They send a realistic-looking invoice with updated bank account details. Your finance team pays it, thinking the change is routine. The money goes to a criminal-controlled account. The scam often surfaces weeks later, when the real supplier asks why their invoice hasn’t been paid.
Modern BEC emails are hard to tell apart from genuine ones. They mimic the tone, formatting, and even internal references from real email threads. To protect your business:
- Treat any change to supplier bank details as suspicious until independently verified.
- Call the supplier on a number you already have on file, not a number listed in the email, to confirm the change.
- For high-value invoices, require written confirmation through your regular supplier portal before processing payment.
- Check the sender’s email address carefully. Scammers often add a single letter or swap a character to mimic the real address.
- Set a payment approval threshold. Any new account or changed account above that threshold needs a second person’s sign-off before transfer.
Tax refund and debt scams
These scams contact businesses by email, SMS, or phone and claim you either owe the ATO money or are owed a refund. Both versions aim to extract your banking details, Tax File Number (TFN), ABN, or credit card information. The ATO is clear: it will never ask for banking details by email or SMS, request a fee to release a refund, or ask you to pay a tax debt using gift cards, cryptocurrency, or unusual transfer methods.
Common variations include:
- A message claiming you have overpaid tax and are owed a refund, but you must pay an administration or transfer fee first to receive it.
- A message claiming you have underpaid tax and must repay immediately, with a link to enter your card or banking details.
- An SMS claiming you are under investigation for cryptocurrency tax evasion and must call a number to resolve it.
If you get an unexpected message about a tax debt or refund, log into your ATO online services directly through myGov to check your actual account status. Do not use any link or number supplied in the message.
Robocalls and phone spoofing
Scammers send pre-recorded calls (robocalls) that claim to be from the ATO and threaten immediate arrest for an unpaid tax debt. They use spoofing technology to make your phone display a genuine ATO number, even though the call originates overseas. The tactic is designed to keep you on the line and push you to pay before you have time to verify.
The ATO updated its guidance in 2026: genuine ATO calls now display as “No Caller ID”. If a call shows a specific ATO number on your screen, that is a spoofed call. In April 2026, the ATO also launched a “Verify Call” feature in the free ATO app, which lets you confirm in real time whether a caller is genuinely from the ATO. If a call claims to be from the ATO, open the app, tap “Verify Call”, and wait for the confirmation before continuing the conversation. No confirmation means you should hang up.
The ATO will never:
- Send a pre-recorded robocall demanding payment of a tax debt.
- Threaten you with immediate arrest over the phone.
- Request payment by iTunes gift cards, Google Play cards, cryptocurrency, or other unusual methods.
- Ask for money to release a refund or other payment.
- Refuse to let you speak with a registered tax agent or trusted advisor before acting.
What we see at TTA: scams are getting harder to catch
Working with Brisbane and South-East Queensland businesses across professional services, construction, and healthcare, we see a consistent pattern at EOFY. Finance teams are under time pressure. Approval shortcuts get taken. Emails that would normally prompt a quick phone call get acted on without verification because “it’s a busy period”.
The scams we see land most often are not the crude ones. They are carefully timed BEC attacks that arrive during a genuine invoice cycle, or phishing emails that reference a business’s actual accounting platform. One thing that makes a real difference is a simple rule: any payment instruction that arrives by email, or any request to change bank details, requires a separate voice verification call before action is taken. No exceptions, even when the sender looks completely legitimate. This one control alone would stop the majority of BEC losses.
For broader cyber security support, our IT security assessments help Brisbane businesses find the gaps before scammers do. And if your business holds cyber insurance, make sure your cyber insurance compliance requirements are current, as most policies now require documented controls like multi-factor authentication and staff training to be in place before a claim is accepted.
What to do if a scam gets through
Speed matters. If you believe your business has been targeted or has made a payment to a scammer, act immediately:
- Contact your bank’s fraud team straight away. Ask them to stop or recall the transfer. The faster you call, the higher the chance of recovering funds.
- Call the ATO’s dedicated scam line on 1800 008 540 if you have shared personal or business tax information with a scammer.
- Report the incident to ReportCyberthe Australian Cyber Security Centre’s official cybercrime reporting platform.
- Preserve the evidence. Keep the original email with full headers, any SMS messages, and notes from phone calls. Your bank and the authorities will need these.
- Change passwords on all affected accounts and force a re-enrolment of multi-factor authentication for any compromised access.
- Tell your team what happened. A brief, no-blame debrief helps everyone recognise the same tactic if it is tried again.
Keep your team one step ahead
The best defence against EOFY scams is a team that knows what to look for and has a clear process to follow when something looks wrong. Short, practical briefings before the end of June, covering the scam types above and the verification steps, make a real difference. A one-page reference guide with contacts for your bank’s fraud desk, the ATO scam line (1800 008 540), and your IT support team gives staff somewhere to turn when pressure is on.
You can also find more detail on the ACSC’s small business cyber security guidewhich covers practical steps for Australian SMEs. For broader reading on how email-based attacks work and how to respond, our post on business email compromise has more context.
How do we get started?
If you want to talk through your business’s exposure to EOFY scams or check that your email security and payment processes are up to scratch, get in touch with the TTA team. We work with businesses across Brisbane and South-East Queensland to put practical controls in place, without the jargon.



