Add Think Technology as a trusted source How to avoid scams this EOFY | Think Technology

How to avoid scams this EOFY

Graphic titled How to avoid scams this EOFY

EOFY is the one time of year when scammers and legitimate senders are competing for the same inbox. Your team expects to hear from the ATO, myGov, accountants, suppliers and banks all at once. That expectation is exactly what criminals exploit. With 30 June approaching, now is the right moment to make sure your business is ready.

According to the ACCC’s 2025 Targeting Scams Report, Australians lost $2.18 billion to scams last year, an increase of 7.8 per cent on 2024. The EOFY period consistently drives a spike in reportsand businesses are a deliberate target. ANZ reported a 67 per cent surge in rebate scams in July 2025, followed by a 15 per cent rise in impersonation scams over the same period. Scammers time their campaigns around the financial year close because they know businesses are busy, distracted and moving money around.

The good news: most EOFY scams follow predictable patterns. Train your team to spot them and you remove a large share of the risk before anything technical is needed.

The scams most likely to hit your business right now

EOFY scams broadly fall into three categories. Knowing the shape of each one makes them easier to catch.

Phishing emails and fake ATO messages. Scammers send emails, SMS messages and even phone calls that appear to come from the ATO or myGov. They may claim you have an unpaid tax debt, a refund waiting, or a document that needs signing. The ATO has flagged a spike in impersonation reports during tax season each year. A key thing to remember: the ATO will never email or text you asking for payment details, threaten arrest, or direct you to click a link to log in. All legitimate ATO messages appear in your myGov inbox, not your email.

Business email compromise (BEC) and payment redirection. This is where a scammer impersonates a manager, director or supplier to instruct staff to make a payment or change bank account details. Business email compromise is one of the costliest scam types for Australian businesses. The ACCC recorded $166.8 million in payment redirection losses in 2025 alone. The email address often looks legitimate at first glance, with just one character changed or a lookalike domain used.

Fake invoices and refund scams. Fraudsters send invoices from lookalike supplier addresses, or offer a refund that requires you to confirm your banking details. During EOFY, when genuine invoice volumes rise sharply, fake ones blend in more easily. Any invoice requesting a change to payment details should trigger a phone call to the supplier on a number you already have, not one provided in the email.

Why scams are harder to spot in 2026

Spotting a scam used to be easier. Bad grammar, obvious spelling mistakes and generic greetings were reliable tell-tale signs. Those tells are gone. Scammers now use AI tools to write polished, personalised messages that match the tone and style of the organisation they are impersonating. Security researchers have found that AI-generated phishing emails no longer carry the grammatical errors that traditional training taught people to look for.

This matters for EOFY scam awareness. Your team needs to know that a well-written email with correct logos and accurate details is not necessarily safe. The question is not “does this look legitimate?” but “did I expect this contact, and can I verify it through a separate channel?” When in doubt, pick up the phone and call the sender directly using a number you already have on file.

Four steps to protect your business this EOFY

These four measures make the biggest difference for small and mid-sized businesses. None of them require significant budget or weeks of preparation.

  1. Use multi-factor authentication (MFA) everywhere. MFA (multi-factor authentication) adds a second verification step beyond a password. Turn it on for email, accounting software, myGov, and banking. If a scammer gets hold of a password, MFA stops them from getting any further. Every account your team uses during EOFY should have it active.
  2. Use a password manager. Weak or reused passwords are still a leading cause of account compromise. A password manager generates and stores strong, unique passwords for every account. It removes the temptation to reuse passwords across systems and keeps credentials out of spreadsheets or notebooks.
  3. Keep your software and systems patched. Software updates include security fixes that close known vulnerabilities. This applies to your devices, your applications, your email platform and anything connected to your network. A managed IT support partner will handle patching across your environment so nothing falls through the gaps during a busy period.
  4. Brief your team before 30 June. A short heads-up to staff before EOFY goes a long way. Share examples of what a fake ATO email looks like. Remind people to verify any payment instruction that arrives by email, especially one requesting a change of bank details. Set a clear rule: any supplier account change must be confirmed by phone before a payment is made.

Follow the ACSC Essential Eight as your baseline

The Australian Cyber Security Centre’s Essential Eight framework gives businesses a practical, government-endorsed baseline for cyber security. It covers patching, MFA, application control, backups and more. You do not need to be at full maturity across all eight controls to get value from it. Even putting two or three in place materially reduces your exposure.

If you are not sure where your business sits against the Essential Eight, an IT security assessment is a sensible starting point. It gives you a clear picture of what is in place, what is missing, and what to prioritise.

What to do if something looks suspicious

If you or someone in your team receives a message that feels off, act on the instinct. Do not click any links or open attachments. Do not reply. Call the organisation directly on a number from their official website to check whether the contact is genuine.

If you think you have been targeted or have already responded to a scam, report it to Scamwatch at ReportCyber and contact the ATO’s scam reporting line on 1800 008 540. Act quickly. Getting ahead of a potential compromise in the first hours significantly reduces the damage.

Common EOFY scam questions

How do I know if an ATO email is real?

Genuine ATO messages appear in your myGov inbox, not in your regular email. The ATO will never ask you to click a link to log in, request payment details by email or SMS, or threaten arrest. If you receive an email or text claiming to be from the ATO, go directly to myGov by typing the address into your browser and check your inbox there.

What is business email compromise and how does it work?

Business email compromise (BEC) is when a scammer impersonates a manager, director or supplier to trick staff into making a payment or changing bank account details. The email address usually looks almost identical to the real one. EOFY is a high-risk period because payment volumes are elevated and staff are under pressure. Always verify payment instruction changes by phone before acting on them.

Why are EOFY scams harder to spot now than a few years ago?

Scammers now use AI tools to write polished, personalised messages that match the style and tone of the organisation they are pretending to be. The old tells, such as poor grammar and generic greetings, are largely gone. Your team should verify any unexpected request through a separate channel rather than relying on whether the email looks legitimate.

Does my business need to follow the Essential Eight?

The Essential Eight is a government framework, not a legal requirement for most private businesses. That said, it is the most practical cyber security baseline available to Australian SMEs. Even applying two or three of the eight controls, such as MFA and patching, significantly reduces your risk of a successful scam or breach. The ACSC publishes the framework free at cyber.gov.au.

What should I do if a staff member clicks a suspicious link?

Act immediately. Disconnect the affected device from the network if you can. Change any passwords that may have been entered on the suspicious page. Contact your IT support team or managed service provider and report the incident. The faster you respond, the better your chance of containing any damage before it spreads across your systems.

Where do we get started with cyber security for our business?

A good starting point is an IT security assessment. It gives you an honest picture of where your business is exposed and what to fix first. From there, a managed IT partner can put the key controls in place and keep them running so your team can focus on the business.

How do we get started?

EOFY is one of the busiest periods of the year. It is also one of the highest-risk periods for business scams. If you would like a second opinion on your current setup or want to make sure your team is ready before 30 June, we are happy to help. Get in touch with the TTA team and we will take it from there.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.