Consumer awareness

Scams on mobile devices and where to report them

Most harm that reaches Australians through a phone arrives as a message or a call rather than as software. This page describes how those approaches are usually structured, what to do if you have already responded, and which Australian body handles which report.

Security software addresses part of this picture and not the larger part. A link filter can block a page that is already on a known-bad list; nothing in a subscription intervenes when a person is persuaded, over twenty minutes on the phone, to move their savings to a "safe account". Recognising the structure of these approaches is what actually helps, and it costs nothing.

Nothing on this page is a suggestion that your device is currently affected by anything. It is background, written the way a public advisory is written.

How approaches usually reach a phone

Text messages about a delivery, a toll, a fine or a refund
A short message with a link, referencing something plausible enough that a proportion of recipients are expecting exactly that. The link leads to a page that imitates the organisation's own and asks for card details or account credentials.
Calls claiming to be from a bank, a telco or a government agency
Often preceded by a message to make the call look expected. The distinguishing feature is pressure to act during the call, and a request to install remote access software or to confirm codes sent to you by SMS.
Messaging app contact from an unknown number
An opening that reads like a wrong number or a friendly mistake, developing over days or weeks before any money is mentioned. Investment and cryptocurrency propositions commonly arrive this way.
Marketplace and classifieds contact
A buyer or seller who wants to move the transaction onto a different platform or payment method, frequently with a fabricated shipping or verification service in the middle.
Fake support and fake alerts
A web page or pop-up that claims to have found a problem on your device and offers a phone number. A web page cannot inspect your phone, and no legitimate provider makes contact this way.

Scamwatch, operated by the National Anti-Scam Centre within the ACCC, publishes current examples of approaches circulating in Australia, and is the best single place to check whether something you have received matches a known pattern.

The one habit that generalises

Whenever a message or call asks you to do something involving money, credentials or access, stop and re-establish the channel yourself: hang up, close the message, and contact the organisation using a number or address you have looked up independently — from your card, from your own saved contacts, or from the organisation's official site typed in by hand. Legitimate organisations do not mind being called back. This single habit defeats most of the approaches above, regardless of how convincing the original contact was.

If you have already responded

Speed matters more than perfect diagnosis. Work through these in order, and do not spend time deciding how it happened first.

  1. Contact your bank

    If card details, account details or a payment were involved, call your bank straight away using the number on your card or in your banking app. Australian banks operate fraud lines outside business hours. Ask them to note the incident, whatever they say about recovering the funds.

  2. Change the password on your email first

    Email is the reset route for every other account you hold, so it comes before banking, social media and shopping accounts. Turn on multi-factor authentication while you are there.

  3. Remove anything you were asked to install

    If you were talked into installing an app or a remote access tool, uninstall it, then restart the device. On a device where you are unsure what was installed, a factory reset from a known-good backup is the thorough option.

  4. Check what else used that password

    Any other account sharing it needs a new one. A password manager makes this tractable; a written list works too, as long as it is not stored on the device.

  5. Report it

    Use the table below to pick the right body. Reporting takes a few minutes and contributes to the data that drives disruption and public warnings.

  6. Tell someone

    These approaches are engineered to be convincing and to trade on embarrassment. Telling a family member or friend is both practical and a check on further contact from the same source.

Which Australian body handles which report

Where to direct a report, by the kind of incident
SituationWhere it goesWhat that body does
A scam message, call or website, whether or not you lost moneyScamwatch, National Anti-Scam CentreCollects reports, publishes warnings, and shares intelligence used to disrupt scams
A cybercrime: hacking, an account takeover, ransomware, online fraudAustralian Cyber Security Centre, through ReportCyberRoutes reports to the relevant police jurisdiction and provides recovery guidance
Cyberbullying of a child, adult cyber abuse, image-based abuse or seriously harmful contenteSafety CommissionerAustralia's online safety regulator; can seek removal of material and provides support information
An organisation mishandled your personal information, or notified you of a data breachOffice of the Australian Information CommissionerFederal privacy regulator; handles privacy complaints under the Privacy Act 1988 and the Notifiable Data Breaches scheme
A business misled you or would not honour consumer guaranteesACCC and your state or territory consumer protection agencyThe ACCC enforces the Australian Consumer Law; individual disputes are handled by state and territory agencies
An immediate threat to someone's safetyTriple Zero (000)Emergency services

What reporting achieves, honestly

A report rarely returns money directly, and it is worth being plain about that rather than implying otherwise. What it does is aggregate: patterns across thousands of reports are what allow agencies to issue warnings, to work with banks and telecommunications providers on disruption, and to direct enforcement. It also creates a record, which can matter if the same incident resurfaces later in a dispute with a bank or a merchant.

Where software genuinely helps, and where it does not

A mobile security subscription can contribute in three places on this page: blocking a known fraudulent page before it loads, screening some nuisance calls and messages, and managing passwords so that one compromised account does not become five. Those are real contributions and they are a legitimate reason to buy.

It does not contribute where the decision is made by a person under pressure, which is where the largest losses happen. Any advertising that suggests otherwise — that a subscription makes you scam-proof — is overstating what the technology does.

Protecting people who are targeted more often

  • Set up multi-factor authentication on the email accounts of family members who would find recovery difficult, and record the recovery method somewhere safe.
  • Agree in advance that no family member will ever ask for money by message alone, so an unexpected request is easy to identify.
  • Check that older devices in the household still receive updates, since replacing one is easier to plan than to do urgently.
  • Talk through the "hang up and call back" habit with anyone who mostly uses their phone for calls. It is more valuable to them than any software.

For the buying side of this subject, see the choosing guide, the feature definitions, and the page on subscriptions and consumer rights.