Consumer awareness
Scams on mobile devices and where to report them
Most harm that reaches Australians through a phone arrives as a message or a call rather than as software. This page describes how those approaches are usually structured, what to do if you have already responded, and which Australian body handles which report.
Security software addresses part of this picture and not the larger part. A link filter can block a page that is already on a known-bad list; nothing in a subscription intervenes when a person is persuaded, over twenty minutes on the phone, to move their savings to a "safe account". Recognising the structure of these approaches is what actually helps, and it costs nothing.
Nothing on this page is a suggestion that your device is currently affected by anything. It is background, written the way a public advisory is written.
How approaches usually reach a phone
- Text messages about a delivery, a toll, a fine or a refund
- A short message with a link, referencing something plausible enough that a proportion of recipients are expecting exactly that. The link leads to a page that imitates the organisation's own and asks for card details or account credentials.
- Calls claiming to be from a bank, a telco or a government agency
- Often preceded by a message to make the call look expected. The distinguishing feature is pressure to act during the call, and a request to install remote access software or to confirm codes sent to you by SMS.
- Messaging app contact from an unknown number
- An opening that reads like a wrong number or a friendly mistake, developing over days or weeks before any money is mentioned. Investment and cryptocurrency propositions commonly arrive this way.
- Marketplace and classifieds contact
- A buyer or seller who wants to move the transaction onto a different platform or payment method, frequently with a fabricated shipping or verification service in the middle.
- Fake support and fake alerts
- A web page or pop-up that claims to have found a problem on your device and offers a phone number. A web page cannot inspect your phone, and no legitimate provider makes contact this way.
Scamwatch, operated by the National Anti-Scam Centre within the ACCC, publishes current examples of approaches circulating in Australia, and is the best single place to check whether something you have received matches a known pattern.
The one habit that generalises
Whenever a message or call asks you to do something involving money, credentials or access, stop and re-establish the channel yourself: hang up, close the message, and contact the organisation using a number or address you have looked up independently — from your card, from your own saved contacts, or from the organisation's official site typed in by hand. Legitimate organisations do not mind being called back. This single habit defeats most of the approaches above, regardless of how convincing the original contact was.
If you have already responded
Speed matters more than perfect diagnosis. Work through these in order, and do not spend time deciding how it happened first.
Contact your bank
If card details, account details or a payment were involved, call your bank straight away using the number on your card or in your banking app. Australian banks operate fraud lines outside business hours. Ask them to note the incident, whatever they say about recovering the funds.
Change the password on your email first
Email is the reset route for every other account you hold, so it comes before banking, social media and shopping accounts. Turn on multi-factor authentication while you are there.
Remove anything you were asked to install
If you were talked into installing an app or a remote access tool, uninstall it, then restart the device. On a device where you are unsure what was installed, a factory reset from a known-good backup is the thorough option.
Check what else used that password
Any other account sharing it needs a new one. A password manager makes this tractable; a written list works too, as long as it is not stored on the device.
Report it
Use the table below to pick the right body. Reporting takes a few minutes and contributes to the data that drives disruption and public warnings.
Tell someone
These approaches are engineered to be convincing and to trade on embarrassment. Telling a family member or friend is both practical and a check on further contact from the same source.
Which Australian body handles which report
| Situation | Where it goes | What that body does |
|---|---|---|
| A scam message, call or website, whether or not you lost money | Scamwatch, National Anti-Scam Centre | Collects reports, publishes warnings, and shares intelligence used to disrupt scams |
| A cybercrime: hacking, an account takeover, ransomware, online fraud | Australian Cyber Security Centre, through ReportCyber | Routes reports to the relevant police jurisdiction and provides recovery guidance |
| Cyberbullying of a child, adult cyber abuse, image-based abuse or seriously harmful content | eSafety Commissioner | Australia's online safety regulator; can seek removal of material and provides support information |
| An organisation mishandled your personal information, or notified you of a data breach | Office of the Australian Information Commissioner | Federal privacy regulator; handles privacy complaints under the Privacy Act 1988 and the Notifiable Data Breaches scheme |
| A business misled you or would not honour consumer guarantees | ACCC and your state or territory consumer protection agency | The ACCC enforces the Australian Consumer Law; individual disputes are handled by state and territory agencies |
| An immediate threat to someone's safety | Triple Zero (000) | Emergency services |
What reporting achieves, honestly
A report rarely returns money directly, and it is worth being plain about that rather than implying otherwise. What it does is aggregate: patterns across thousands of reports are what allow agencies to issue warnings, to work with banks and telecommunications providers on disruption, and to direct enforcement. It also creates a record, which can matter if the same incident resurfaces later in a dispute with a bank or a merchant.
Where software genuinely helps, and where it does not
A mobile security subscription can contribute in three places on this page: blocking a known fraudulent page before it loads, screening some nuisance calls and messages, and managing passwords so that one compromised account does not become five. Those are real contributions and they are a legitimate reason to buy.
It does not contribute where the decision is made by a person under pressure, which is where the largest losses happen. Any advertising that suggests otherwise — that a subscription makes you scam-proof — is overstating what the technology does.
Protecting people who are targeted more often
- Set up multi-factor authentication on the email accounts of family members who would find recovery difficult, and record the recovery method somewhere safe.
- Agree in advance that no family member will ever ask for money by message alone, so an unexpected request is easy to identify.
- Check that older devices in the household still receive updates, since replacing one is easier to plan than to do urgently.
- Talk through the "hang up and call back" habit with anyone who mostly uses their phone for calls. It is more valuable to them than any software.
For the buying side of this subject, see the choosing guide, the feature definitions, and the page on subscriptions and consumer rights.