A new phishing campaign is impersonating myGov, using a fabricated “secure message” notification to lure recipients into a multi‑step web flow designed to harvest myGov login credentials, multiple one‑time SMS codes, security question answers, full name and date of birth, and images of a driver’s licence, all in a single visit.
The email itself is deliberately low‑key. Rather than a dramatic subject line, it arrives with the generic heading “You have (1) New Message”, styled to look like a routine myGov or ATO account notification.
The body tells the recipient they have “1 New MyGov Notification” and “1 new secure message(s)” waiting, and invites them to click a blue “View Message” button to review it. The email includes Australian Government and Australian Taxation Office branding, along with language about secure links and legally binding communications, details that make it feel like a standard government notice rather than a threat.
Behind the branding, the sender details tell a different story:
None of these align with legitimate myGov infrastructure, but the email is styled convincingly enough that a busy staff member or individual taxpayer could miss the mismatch.
Example phishing content shown using myGov and ATO branding. Not affiliated with myGov or the Australian Taxation Office.
Clicking “View Message” leads to a phishing site that closely mimics the look and feel of the official myGov portal, including Australian Government and myGov logos, familiar colour schemes, and footer acknowledgements.
From there, the fake site walks visitors through a staged, escalating sequence of pages.
Step 1: Username and password
The first page is a “Sign in with myGov” screen requesting:
It closely mirrors the genuine myGov sign‑in experience, including links such as “Forgot username” and “Forgot password”, and a button to “Create a myGov account if you don’t have one already.”
Step 2: SMS code
After “signing in,” the site moves to an “Enter Code” page, instructing the user to enter a code sent by SMS to their mobile number. A text box labelled “Code” and a “Next” button are presented, along with references to Digital Identity and helpdesk support.
Step 3:Security questions
The next page is titled “Sign in with myGov” and prompts the user to verify three security questions:
A “Submit” button completes the step.
Example phishing content shown using myGov branding. Not affiliated with myGov.
Step 4:Full name and date of birth
The flow then moves to a “Personal Information” page requesting:
Again, the layout and footer closely resemble the genuine myGov environment.
Example phishing content shown using myGov branding. Not affiliated with myGov.
Step 5:Another SMS code
A further “Enter Code” page appears, asking for another SMS code. This repetition is likely intended to reinforce the illusion of a secure, multi‑factor process while capturing additional live codes that could be used for account takeover.
Example phishing content shown using myGov branding. Not affiliated with myGov.
Step 6: Driver’s licence images
The next step is a “Drivers License” upload interface, with fields for:
Each field includes a “Browse…” button and a “submit” button to upload images.
Example phishing content shown using myGov branding. Not affiliated with myGov.
Step 7:Another SMS code
A third “Enter Code” page then asks for yet another SMS code, further increasing the attacker’s chances of capturing a valid, time‑sensitive verification code.
Example phishing content shown using myGov branding. Not affiliated with myGov.
Final step: Fake confirmation and redirect
The flow ends on a confirmation screen stating that “Your details has successfully been submitted, please wait 21 days for your income statement to be tax ready.” MailGuard’s analysts observed that a genuine visitor would then be redirected to the legitimate myGov site, a deliberate piece of misdirection designed to leave the victim believing the process worked normally rather than realising their details have already been captured.
Example phishing content shown using myGov branding. Not affiliated with myGov.
A few details make this campaign more dangerous than a typical credential‑phishing attempt:
For organisations whose staff use myGov for tax, benefits, or government services, this kind of scam has implications beyond individual loss. Compromised identities can be leveraged to access other systems, open accounts, or bypass controls that rely on government‑issued documentation.
GlobalGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.
Reach out to speak to a GlobalGuard expert about securing your inboxes against advanced, malicious email-borne threats with our AI-powered email security solutions.