June is peak season for fake ATO, myGov and invoice scams. Here are the EOFY tricks to watch for and the simple habits that stop them.
Every June, without fail, we see a rise in scam attempts hitting small businesses. It is not a coincidence. End of financial year is the one time when everyone expects messages about tax, super, invoices and refunds, and when accounts people are at their busiest. Scammers know that a busy person expecting a tax email is the easiest person to fool.
The EOFY scams we see most
The fake ATO or myGov message is the classic. It arrives as a text or email about a refund, a debt or an urgent update, with a link to "log in". The page looks convincing, and its only job is to steal your myGov credentials. A related one claims your super fund needs you to verify your details before year end.
The fake accountant email is more targeted. It appears to come from your own accountant or bookkeeper, asking you to send documents, change bank details or pay a bill urgently before 30 June. Then there is invoice redirection: a supplier's "accounts department" emails to say their bank details have changed, timed precisely for the weeks when your accounts team is flat out and least likely to double-check. It rarely arrives as one suspicious email. Typically the attacker has been sitting quietly in a supplier's email account for a fortnight, reading the real correspondence, learning how invoices look and who signs off payments. Then they reply inside a genuine existing thread, with the real history attached, and only the bank details are new. Nothing about it looks odd, because everything except the account number is real. Rounding out the list are fake auditor or compliance requests demanding business records by a deadline.
Why it works even on careful people
These scams do not succeed because people are careless. They succeed because they pull three levers at once, and June turns all three up. The first is urgency: a deadline of 30 June, a refund that expires, a payment needed within the hour. Urgency short-circuits checking. The second is authority: the message wears the logo of the ATO, your bank, your accountant or a supplier you have paid for years, and most of us were raised to cooperate with authority. The third is expectation: in June you are genuinely waiting for tax emails, super statements and final invoices, so a fake one does not stand out the way it would in October. When urgency, authority and expectation line up, even the person in your office who "never falls for anything" is one busy afternoon away from clicking. That is why the defence is a habit, not a judgement call: you verify the same way every time, especially when the message feels legitimate.
How to verify safely
The habits that stop these are simple, and none of them require technical skill.
- Never log in through a link in a message. If the ATO, myGov or your super fund supposedly needs you, open your browser and go to the site yourself, the way you normally would.
- Ring your accountant on the number you already have saved, not the number in the email, before sending documents or changing anything about how you pay them.
- Know how the ATO actually contacts you. The ATO's own guidance is clear that it will never threaten you with immediate arrest, demand payment by gift card or cryptocurrency, or ask for your login details. Any message doing those things is fake, full stop.
- Treat any change to bank details as guilty until proven innocent. Verify it by phone on a known number before paying a cent.
A June and July checklist for the accounts team
Share this with whoever touches money or payroll in your business:
- Agree now that any bank-detail change, no matter who it appears to come from, gets verified by a phone call to a known number before payment.
- Agree that no payment over a set threshold is made by one person alone during June and July.
- Remind everyone that urgency is the tell: real suppliers and the ATO do not demand payment within the hour.
- Keep payroll and superannuation portal logins behind multi-factor authentication, and check they are working before the rush.
- Book five minutes at the next team meeting to show everyone a real scam example, so the pattern is fresh in mind.
Protect the accountant relationship itself
Your accountant is both a target and a weak point: if an attacker gets into their email, the fake messages come from a real address you trust. Have a two-minute conversation with them now. Agree a verification word or a call-back rule: any request for payment or sensitive documents, from either direction, gets confirmed by a quick phone call before action. Good accountants welcome this. It protects them as much as you.
After 30 June: the July version
The calendar flips and the scams flip with it. July brings fake refund notifications, because plenty of people are owed money after lodging and the promise of a refund is hard to ignore. It brings fake "your tax return has been received, click to view" messages. And it brings fake "your BAS is overdue" demands aimed at business owners who genuinely do have a business activity statement (BAS) due and are feeling guilty about it. The verification habits do not change: log in directly, never through a link, and ring a known number before paying or sending anything.
If money has already gone
Speed matters more than embarrassment. Call your bank first, immediately, because transfers can sometimes be frozen if you are fast. Then report it to ReportCyber, the Australian Government's cyber crime reporting service, and to Scamwatch so others are warned. Finally, tell your IT provider so the entry point, usually a compromised email account, can be closed before it is used against someone else in your contact list.
The 30-second rule for any money request in June
Before any payment, changed bank detail or document handover in June and July, take thirty seconds to verify it through a channel you already trust: a phone call to a saved number, or a portal you open yourself. Thirty seconds of checking beats weeks of trying to recover money.
If you would like your team walked through these habits properly, with the technical protections like email filtering and multi-factor authentication checked at the same time, we are happy to help. June is exactly the right month to do it.
Want your business checked before EOFY scam season peaks? Start with a free, no-obligation assessment.
Book a free cyber security assessment- eofy
- scams
- cyber security
- ato
- small business
