The ATO received 7,500 impersonation scam reports last July alone, and this year’s crop is even more convincing. Fake DocuSign emails carrying a document called “Declaration and Final Release”, phoney myGov sign-in pages, and cryptocurrency “declaration” demands are all landing in business inboxes right now.
The most dangerous variant uses a DocuSign-styled email with an ATO subject line. The “Review Document” button leads to a cloned myGov login page that harvests your username, password, date of birth and driver’s licence details. With those, attackers redirect tax refunds, drain super accounts and commit identity fraud. The ATO has confirmed it never uses DocuSign and never sends unsolicited sign-in links — if you see one, it’s fake.
We’re seeing these forwarded to bookkeepers and finance teams across our Sydney and Central West NSW client base almost daily this month. The formatting is now polished enough that even careful staff hesitate before dismissing them — and one click from an accounts payable team member is all it takes.
What to do right now
- Brief your finance team today. Show them the ATO’s scam alerts page so they know what the fakes look like.
- Never sign in to myGov via a link. Always type my.gov.au directly into your browser.
- Enable MFA on myGov and all business email accounts. A stolen password alone won’t get them in.
- If someone clicked: change passwords from a different device, call the ATO on 1800 008 540, and contact IDCARE on 1800 595 160.
If your team needs a quick refresher on spotting phishing emails, All IT runs cyber safety training sessions that use real-world examples like these. Get in touch if you’d like one before tax season wraps up.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
