Tax-Time Scam Surge: Why EOFY Is Open Season for Impersonation Scams

Tax-Time Scam Surge: Why EOFY Is Open Season for Impersonation Scams

In June 2026, the Australian Taxation Office released scam data that should concern any organisation heading into tax time.

The ATO received 1,547 reports of ATO impersonation scams in June alone, a 12% increase from May. Because this data relies on people recognising and reporting scams, the real number of attempts is likely to be higher.

It is also worth treating these figures as a signal of trend rather than a complete count of activity. Scam reports depend on people recognising and reporting suspicious contact, so the actual volume of attempted impersonation is likely to be higher than the reported number.

The months after the end of the financial year are a particularly attractive period for these attacks. Australians are expecting tax-related messages, finance teams are processing year-end activity, and ATO and myGov references are more likely to feel legitimate.

 

Why are these attacks spiking now?

We just passed the end of the financial year. This means the ATO is already overwhelmed with contact, which makes it easier for fake refunds or debt notices to fly under the radar.

ATO found that 98.5% of scam reports in June came by email, compared to less than 1% by SMS. This is worth paying attention to, since most people are still on the lookout for scam texts more so than emails.

 

What’s changed in 2026?

Scammers are getting smarter, often fuelled by AI. According to Scamwatch, criminals are building fake websites with official-looking logos and branding, making it easier for victims to mistake them for ATO or myGov services if they arrive via a convincing email or search result.

There are also new protections in place. The Sender ID Register, which went live on 1 July 2026, is designed to make it easier to identify SMS messages that may not come from the organisation they claim to represent. It is a step in the right direction, but the ATO’s June reporting shows that email remains the more prominent channel for this scam activity.

For business owners, the risk is not only that an employee may lose personal information. A convincing tax-time email can also trigger invoice redirection, credential theft, payroll compromise, or unauthorised access to finance systems. That makes EOFY scam awareness a business continuity issue, not just an individual cyber safety concern.

 

Here’s what SMBs can do today

There are several steps you and your teams can take to defend against impersonation scams.

● Never click any links in SMS messages from ATO or myGov. The ATO has said it does not send unsolicited SMS with hyperlinks.

● Always verify any correspondence independently by calling the ATO or logging into myGov directly. Don’t blindly trust links.

● Always brief your finance and admin staff specifically before EOFY, since they’re the ones dealing with refund or debt emails

● Report any suspected scams via Scamwatch and the ATO’s dedicated spam-reporting channel

 

Because these scams are now heavily email-based, organisations should also check whether their email security controls are keeping pace. That includes reviewing SPF, DKIM and DMARC alignment, tightening impersonation protection, monitoring lookalike domains, and making sure suspicious messages are easy for staff to report.

Most importantly, educate your team. These scams target everyone at every level in your organisation, so it’s no use if only your security team are aware of the above best practices. Encourage questions and try to build a culture of communication.

 

Work with Aryon

At Aryon, we help Australian SMBs defend against cyber threats during tax season and all year round.

We can help you build staff awareness training and email filtering into your processes as a standing EOFY measure, so you’re prepared every year.

Contact us to find out more about how we can help.

Share this Article!