MYTHOSAI

Australian business / PRACTICAL GUIDE

Where to report a scam or cybercrime in Australia

Prioritise containment, then choose the official reporting route for what happened.

Before you start

A safe device and a concise timeline; reporting services linked here are official.

Act on immediate harm first

If money or bank access is at risk, contact your bank through its genuine app or published number promptly. If a work device or business account is involved, notify the responsible IT contact. Reporting a scam does not itself cancel a transfer, revoke a session or remove malware.

Use a trustworthy device for recovery if the original one may be compromised. Do not keep communicating with the suspected scammer while attempting to verify their story.

Prepare a short factual record

  1. Record when the interaction happened and the channel used.
  2. Keep the message, relevant URL and transaction reference where applicable.
  3. Describe what you disclosed or approved: password, code, identity details, remote access or money.
  4. Record the protective actions already taken and the organisations contacted.

Do not include passwords, full recovery keys or unnecessary personal documents in ordinary notes. Preserve original evidence securely rather than editing your only copy.

Choose the route deliberately

Scamwatch accepts scam reports and provides recovery guidance. Australia's official cyber.gov.au reporting service directs users to relevant cybercrime or cyber-incident reporting paths, including ReportCyber where appropriate. Use the official page so current categories and eligibility guide your selection.

For identity misuse, follow the official recovery guidance and consider the services it directs you to, such as IDCARE. If there is immediate danger or a threat to personal safety, use the appropriate emergency or police contact route. Do not assume an online report guarantees an investigation or recovery of funds.

Check for continuing access

For an account incident, review sessions, recovery methods, app permissions and mailbox rules. For remote-access scams, disconnect the affected device and get its trustworthiness assessed; uninstalling the remote tool alone may not address everything done during access.

Watch for recovery scams

Someone promising guaranteed retrieval for an upfront fee can be a second scam. Never give another person banking codes or access because they claim to work with the original platform. Contact official organisations yourself using independent details.

Verify your recovery tasks

Keep a list of account changes, bank case references and reports submitted. Check that the actual exposed route was addressed. Reporting can help authorities understand patterns, but your recovery also needs practical containment and follow-up.

Business scope

Additional notification duties can depend on the incident and organisation. Do not infer all obligations from this general guide. Preserve evidence and obtain current authoritative guidance for the business's situation.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.