ATO confirms some systems targeted by fraudulent actors

Technology

The Tax Office has become aware that malware installed via dodgy links has affected some practitioners and has provided assurance that its systems remain secure and resilient and have not been compromised.

11 August 2026 By Carlos Tse 3 minutes read
Share this article on:

The Tax Office has implemented additional security measures and controls following its becoming aware of “fraudulent activity targeting the systems of a small number of tax professionals”.

Speaking to Accountants Daily, an ATO spokesperson said the scam involved malicious links embedded in inbound communications, such as job applications, CVs, and emails. The communications the ATO refers to do not relate to impersonation of its emails.

“When clicked, these links can install unauthorised software or malware on your device. Once compromised, third parties may gain access to tax agent systems, obtain client information, and potentially interact with the ATO through Online services for agents,” the spokesperson said.

“Identity information can be compromised in a variety of ways, including requests for information by malicious actors, phishing emails, large-scale data breaches, and individual device or home network hacking.

“The ATO continues to remain vigilant for new and emerging cyber threats. The ATO has put additional security measures and controls in place in respect of these agents and their clients.”

The Tax Office recommended that tax professionals maintain security practices, including exercising caution when opening emails, downloading attachments, or clicking on unfamiliar links, and shutting down computers at the end of each day.

Further, it said practitioners should regularly review and manage user access through Relationship Authorisation Manager (RAM) and Access Manager, promptly remove outdated, unnecessary, or inappropriate permissions, and monitor user access and privileges on an ongoing basis.

 
 

For tax practitioners who have received or engaged with these scam communications and believe their systems to be compromised, the ATO recommends that they report a breach by searching QC54173 on the ATO website or by calling the ATO’s client identity support centre on 1800 467 033.

“Early engagement can help minimise harm, protect client information, and support a timely resolution.

“The safety of taxpayers’ information is of the utmost importance to the ATO. If an individual sees unusual activity on their ATO account, it may be related to identity theft,” the Tax Office spokesperson said.

Accountants DailyWant to see more stories from trusted news sources?
Make Accountants Daily a preferred news source on Google.
Tags: