ATO logo

Fraudulent activity targeting tax professionals’ systems

The ATO is aware of fraudulent activity targeting the systems of a small number of tax professionals.

Published 26 August 2026

The Australian Taxation Office (ATO) is aware of fraudulent activity targeting the systems of a small number of tax professionals.

The ATO can confirm that its systems are secure, resilient and have not been compromised.

Tax professionals are being targeted by cyber criminals, primarily via malicious links in emails, attachments and other communications. When clicked, these links can install unauthorised software or malware. Once compromised, third parties may gain access to tax agent systems, obtain client information, and potentially interact with the ATO through Online Services for Agents.

The ATO is providing support to a small number of tax professionals that have been impacted. The ATO has put additional security measures and controls in place in respect of these agents and their clients.

The ATO is encouraging tax agents to take the following actions to protect their systems and their clients:

  • install anti-virus software on your system and make sure it is kept it up to date
  • be cautious when opening links or attachments, or downloading files from unexpected or unknown sources
  • independently verify suspicious communications using trusted contact details
  • use multi-factor authentication, and
  • keep your devices, apps and software up to date.

The ATO encourages tax professionals who have received suspicious communications, clicked on a potentially malicious link, or who believe their systems may have been compromised to contact the ATO to report the breach. Instructions for how to do this are available on the ATO website or agents can call the ATO’s client identity support centre on 1800 467 033. Early engagement can help minimise harm, protect client information, and support a timely resolution.

Agents should also review the Office of the Australian Information Commissioner's information about notifiable data breachesExternal Link to make sure they comply with their obligations under the Privacy Act 1988, including the Notifiable Data Breaches scheme. They should also review the Tax Practitioners Board information on how the NDBS can impact their TPB registrationExternal Link.

Protecting taxpayers’ information

The security of taxpayers’ information is of the utmost importance to the ATO. If an individual sees unusual activity on their ATO account, it may be related to identity theft. Identity information can be compromised in a variety of ways, including requests for information by malicious actors, phishing emails, large-scale data breaches, and individual device or home network hacking.

When the ATO suspects that a taxpayer’s identity may be compromised, we activate stringent security measures to protect the taxpayer. If an individual is found to be a victim of third-party fraud, we will work with them to fix their client account and remediate it to its true and genuine position. The ATO will then work to recover any lost funds.

In the past year, the ATO has introduced a range of measures to better protect client identity and accounts.

The ATO continues to encourage individuals to use myID when interacting with the ATO’s online services and to set up to the highest identity strength where possible to make it harder for fraudsters to exploit their identities.

To help keep your personal information safe and protected, the ATO’s app now has powerful new safety features designed to give individuals real-time control over their tax affairs through alerts and instant account locking to help stop fraudsters in their tracks.

Notes for journalists

QC107941