Centrelink warning as 270,000 emails sent out in attack related to Medicare, superannuation and tax benefits
Summary
A large-scale phishing campaign is targeting Australians with over 270,000 malicious emails detected in the past four months by human risk management platform Mimecast. These emails impersonate Centrelink and Services Australia, leveraging artificial intelligence to create "super clones" with perfect grammar, syntax, and layout, making them extremely difficult to distinguish from legitimate communications. The scam emails mimic information about benefits such as superannuation, JobSeeker payments, Medicare, and Family Tax Benefits. Cybercriminals aim to trick recipients into clicking links and entering personal details, which can lead to data theft, malware installation, ransomware infections, and identity theft through credential stuffing. Services Australia confirms it will never send links, attachments, or QR codes in emails or text messages, and official government websites always end in ".gov.au".
Key takeaway
For Australians managing personal data or government benefits, the rise of AI-powered phishing means you must abandon traditional scam detection methods. Do not click any links in emails claiming to be from Services Australia or Centrelink. Instead, manually type official URLs like my.gov.au into your browser or use the official app. Verify all urgent messages directly within your official account or by calling the agency. Implementing passkeys and two-factor authentication significantly enhances your account security against credential theft.
Key insights
AI-powered phishing campaigns now produce "super clone" emails, rendering traditional grammar-based scam detection ineffective.
Principles
- AI significantly elevates phishing realism.
- Official government communications avoid embedded links.
- Scammers exploit urgency and emotional triggers.
In practice
- Manually type official website URLs.
- Verify all notifications within official apps.
- Implement two-factor authentication and passkeys.
Topics
- Phishing Campaigns
- AI-powered Scams
- Identity Theft
- Services Australia
- MyGov Security
- Credential Stuffing
Best for: CTO, VP of Engineering/Data, Executive, General Interest, IT Professional
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Welcome to the Artificial Intelligence Incident Database.