Your myGov or ATO account has been hacked — what to do now
A myGov takeover is not one problem but one per linked agency. This is the operational sequence: retake the sign-in, audit every linked service, get the locks applied, and decide whether to close and rebuild.
Short answer
Sign in at my.gov.au, switch to a passkey or Digital ID and turn the password off, then read Account settings and Account history for changes you did not make. Call the Services Australia Scams and Identity Theft Helpdesk on 1800 941 126 and the ATO Client Identity Support Centre on 1800 467 033. Each agency must be told separately.
Part of How to report a scam in Australia — and try to get your money back
A compromised myGov account does not feel like one event, because it is not one. myGov is a sign-on layer sitting in front of a couple of dozen separate federal services, and each keeps its own record, its own contact details and — this is the part that costs money — its own bank account field. Someone who gets in once can change the account your Centrelink payment lands in, order a replacement Medicare card to an address that is not yours, and change where the ATO pays refunds. None of that undoes itself when you change your password. Retaking the sign-in is the smallest part of the job.
The clock matters in a specific way. Payment redirection is the fastest-moving harm, because a changed destination silently converts a legitimate entitlement into someone else's income. Services Australia's own out-of-hours instructions put it plainly: contact your bank immediately, check your myGov account history for activity you do not recognise, check your linked services for changes such as a change to your usual payment destination, contact any linked service you are worried about, and call its Scams and Identity Theft Helpdesk the next business day. That list is short because it is meant to be done at eleven at night.
The advice that surprises people is official, published, and repeated by both myGov and Services Australia: where there is activity on the account that was not done by you and you cannot secure it or reach the helpdesk, the safest step is to close the myGov account entirely and create a new one. It is not a forum myth. It is what the department publishes, and this page explains what closing actually costs you, what it does not touch, and how to move your linked services across without creating the duplicate-account problem that makes everything worse.
This page stops at the account layer, deliberately. Cleaning up a return someone lodged in your name, chasing a refund that went elsewhere and arguing about the interest that followed is a different process with different remedies, and it belongs to the ATO's tax-fraud victim path. So does the wider identity-theft response — credit bans with all three bureaus, document reissue, IDCARE case management — which our identity theft guide covers in full. What follows is the narrow, operational version: a government account has been taken over, and you need it back.
Take the sign-in back before you audit anything
Reach myGov by typing my.gov.au, never through a link in a message, and change how you sign in before you change anything else. myGov's published advice is to use a multifactor option — a passkey, or Digital ID through myID — and then to turn the password off as a sign-in option entirely. That second half is the step almost everyone skips. A password left enabled is still a working route in, and if the credentials were bought from a marketplace rather than guessed, the attacker already holds them. Secure the email account behind it at the same time, with a different password again, because email is the recovery channel for everything else.
Then turn off your email address and mobile number as usernames. myGov lets you sign in with either, and its guidance is explicit that you should switch this off and use your myGov-generated username instead, because an email address you have used across a dozen other platforms has almost certainly appeared in someone else's breach. The generated username has not. It is ugly and unmemorable, which is the point.
Now read the account history. Under Account settings, Account history lists the last 50 actions on the account — sign-ins, attempted sign-ins, and changes to settings including your email address, mobile number, a connected Digital ID and any added passkey — with the local date and time and the device used. myGov states the test in one sentence: if there is activity that was not done by you, that indicates unauthorised access. Screenshot the list first. It holds fifty entries, and your own remediation will push the attacker's off the bottom of it.
Check connected devices on the same screen and disconnect anything you do not recognise. A connected device or app can hold a live session that survives a password change, so an attacker signed in on their own handset stays signed in while you congratulate yourself on the new passkey. Disconnecting forces every device to authenticate again — which is why you harden the sign-in first and disconnect second.
Then call the Services Australia Scams and Identity Theft Helpdesk on 1800 941 126, open Monday to Friday 8 am to 5 pm AEST, and AEDT during daylight saving. This is not the general Centrelink line and it is not the myGov helpdesk. Services Australia publishes exactly what it does: give advice on protecting your information, check your customer records for suspicious activity, make corrections where needed, and add extra security measures to prevent further unauthorised access. The last two are the reason to phone rather than email. An interpreter can be arranged free, and the line is reachable through the National Relay Service.
If you cannot sign in at all, treat that as a symptom rather than an inconvenience. Unusual sign-in activity can lock an account, and an attacker who has changed the registered email address and mobile number has taken the recovery path with them. Call the myGov helpdesk on 132 307 and select option 1 — Monday to Friday 7 am to 10 pm and weekends 10 am to 5 pm in local time zones, closed on national public holidays. It deals only with your own account: if you are calling for someone else, even as their nominee, that person has to be on the call with you.
Audit each linked service separately — myGov will not do it for you
myGov is a front door, not a record. It holds your sign-in, contact details and Inbox; the money, the claims and the bank account fields live inside the member services behind it. myGov's instruction after unauthorised access is to check your linked services for changes to your personal information, singling out bank account details, and to contact that service directly if anything looks wrong. The myGov helpdesk cannot correct an ATO record or reverse a Centrelink claim. Every agency has to be told, and each runs its own identity check.
Start with the two that move money fastest. In ATO online services, check the bank account nominated for refunds, then look for returns, activity statements or amendments lodged in your name, then the super accounts listed against you and your contact details. The ATO folds all of this into one number: it publishes 1800 467 033 for someone who thinks their myGov account or linked ATO services were accessed without permission, and for someone who thinks fraudulent updates were made to their ATO record — naming changed bank account details as the example.
In your Centrelink online account, check the payment destination, your address, and your payment and transaction history. Look for claims and advance payments made in your name, changes to Centrepay deductions, and new entries under Money you owe. This is not hypothetical: the Commonwealth Ombudsman's investigation documented perpetrators lodging false claims for payments, advances and loans in victims' names and redirecting pension payments, with some victims then unable to claim assistance such as the Child Care Subsidy until the agencies had finished investigating.
Medicare is where people look last and should not. Your Medicare online account shows three years of claims history for your current card, and lets you order a replacement card, update your address and bank details, manage who is listed on the card and view a digital copy. Check the bank account that receives benefits, whether a replacement card has been ordered to an address that is not yours, and whether anyone has been added to or removed from the card. Claims information older than three years, or from a past card, needs a paper request or a service centre visit.
Child Support, My Health Record, the Department of Veterans' Affairs, the NDIS, My Aged Care, the Unique Student Identifier and Workforce Australia each hold their own record and their own contact details, which is why myGov publishes a contact list per service rather than one number. Read the linked services list itself: myGov tells you what to look for there — whether new services have been linked, or services are missing. A service you never linked means someone else has been at your account. A service that has quietly disappeared is often more alarming, because unlinking is how a record gets moved somewhere you can no longer see it.
Write down what you find as you find it, with dates, times and reference numbers, and keep the file somewhere other than the email account you have just had to secure. Every agency you call will ask for it, and the ATO's standing advice to fraud victims is to document everything — communications, transactions and any evidence related to the fraud. It is also the raw material for a Commonwealth Victims' Certificate application or a dispute with a bank.
| Linked service | Check first | Who to call |
|---|---|---|
| Australian Taxation Office | Bank account nominated for refunds, returns or activity statements lodged in your name, listed super accounts, contact details | 1800 467 033 — Client Identity Support Centre |
| Centrelink | Payment destination, address, claims and advance payments, Centrepay deductions, entries under Money you owe | 1800 941 126 — Scams and Identity Theft Helpdesk |
| Medicare | Bank details for benefits, three years of claims history, replacement cards ordered, people added to or removed from the card | 1800 941 126, or 132 011 for card and claim mechanics |
| Child Support | Bank details, address, and any new assessment activity | 1800 941 126, then the Child Support enquiry line for extra security |
| My Health Record, DVA, NDIS, USI and the rest | Whether the service is newly linked, or has vanished from your linked services list | The service itself — myGov cannot act on another agency's record |
Account features and audit points from the Services Australia Medicare online account guidance and the myGov unauthorised-access page; phone numbers as published by Services Australia and the ATO and verified 6 August 2026.
Ask for the locks — the protections that are not self-service
Services Australia publishes a set of protections almost nobody knows about, for a structural reason: none of them can be switched on from a screen. You have to ask, by phone or in person. If you are already on the call to the Scams and Identity Theft Helpdesk, ask for all of them at once.
The first is a secret password added to your Medicare, Centrelink and Child Support records. It sits on top of the usual identity questions and you must give it to a Service Officer when you speak to them by phone or in person. You cannot add it online — you phone or visit a service centre — and Services Australia's warning travels with it: never tell it to anyone unless you are certain you are speaking to its staff, which in practice means a call you placed.
The second is a lock. You can ask Services Australia to lock access to your Centrelink, Medicare and Child Support online accounts, to phone self-service, and to the Express Plus apps. This too requires a phone call or a visit. It is inconvenient by design, and it is the right choice when you know credentials are circulating and would rather transact in person for a few weeks than leave a door ajar while an investigation runs.
If your Customer Reference Number has been exposed, you can ask for additional authentication measures on your Centrelink information; the department directs you to call your payment line. If a Child Support Reference Number has been exposed, Services Australia says it will put additional security measures in place and asks you to phone the Child Support enquiry line so the requirement is recorded. A concession card that has been exposed does not need replacing — it keeps working, and the department says so plainly, which saves a call.
A Medicare card is the exception. If the number has been exposed you can order a replacement through myGov or the myGov app, and the replacement carries a new issue number and expiry date, which makes the old card invalid. That is not the same as a new Medicare number: to change the number itself you must transfer to a new Medicare card, a separate request. A digital copy appears in the myGov app straight away; the physical card takes three to four weeks.
On the tax side, ask the ATO's Client Identity Support Centre what safeguards it can apply. The ATO publishes three categories: additional proof of record ownership before it will discuss your affairs at all, additional monitoring that flags irregular activity before automatic processing, and additional security measures inside its systems. It also states the exit condition — the measures stay on your file until the ATO determines there is no further risk. This is not a setting you switch off when it becomes annoying in October.
Do all of this in a single pass if you can. Every one of these calls requires you to prove your identity to an agency that has just been told your identity is compromised, which is slower than a normal call by design. Have your identity documents in front of you before you dial, along with your log and any report reference number.
What an ATO fraud flag actually changes about your tax year
The safeguards the ATO applies after fraud are useful and also disruptive, and the disruption is rarely explained before it lands. The ATO sets out what the measures can do. You may lose ongoing access to ATO online services and myGov unless you hold a Strong Digital ID such as myID. Pre-fill data may not be available. Extra checks may delay returns and other forms. Business activity statements may stop issuing automatically, so you or your agent must contact the ATO before each lodgment. And your Digital ID may itself be suspended while a compromise is investigated.
Read that list again against your own year. No pre-fill means assembling your income statement, bank interest, dividends and private health information by hand from the source documents. Delayed processing means a refund you had budgeted for in a fortnight may take considerably longer, so do not commit it. A suspended Digital ID means the recovery route you were relying on to get back into myGov is, temporarily, not there.
The fix for most of that is the same thing the ATO recommends as the protection. Its position is that a Strong myID is the most secure way to reach ATO online services through myGov, because setting one up requires verified identity documents plus a one-off face verification check in the app, and because it sets your online access strength — which gives you unrestricted access even where additional safeguards have been applied to your record. The thing that keeps the fraudster out is also the thing that keeps you in.
If the documents that would get you to Strong are themselves among those compromised, this becomes circular, and it is worth saying so on the phone rather than struggling on alone. The ATO's Client Identity Support Centre discusses which identification documents you will need when you call, and it exists precisely because the standard proofs of identity are often the things that were stolen. The same applies to a driver licence reissued with a new number after a fraud — tell the ATO rather than letting a mismatch fail silently in the app.
One boundary is worth stating clearly. What happens to a return lodged in your name, a refund paid to an account that is not yours, and the interest or penalties that followed is a separate process from securing the account. The ATO can extend time to lodge a replacement return, remit general interest charge where that is fair and reasonable, and arrange payment by instalments where a resulting debt causes hardship. It also publishes where it cannot help — where an assessment is valid, where a refund has already issued to the destination you or your authorised representative instructed, or where there is insufficient evidence of fraud.
When closing and rebuilding the myGov account is the right answer
myGov and Services Australia give the same advice, and it still surprises people: where there is activity on the account that was not done by you, and you cannot secure it or cannot reach the helpdesk, the safest step is to close the myGov account and create a new one. Services Australia repeats it in its out-of-hours guidance, and myGov repeats it on both its unauthorised-access and account-history pages. It is the published position, not a counsel of despair.
Understand what closing does before you do it. It is permanent. It unlinks every service you have connected, and you lose access to every message in your myGov Inbox. What it does not do is delete your underlying records: your Centrelink customer record, your Medicare enrolment and your ATO record live with those agencies, not with myGov, and survive intact. What dies is your copy of everything they have sent you — for most people, several years of letters nobody printed.
So spend twenty minutes first. Download or print anything in the Inbox you might plausibly need: Centrelink letters and payment summaries, Medicare statements, notices of assessment, income statements, concession card correspondence. Write down your Customer Reference Number, your Medicare card number including the individual reference number beside your name, and your tax file number — and store all of it somewhere other than the email account you have just had to secure.
Then close it: sign in, Account settings, Close account. myGov asks you to enter your password or use your Digital ID again before it proceeds, which is the last time that password will be useful to you. Create the new account with a different email address from the compromised one, and set it up from the start with the strongest sign-in option available — Digital ID or a passkey — with the password disabled and without reusing a password from any other account.
Relinking is the slow part, and it is where the duplicate-account trap lives. Do not create the second account while the first still exists, and do not abandon a half-relinked new account and start a third when a linking code expires. Link each service deliberately, using a linking code from that agency or a verified myID, and check as you go that each service shows the history you expect. A service that links but shows an empty or unfamiliar record is a signal to stop and phone that agency rather than push on.
Closing is not always proportionate. If you still control the account, the history shows a single failed sign-in attempt from an unfamiliar device, and nothing in any linked service has changed, then hardening the sign-in, disconnecting stale devices and completing the security review is enough. The trade is simple: closing costs you the Inbox archive and most of a day, while keeping a genuinely compromised account costs you everything behind it.
Superannuation, Medicare claims and the trails people forget
Superannuation is the largest number attached to your identity and the one almost nobody checks after a breach. The ATO lists it as its own scenario on the same helpline: someone falsely using your personal information to set up a self-managed super fund in your name, or changing an existing SMSF to reach your superannuation, is a call to 1800 467 033 on the same footing as a stolen tax file number.
Check with the fund itself, not only through myGov. Log in to each superannuation account directly and look at the contact details, the nominated bank account, any rollover requests in progress and any recent withdrawals. The ATO's advice to fraud victims is to check super accounts regularly for unusual transactions and to contact the fund if something does not look right — the fund, not the ATO, is the party that can stop a payment that has not yet left.
Be alert to the messages that arrive afterwards. A text or email telling you your myGov details have been changed, or that you have applied for early release of super when you have not, is a signal to treat as identity misuse rather than a system error — and a reason to phone the numbers on this page rather than reply. The same channel runs the other way: a message claiming your account is locked, with a link attached, is the classic myGov impersonation and is never legitimate.
On Medicare, read the claims history statement carefully before reporting anything, because a name you do not recognise is usually not fraud. The Department of Health, Disability and Ageing says so directly: consider whether you might have had a service such as an eye test, pathology or diagnostic imaging from someone other than your usual provider, and note that pathology is claimed by the practitioner who reports the result, not the person who collected the sample.
Where a claim genuinely was not yours, the reporting split matters and getting it wrong costs weeks. Suspected incorrect billing or claiming by a health provider — a doctor, pharmacist, dentist or allied health professional, or a practice or hospital — goes to the Department of Health, Disability and Ageing on its Provider Benefits Integrity Hotline, 1800 314 808. Suspected Medicare or Centrelink fraud by a member of the public, including a stolen Medicare card or details exposed in a breach, goes to Services Australia instead. The department publishes that division explicitly because reports keep arriving at the wrong door.
Finally, check the bank details each service holds rather than only looking for outgoing fraud. A benefit that should have reached you and did not is as much a symptom as a claim you did not make, and the account details recorded against your Medicare, Centrelink and ATO records are what an attacker changes first. Confirming all three point at an account you control is the closing move — worth repeating a week later, once the agencies have made their own corrections.
Report it properly, and consider a Commonwealth Victims' Certificate
Report the cybercrime through ReportCyber on the Australian Cyber Security Centre's site. The report is routed to police and produces a reference number that banks, insurers, credit bodies and agencies routinely ask for before they will act, so getting it early removes a round of argument later. Report the scam itself separately to Scamwatch, run by the ACCC's National Anti-Scam Centre — it does not investigate individual cases or recover money, but reports are used to take scam websites down, and it will connect you with IDCARE if you are at risk of identity misuse.
Call IDCARE on 1800 595 160. It is Australia and New Zealand's national identity and cyber support service, free to individuals, and a case manager produces a written response plan for your specific exposure rather than a generic checklist. That matters because the correct order of steps differs depending on whether what leaked was a driver licence number, a myGov credential or a Medicare card. Services Australia, the ATO and the Attorney-General's Department all point to it, and nobody legitimate charges for identity recovery help.
If the compromise traces back to a data breach, the notification you receive is not just information. Services Australia is required under the Privacy Act 1988 to notify the Office of the Australian Information Commissioner and the affected individuals of a notifiable data breach, and it says a letter about potential unauthorised access or changes to a Centrelink record will reach you by post or in your myGov Inbox depending on your preference. If one arrives, treat it as an instruction to audit your record that day.
Then there is a document almost nobody knows exists. A Commonwealth Victims' Certificate is issued by a state or territory magistrate to a victim of Commonwealth identity crime under the Criminal Code. The Attorney-General's Department's own examples are this page's subject matter almost exactly: someone using your birth certificate to falsely claim a Centrelink payment in your name, or using your identification details to have your Medicare rebates redirected to their bank account. The certificate records your name and describes the circumstances; it does not identify the perpetrator.
Be clear about what it is and is not. No prosecution or conviction is required, and the magistrate need not decide that a particular person committed the offence — only that, on the balance of probabilities, identification information was dealt with in the relevant way and that a certificate may help you address the resulting problems. You apply with an application form and a Commonwealth statutory declaration, and present proof of identity. The department states the limits plainly: a certificate compels no organisation to do anything, will not automatically restore your credit rating or remove a fraudulent transaction, and is not admissible in legal proceedings.
Its real value is leverage with an agency, a bank or a credit body that has stopped moving. If a magistrate declines to issue one, you can still ask the organisation for help with whatever evidence you have gathered. And keep the log going — the ATO's advice to fraud victims is to keep records of every communication, transaction and piece of evidence, and that log is what a certificate application, a complaint to the Commonwealth Ombudsman or a dispute with your bank is built from.
Key takeaways
- Change the sign-in method first — passkey or Digital ID, password turned off, email address and mobile number disabled as usernames — because a password change alone leaves the attacker's session and re-entry routes intact.
- The myGov helpdesk cannot fix an agency record: call the Services Australia Scams and Identity Theft Helpdesk on 1800 941 126 and the ATO Client Identity Support Centre on 1800 467 033 separately.
- Unauthorised linking attaches your Centrelink, Medicare or ATO record to a second myGov account, so a clean account history proves nothing — ask each agency whether another account is linked to your record.
- Ask for the protections that are not self-service: a secret password on your Medicare, Centrelink and Child Support records, and a lock on online accounts and the Express Plus apps, both set only by phone or in person.
- Closing the myGov account is official advice where there is activity you do not recognise, but it is permanent, it unlinks everything and it deletes your Inbox — save what you need before you press the button.
Who to contact
Services Australia — Scams and Identity Theft Helpdesk
myGov, Centrelink, Medicare and Child Support account compromise. Checks records for suspicious activity, makes corrections and applies extra security measures.
Monday to Friday 8 am to 5 pm AEST (AEDT during daylight saving months)
ATO Client Identity Support Centre
Compromised TFN or ABN, unauthorised access to ATO online services, fraudulent changes to your ATO record or bank details, and SMSF set up in your name.
Monday to Friday 8 am to 6 pm AEST
myGov helpdesk — Online Services Support Hotline
Sign-in problems, locked accounts and myGov account settings only. Cannot act on an agency record behind myGov.
Select option 1. Mon–Fri 7 am to 10 pm, weekends 10 am to 5 pm local time
Free national identity and cyber support service. A case manager produces a written response plan for your specific exposure.
ReportCyber — Australian Cyber Security Centre
Police reporting for cybercrime and identity crime. Produces the reference number banks and agencies ask for.
Provider Benefits Integrity Hotline
Department of Health, Disability and Ageing — suspected incorrect Medicare or PBS billing by a health provider.
At a glance
- First call
- 1800 941 126Services Australia Scams and Identity Theft Helpdesk, Mon–Fri 8 am to 5 pm AEST (AEDT in daylight saving)
- Tax and super
- 1800 467 033ATO Client Identity Support Centre, Mon–Fri 8 am to 6 pm AEST
- myGov helpdesk
- 132 307, option 1Online Services Support Hotline — sign-in and account problems only
- Account history depth
- Last 50 actionsAccount settings → Account history. Screenshot it before it rolls over
- Medicare claims online
- 3 years, current cardOlder claims or a past card need a paper request or a service centre
- Closing myGov
- PermanentUnlinks every service and deletes your access to myGov Inbox messages
- Not self-service
- Secret password and account locksSet only by phone or in person, on Medicare, Centrelink and Child Support records
- Free case support
- IDCARE — 1800 595 160Government-funded, free to individuals, builds a written response plan
Your myGov or ATO account has been hacked — FAQ
My myGov account was hacked, who do I call first?
Call the Services Australia Scams and Identity Theft Helpdesk on 1800 941 126, open Monday to Friday 8 am to 5 pm AEST. It can check your customer records for suspicious activity, correct them and add extra security measures. If the ATO service was linked, also call the ATO Client Identity Support Centre on 1800 467 033. The myGov helpdesk on 132 307 handles sign-in problems only.
How do I check if someone has been in my myGov account?
Sign in, go to Account settings and select Account history. It shows the last 50 actions, including sign-ins, attempted sign-ins and changes to your email address, mobile number, connected Digital ID or passkeys, with the date, time and device used. myGov's own test is simple: any activity that was not done by you indicates unauthorised access. Also check your linked services list and connected devices.
Should I close my myGov account if it has been hacked?
Where there is activity you do not recognise and you cannot secure the account or reach the helpdesk, both myGov and Services Australia say closing it and creating a new one is the safest step. Closing is permanent, unlinks every service and removes access to your myGov Inbox messages, so save the letters and note your CRN, Medicare number and TFN first. Your agency records themselves are not deleted.
What is unauthorised linking on myGov?
It is where your genuine Centrelink, Medicare or ATO record is linked to a fake myGov account created by someone else. The Commonwealth Ombudsman's 2024 investigation found myGov's controls did not adequately protect against it, describing it as a side entrance to member service accounts. Because nothing happens inside your own account, your myGov history looks clean — you have to ask each agency directly.
Someone changed my bank details on Centrelink — what happens to my payment?
Call 1800 941 126 immediately so the record can be corrected and extra security applied. Expect the agency to investigate, and be aware that the Ombudsman found victims' accounts were sometimes locked and payments suspended during investigations. Ask explicitly on the call that your legitimate payments continue while the fraud is examined, and record the name of the officer who agrees to it.
Can I get a new Medicare number after my details were exposed?
Yes, but a replacement card is not the same thing. Ordering a replacement through myGov or the myGov app gives you a card with a new issue number and expiry date, which invalidates the old card but keeps the same Medicare number. To change the number itself you must transfer to a new Medicare card, which is a separate request. A digital card is available immediately; the physical card takes three to four weeks.
Does the ATO lock my account after identity fraud?
It may apply security measures rather than a lock. The ATO says these can mean no ongoing access to its online services or myGov unless you hold a Strong Digital ID such as myID, no pre-fill data, extra checks that delay processing, business activity statements no longer issuing automatically, and a temporarily suspended Digital ID. The measures stay on your file until the ATO decides there is no further risk.
What is a Commonwealth Victims' Certificate and do I need one?
It is a certificate issued by a state or territory magistrate to a victim of Commonwealth identity crime, describing the circumstances without naming the offender. You apply with a form and a Commonwealth statutory declaration. It helps you argue with an agency, bank or credit body, but the Attorney-General's Department is clear it compels nobody, does not automatically restore a credit rating and is not admissible in legal proceedings.
Read next
Sources & provenance
Facts verified
- 1.Help if a scam or identity theft has affected you OfficialServices AustraliaUsed for: Scams and Identity Theft Helpdesk number and hours, the four things the helpdesk can do, the out-of-hours checklist, the data breach letter about a Centrelink record, and the statement that closing the myGov account is the safest step where there is activity you do not recognise
- 2.How you can protect your personal information after a data breach OfficialServices AustraliaUsed for: Secret password on Medicare, Centrelink and Child Support records; locking online accounts, phone self-service and Express Plus apps; extra authentication where a CRN or CSRN is exposed; replacement Medicare card versus transferring to a new Medicare number; concession cards not needing replacement
- 3.Keeping people's information secure OfficialServices AustraliaUsed for: Progress against the Commonwealth Ombudsman's Keeping myGov Secure recommendations as at February 2026 — three of four recommendations complete, controls added on banking changes and account settings, and almost 3.7 million accounts moved to stronger sign-in since December 2024
- 4.What you can do with your Medicare online account OfficialServices AustraliaUsed for: Three years of claims history for a current card, ordering a replacement card, updating address and bank details, managing who is on the card, and when a paper request or service centre visit is required instead
- 5.Unauthorised access to your myGov account OfficialmyGov (Services Australia)Used for: What to check after unauthorised access — account history, linked services, connected devices — the instruction to check linked services for changed bank account details, and the advice to close the account and relink using the strongest sign-in option
- 6.Check your myGov account history OfficialmyGov (Services Australia)Used for: That account history holds the last 50 actions, where to find it, and the specific changes to look for including email address, mobile number, connected Digital ID, added passkeys and device details
- 7.How you can protect your myGov account OfficialmyGov (Services Australia)Used for: Multifactor options, the advice to turn the password off as a sign-in option when using Digital ID or passkeys, turning off email and mobile as usernames, and the security review feature
- 8.How to close your myGov account OfficialmyGov (Services Australia)Used for: The closure path through Account settings, the re-authentication step, and that closing is permanent, unlinks all services and removes access to myGov Inbox messages
- 9.Help for identity theft OfficialAustralian Taxation OfficeUsed for: The 1800 467 033 scenarios including unauthorised myGov and ATO access, fraudulent bank detail changes and an SMSF set up in your name; monitoring of records before automatic processing; and the case for a Strong myID
- 10.Data breach guidance for individuals OfficialAustralian Taxation OfficeUsed for: The three categories of protective measure and what they change in practice — access restricted to a Strong Digital ID, no pre-fill data, delayed processing, activity statements not issuing automatically, and possible Digital ID suspension
- 11.If you are a victim of tax fraud OfficialAustralian Taxation OfficeUsed for: The victim checklist including changing sign-in methods, reissuing compromised documents, checking super accounts and documenting everything; the extension to lodge a replacement return, remission of general interest charge and instalment arrangements; and the stated limits on ATO intervention
- 12.Identity protection and recovery OfficialAttorney-General's DepartmentUsed for: What Commonwealth identity crime is, the Centrelink and Medicare examples, how to apply to a magistrate for a Commonwealth Victims' Certificate, the balance-of-probabilities test, and the express limits — it compels nobody, does not restore a credit rating and is not admissible in proceedings
- 13.Reporting incorrect billing, claiming, or suspected fraud OfficialDepartment of Health, Disability and AgeingUsed for: Why an unfamiliar name on a Medicare statement is usually not fraud, that pathology is claimed by the practitioner reporting the result, the Provider Benefits Integrity Hotline number, and the split between provider fraud and public fraud reported to Services Australia
- 14.Criminal Code Act 1995 LegislationFederal Register of LegislationUsed for: The Commonwealth statute containing the Part 9.5 identity crime offences and the Division 375 victims' certificate provisions under which a magistrate issues a Commonwealth Victims' Certificate
- 15.Revealed: How fraudsters steal from Australians through a myGov 'side entrance' NewsSBS NewsUsed for: Reporting of the Commonwealth Ombudsman's 2024 investigation — the definition of unauthorised linking, the finding that controls did not adequately protect against it, the 'side entrance' quotation, the four accepted recommendations, and the harms including redirected pension payments and suspended payments during investigations
Not a source — AI-assisted analysis on this page
- AI-assisted analysis — the order of the first-hour steps — The sequencing of the recovery steps — harden the sign-in method, then disable email and mobile as usernames, then disconnect devices, then read the account history, then audit linked services in descending order of how fast they move money — is our reasoning. myGov, Services Australia and the ATO each publish these actions individually; none of them publishes them as an ordered sequence or states that a password change alone leaves an attacker's live session intact.
- AI-assisted analysis — the threshold for closing rather than hardening — The test offered for deciding whether to close the myGov account or simply harden it — a failed sign-in attempt means harden, while a successful unexplained sign-in, a changed email or mobile, a new or missing linked service, or any altered bank account field means rebuild — is our analysis. Services Australia and myGov recommend closing where there is activity you do not recognise, but neither publishes a threshold test or weighs the cost of losing the Inbox archive against the risk of keeping the account.
The phone numbers and hours, account-history mechanics, close-and-relink advice, secret password and account-lock options, Medicare card replacement rules and the ATO's post-fraud safeguards are lifted from the Services Australia, myGov and ATO pages cited above. The Commonwealth Victims' Certificate process and its stated limits come from the Attorney-General's Department; the unauthorised-linking findings come from SBS News reporting of the Commonwealth Ombudsman's 2024 investigation and from Services Australia's own February 2026 progress update. Two passages are marked as AI-assisted analysis: the ordering of the first-hour steps, and the threshold for closing an account rather than hardening it. Phone numbers, opening hours, menu options, myID document requirements and the remediation status of the Ombudsman's recommendations all change — confirm the current position with Services Australia on 1800 941 126 and the ATO on 1800 467 033 before acting.
Facts on this page are taken from the sources listed above — Australian government departments, regulators, statutory bodies and official statistical releases. Comparisons, judgements and "which option suits whom" conclusions are AI-assisted analysis written over those sources; they are marked in the text and listed as an AI-analysis entry in the sources, not attributed to any authority. Rates, thresholds, fees and processing times change, often at the start of a financial year; figures are current as at the review date shown and should be confirmed with the responsible agency before you rely on them for money or legal decisions.