Australians reported $2.18 billion in scam losses in 2025 according to the ACCC’s most recent Targeting Scams report, up 7.8% on 2024. That figure is still well below the 2022 peak of $3.1 billion, so coordinated action by the National Anti-Scam Centre, banks and telcos is having an effect. But it isn’t winning outright, and 2025’s upward move was driven largely by AI-powered fraud: deepfake voice clones, AI-generated romance profiles, and investment scam bots that now hold sustained conversations across weeks.
Investment scams alone cost Australians $837.7 million in 2025, comfortably the largest single category. Payment redirection ($166.8m), romance ($139.9m), phishing ($97.6m) and remote access scams round out the top five, which together accounted for 60% of total losses.
The financial cost is only part of it. Victims lose time, confidence, and often their sense of trust in ordinary interactions. The best protection isn’t fear, it’s familiarity with the patterns.
Below is an 8-question quiz. Work through it before checking the answers.
The quiz
Q1. I avoid technology so I’m not likely to be scammed. True or false?
Q2. Financial scams can target you via which of the following? (Multiple answers.) a) Text b) Dating websites c) Social media
Q3. An email from a trusted source contains a link. Should you click it? a) Yes, it’s from a friend b) No, never click links in emails c) It depends: were you expecting the email, is it legitimate?
Q4. You’ve become close to someone you met online. When they ask you to buy goods to send to them, you: a) Do your research and if in doubt, break off communication b) Say you’ll think about it and continue the relationship c) Agree — they’re not asking for money
Q5. A friend sends a text saying they’ve changed their number. What do you do? a) Save the new number in your contacts b) Block the text c) Message the new number with a question only your friend would know
Q6. You can trust the websites of well-known brands. True or false?
Q7. What is credential stuffing? a) Fake documents used to create false identities b) Someone using data from a breach to log into your accounts elsewhere c) A lost wallet being used by whoever finds it
Q8. You think you’ve been scammed. Which of the following should you do? (Multiple answers.) a) Review what happened and think about how to protect yourself in future b) Contact your financial institutions, change passwords, report to Scamwatch c) Don’t tell anyone; you’re embarrassed and feel foolish
The answers
Q1: False
If you don’t use the internet you still need to be alert. Door-knockers pose as charity collectors or utility inspectors. Phone scammers still work the landline. Postal fraud is quieter but hasn’t gone away.
The safest defaults:
- Don’t feel pressured to let strangers into your home
- Ask for identification, then look up the organisation’s phone number yourself and call it to confirm
- Never make a payment to a door-to-door salesperson
Some door-knockers are legitimate (government efficiency programs, licensed tradespeople) but they’ll wait while you verify.
Q2: All of the above
According to the government’s Scamwatch service, scams reach victims through text, email, phone, social media, dating sites, in-person contact, impersonation of businesses or officials, threats and extortion, employment offers, and “unexpected money” (inheritances, prizes, refunds).
The single biggest category by dollars lost in Australia is investment scams: fake trading platforms, fraudulent crypto opportunities, and impersonation of legitimate fund managers. If someone offers you an investment through a channel other than a licensed adviser, treat it as fraudulent until proven otherwise.
Q3: It depends
Legitimate emails do contain links. The question is whether the email is actually from who it claims to be from.
Before clicking, check:
- Were you expecting it? An unprompted “invoice”, “delivery notice”, or “account issue” is a common phishing shape.
- Does the sender’s address match? A close-but-wrong domain (paypa1.com, mygov-au.net) is the tell.
- Are you addressed correctly? Generic “Dear customer” openings on account-related emails are suspicious.
- Hover over the link before clicking. The URL it actually points to shows in your browser’s status bar. If it doesn’t match the visible text, don’t click.
If you’re unsure, log into the account directly through your browser rather than through the email link. The email is safe to ignore; a real notification will also be waiting for you inside the account.
Q4: Do your research and break off contact if in doubt
Romance and relationship scams cost Australians tens of millions of dollars annually and cause disproportionate emotional harm. Scammers build trust over weeks or months, then start asking for help: buying goods to ship overseas, opening accounts in your name, wiring money for a “crisis”, or paying for their travel.
Signs to notice:
- They can’t video call, or the video is always brief and low-quality
- Their stories don’t quite line up on repeat questions
- The relationship escalates faster than a normal friendship would
- Any request for money, cryptocurrency, gift cards, or your bank details
Search their name plus “scam”. Reverse-image search their photos. If anything feels off, break contact. Legitimate people don’t ask for money from someone they’ve never met in person.
Q5: Message the new number with a question only your friend would know
Fraudsters clone or spoof phone numbers, and the “hi Mum, I’ve dropped my phone, this is my new number” scam is one of the most common in Australia. If the follow-up message asks you to pay a bill, transfer money, or click a link, the scammer has your friend’s number in their contacts and is working through them.
Verify through a channel the scammer doesn’t control: call the original number, or ask something only the real person would know.
Q6: False
Scammers build convincing lookalike websites for major brands. They also build fake investment platforms that look institutional-grade. Before buying or investing, check:
- The URL exactly (paypal.com not paypa1.com; ato.gov.au not ato-refund-au.com)
- The padlock icon and
https://prefix - Whether the payment methods are legitimate (be wary of crypto, wire transfer, or gift card requests)
- Whether the business exists on ASIC or the ATO’s business register
For investment platforms specifically, check ASIC’s Professional Registers Search to confirm the entity actually holds an Australian Financial Services (AFS) licence. For a financial adviser, use the Financial Advisers Register. If the entity or adviser isn’t listed, walk away.
Q7: Someone using data from a breach to log into your accounts elsewhere
Credential stuffing happens when a data breach at one company exposes emails and passwords, and criminals then try those same credentials against other services (banks, super funds, myGov). It works because a large proportion of people reuse passwords.
The defences are straightforward:
- Different password for every account. A password manager makes this practical.
- Two-factor authentication (2FA) on anything sensitive. Bank, email, super fund, myGov, work accounts.
- Act quickly when notified of a breach. Change the affected password AND any other account that used the same one.
If your super fund or bank is on the breach list, the same account should be first on your list to lock down. Super balances have been a rising target for scammers because the balances are large, the login pathways vary in security, and detection of a fraudulent rollover can take weeks.
Q8: Both a and b
Being scammed carries real emotional weight, and staying silent is the response most scammers rely on. The productive moves are:
- Immediately contact your bank and any other financial institution involved. Freeze cards, block transactions, and put the account on alert.
- Change all passwords. Email first, then anything using the same or similar password.
- Enable 2FA on everything you haven’t already.
- Report to Scamwatch to help identify patterns and warn others.
- Contact IDCARE if identity documents were involved. It’s a free service and knows the process cold.
The bigger picture in 2026
Two trends are changing the scam landscape faster than public awareness is keeping up:
- AI voice cloning. A few seconds of audio from a social media video is enough to clone someone’s voice. The “grandparent in trouble” scam and CEO wire-fraud impersonation now sound convincing.
- Long-play investment scams. Sophisticated fake platforms with genuine-looking dashboards, small early “returns” to build trust, and pressure to add more before withdrawing. These target older Australians with super balances specifically, and losses regularly run to six figures.
The single most reliable defence against sophisticated investment scams: only engage with advisers and platforms you’ve verified through the ASIC register, and never move retirement money in response to an unsolicited approach, however professional it looks.
If your super is involved
Super scams are their own category. If someone unsolicited approaches you about “unlocking” your super, “rolling” it into an SMSF, or investing it in a “high-return” alternative, treat it as fraud. Our article on what happens to your super when you die covers the legitimate side of who can access super and how. Any pathway outside that framework isn’t a pathway.
If you’ve been approached about anything that touches your super or retirement savings, or you’re not sure whether a communication is legitimate, contact us before you act. A five-minute call to a licensed adviser is a cheap insurance policy against a six-figure mistake.