ASIC kept adding unlicensed trading brands and fake lookalikes of real Australian firms to the Moneysmart investor alert list. Between 31 August and 4 September it listed 38 names, including impersonations of Bank Australia, IG Australia and MEX Australia. The Australian Signals Directorate’s Cyber Security Centre also opened September with a national push to switch on multi-factor authentication.
Scamwatch did not publish a fresh news-and-alerts item after 17 August. Older official warnings on fake purchase-callback texts and ATO / myGov impersonation remain current.
Official alerts this week
ASIC Moneysmart investor alert list — new names this week
Source: ASIC Moneysmart investor alert list
Between 31 August and 4 September 2026 ASIC added 38 names. Most are unlicensed crypto- or “AI” trading brands on throwaway domains. Five impersonate real Australian companies:
- Impersonation of Bank Australia Limited (AFSL 238431) at oneatlanticunion.com, also using the name One Atlantic Union Banking
- Impersonation of IG Australia Pty Ltd (AFSL 515106) at igaus.org — the real site is ig.com/au
- Impersonation of MEX Australia Pty Ltd (AFSL 416279) at nexfengrowth.com, also using the name Nexfen Growth
- Impersonation of Admirals AU Pty Ltd at services-asic-au.org
- Impersonation of Quantum Cryptocurrency Exchange Pty Ltd at quantumcrypto.world
Unlicensed names added this week include a further Yepbit pair (yepbgg.com, yepszs.com), CapBit AI, Gallion-GPT, Web3 Sync, GlobeMarket, Rinehart Capital, TradePlus24 and FinAiBox. Being on the list means ASIC says the operator is not licensed to offer investments in Australia. The list is not complete: a missing name is not a green light. Check the live list and ASIC’s professional registers before you send money, and treat unexpected bank, broker, super, wealth or crypto offers as hostile until you have verified them yourself.
ASD Australian Cyber Security Centre: switch on multi-factor authentication
Source: ASD ACSC, 1 September 2026
ASD says 42 per cent of industry, government and critical-infrastructure incidents reported to it in 2024–25 involved compromised accounts or credentials. A password on its own is no longer enough. The Centre is asking people and businesses to turn on phishing-resistant multi-factor authentication this month, starting with email, banking and social-media accounts.
Passkeys are the preferred option where a service supports them: they combine something you know (a PIN or biometric) with a device you have. If passkeys are not available, use an authenticator app. Do not read a one-time code back to anyone who rang or messaged you first. Setup steps for common accounts are on the Centre’s multi-factor authentication guide.
Still active official warnings
Fake purchase-callback texts
Source: Scamwatch, 14 July 2026
A message claims you bought something you did not buy and tells you to call a number to cancel. The number is the scammer. Hang up and check any real purchase through the store’s official app or website. Do not read back a one-time code to anyone who rang you.
ATO and myGov impersonation
Source: Scamwatch and the ATO, 26 June 2026
Emails, texts and calls pretending to be from the ATO or myGov are still circulating. The ATO will not demand urgent payment by gift card, crypto or a transfer to a “safe account”. Sign in only through ato.gov.au or my.gov.au that you typed yourself. The ATO’s own scam alerts page still features a July 2026 fake appointment-email warning.
What to do
- Stop. Unexpected messages that rush you to pay, call, buy gift cards or share codes are a warning sign. Pause.
- Check. Use a phone number or website you already know, not the one in the message. For investments, check ASIC’s registers and the investor alert list.
- Protect. Turn on multi-factor authentication. If money or details have gone, contact your bank first, then report it.
How to report
- Scamwatch (ACCC): scamwatch.gov.au/report-a-scam
- Report a cybercrime to police via ReportCyber: cyber.gov.au
- Identity and recovery support: IDCARE on 1800 595 160
This brief is a public-interest summary of official Australian sources. It is not legal, financial or tax advice. Always rely on the original agency page linked above.
Sources used
- Scamwatch news RSS
- Scamwatch news and alerts
- National Anti-Scam Centre news
- National Anti-Scam Centre news RSS
- ASIC Moneysmart investor alert list
- ASIC investor alert list (JSON)
- ASIC professional registers
- ASIC 2026 media releases
- ASD ACSC: Multi-factor Authentication: Switch it on
- ASD ACSC multi-factor authentication guide
- WA ScamNet warnings
- WA ScamNet search
- ACCC public warning notice register
- Telstra active scams
- ACMA scam alerts
- Scamwatch: fake purchase callback scams
- Scamwatch: ATO and myGov impersonation scams
- ATO scam alerts