Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow
Fake myGov 'Secure Message' Phishing Scam Targets (TL-2026-2556) is a medium-severity phishing campaign, first published 2026-09-18. It has no confirmed attribution, maps to 11 MITRE ATT&CK techniques (T1036, T1056.003, T1111), and is covered by 9 detection rules and 3 indicators of compromise.
Key facts for TL-2026-2556
- Threat ID
- TL-2026-2556
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-18
- Last reviewed
- 2026-09-18
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, consumer
- Target regions
- australia, Oceania
- Detection rules
- 9
- Indicators of compromise
- 3
A phishing campaign impersonating Australia's myGov portal and the Australian Taxation Office (ATO) uses a fake 'secure message' email lure sent from workspace@sasinm.com to drive victims through a seven-step web flow that harvests credentials, three separate SMS one-time codes, security question answers, full name/DOB, and front/back driver's license photos, before redirecting to the real myGov site with a fake tax-statement confirmation.
How Fake myGov 'Secure Message' Phishing Scam Targets works
MailGuard identified and analyzed a phishing campaign that spoofs Australia's myGov citizen-services portal and the Australian Taxation Office (ATO). The lure is an email with the display name 'myGov' sent from the address workspace@sasinm.com, subject 'You have (1) New Message', claiming the recipient has '1 New MyGov Notification' and '1 new secure message(s)' waiting, styled with Australian Government/ATO branding and language about a secure link.
Clicking through leads to a fake myGov website that runs the victim through a seven-stage progressive data-harvesting flow rather than a single credential form: (1) username/email and password, on a page mimicking the genuine myGov login complete with 'Forgot username'/'Forgot password' links; (2) a first SMS one-time verification code via a labeled 'Code' field; (3) answers to three user-selected security questions via dropdown selections; (4) full name and date of birth (dd/mm/yyyy); (5) a second SMS code via a repeat 'Enter Code' page; (6) front and back photos of the victim's driver's license via a 'Drivers License' upload interface with separate 'Browse' buttons; (7) a third SMS code via a final 'Enter Code' page. Prompting for three separate SMS codes at different points in the flow, interleaved with credential and PII collection, is consistent with a real-time credential-relay/adversary-in-the-middle kit that forwards stolen username/password and OTP to the genuine myGov login in order to capture an authenticated session, a pattern documented across the broader 2026 Australian myGov phishing wave and explicitly described by independent researchers as a 'reverse-proxy or credential-relay [that] forwards both factors to the real my.gov.au and captures the authenticated session' (credential-relay kits observed by other researchers achieving account takeover within 5-30 minutes of harvest).
After the seventh step, the page displays a fake confirmation reading 'Your details has successfully been submitted, please wait 21 days for your income statement to be tax ready' and redirects the victim to the legitimate my.gov.au site, a technique designed to suppress suspicion by ending the interaction on a real, trusted domain.
The combination of full credentials, live MFA/OTP interception, security-question answers, DOB/PII, and government photo-ID capture goes beyond simple account takeover: it supplies everything needed for synthetic-identity fraud, fraudulent tax-return filing, and redirection of Centrelink/ATO payments. This matches the 'Identity re-verification' template documented as one of four rotating myGov-impersonation templates driving the highest-volume government-impersonation phishing wave hitting Australian inboxes in 2026, per independent 2026 reporting. It also continues a documented lineage of MailGuard-tracked multi-stage myGov/ATO credential-harvesting kits: a May 2025 MailGuard campaign ('Multi-Stage Super Scam Mimics myGov to Harvest Credentials') used a 10-stage flow from a different sender (mnadeau@pshift.com, subject 'Action Required Under Section 12B – Personal Records Audit') landing on pazenesaction.org.es, harvesting myGov credentials, 2FA SMS codes, name/DOB/driver's-license/Medicare/TFN details, an ID-document selfie, and superannuation-fund login credentials, before also redirecting to the genuine myGov site — the same operational template (progressive multi-step harvest ending in a real-domain redirect) as this campaign, differing mainly in step count and the addition of the driver's-license-photo-upload step in this variant. The MailGuard source article for this specific threat discloses no threat-actor attribution and no additional infrastructure beyond the sasinm.com sending domain, and BeaconBeagle returned no C2 infrastructure correlation for that domain.
MITRE ATT&CK techniques used in TL-2026-2556
Defense Evasion
T1036 Masquerading; T1684.001 Impersonation
Collection
T1056.003 Input Capture: Web Portal Capture
Credential Access
T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle
Execution
T1204.001 User Execution: Malicious Link
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1585.002 Establish Accounts: Email Accounts; T1608.005 Stage Capabilities: Link Target
Reconnaissance
Remediation for Fake myGov 'Secure Message' Phishing Scam Targets
Immediate actions
- Do not click links in unsolicited 'myGov secure message' emails; navigate directly to my.gov.au or use the official myGovID app instead
- Delete and report suspicious myGov/ATO-branded emails via Scamwatch (scamwatch.gov.au) and the ATO scam line (1800 008 540)
- If credentials, SMS codes, security answers, PII, or driver's license images were already submitted, immediately reset the myGov password, notify Services Australia/ATO to flag the account for fraud monitoring, and engage IDCARE for identity-theft remediation
- Block or quarantine mail from the sending domain sasinm.com and flag the 'You have (1) New Message' / 'myGov' display-name pattern at the secure email gateway
Workarounds
- Always reach myGov services by typing my.gov.au directly into the browser or opening the official myGovID app rather than following a link in an email or SMS
Longer-term hardening
- Enforce DMARC/DKIM/SPF and brand-impersonation/display-name-spoofing detection at the email gateway to catch spoofed 'myGov' senders
- Run user awareness training covering multi-step phishing flows and real-time OTP-relay/adversary-in-the-middle kits that defeat SMS-based MFA
- Where supported, migrate from SMS OTP to phishing-resistant authenticators (passkeys/FIDO2) for myGov and other sensitive government accounts
- Monitor for and request takedown of newly registered myGov/ATO lookalike domains via Services Australia's scam-reporting channel
Timeline of Fake myGov 'Secure Message' Phishing Scam Targets
- ATO and Services Australia first publicly warn of a myGov/myGovID impersonation email scam requesting identity verification via a fake login page, establishing this as a recurring threat pattern.
- MailGuard reports a prior multi-stage myGov/ATO impersonation campaign ('Action Required Under Section 12B – Personal Records Audit', sender mnadeau@pshift.com, landing page pazenesaction.org.es) using a 10-step flow that harvests myGov credentials, 2FA SMS codes, name/DOB/driver's-license/Medicare/TFN details, an ID-document selfie, and superannuation login credentials before redirecting to the genuine myGov site — the same progressive-harvest-then-redirect template as this campaign.
- Independent research documents an escalating 2025-2026 wave of AI-generated myGov phishing emails 'virtually indistinguishable' from genuine communications, with myGov impersonation described as Australia's most-reported scam category.
- Researchers document four rotating myGov-impersonation phishing templates active in 2026, including an 'Identity re-verification' template requesting scanned Medicare cards and driver's licences for synthetic-identity fraud, matching this campaign's document-harvesting step.
- Scamwatch and the ATO issue a joint public alert on ongoing ATO/myGov impersonation scams, warning that the ATO never sends emails or SMS with hyperlinks to a login page.
- MailGuard identifies and publishes technical analysis of the fake myGov 'Secure Message' phishing campaign, detailing the seven-step credential/PII/SMS-code/driver's-license harvesting flow sent from workspace@sasinm.com.
Sources cited for Fake myGov 'Secure Message' Phishing Scam Targets
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow
- Australian Taxation Office (ATO) and 'myGov' impersonation scams
- The myGov Scam Costing Australians Thousands
- myGov 'account locked' scam Australia: how to spot the Medicare, Centrelink and ATO phishing wave in 2026
- Aussies urged to beware of myGov email phishing scam
- Multi-Stage Super Scam Mimics myGov to Harvest Credentials
More in phishing
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google API Open-Redirect and nxcli.io Infrastructure
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data
- Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via nxcli.io
Detection coverage for TL-2026-2556
As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2556 across Splunk SPL, Microsoft KQL and Sigma, covering 3 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.