Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow

Fake myGov 'Secure Message' Phishing Scam Targets (TL-2026-2556) is a medium-severity phishing campaign, first published 2026-09-18. It has no confirmed attribution, maps to 11 MITRE ATT&CK techniques (T1036, T1056.003, T1111), and is covered by 9 detection rules and 3 indicators of compromise.

Key facts for TL-2026-2556

Threat ID
TL-2026-2556
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-09-18
Last reviewed
2026-09-18
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
government administration, consumer
Target regions
australia, Oceania
Detection rules
9
Indicators of compromise
3

A phishing campaign impersonating Australia's myGov portal and the Australian Taxation Office (ATO) uses a fake 'secure message' email lure sent from workspace@sasinm.com to drive victims through a seven-step web flow that harvests credentials, three separate SMS one-time codes, security question answers, full name/DOB, and front/back driver's license photos, before redirecting to the real myGov site with a fake tax-statement confirmation.

How Fake myGov 'Secure Message' Phishing Scam Targets works

MailGuard identified and analyzed a phishing campaign that spoofs Australia's myGov citizen-services portal and the Australian Taxation Office (ATO). The lure is an email with the display name 'myGov' sent from the address workspace@sasinm.com, subject 'You have (1) New Message', claiming the recipient has '1 New MyGov Notification' and '1 new secure message(s)' waiting, styled with Australian Government/ATO branding and language about a secure link.

Clicking through leads to a fake myGov website that runs the victim through a seven-stage progressive data-harvesting flow rather than a single credential form: (1) username/email and password, on a page mimicking the genuine myGov login complete with 'Forgot username'/'Forgot password' links; (2) a first SMS one-time verification code via a labeled 'Code' field; (3) answers to three user-selected security questions via dropdown selections; (4) full name and date of birth (dd/mm/yyyy); (5) a second SMS code via a repeat 'Enter Code' page; (6) front and back photos of the victim's driver's license via a 'Drivers License' upload interface with separate 'Browse' buttons; (7) a third SMS code via a final 'Enter Code' page. Prompting for three separate SMS codes at different points in the flow, interleaved with credential and PII collection, is consistent with a real-time credential-relay/adversary-in-the-middle kit that forwards stolen username/password and OTP to the genuine myGov login in order to capture an authenticated session, a pattern documented across the broader 2026 Australian myGov phishing wave and explicitly described by independent researchers as a 'reverse-proxy or credential-relay [that] forwards both factors to the real my.gov.au and captures the authenticated session' (credential-relay kits observed by other researchers achieving account takeover within 5-30 minutes of harvest).

After the seventh step, the page displays a fake confirmation reading 'Your details has successfully been submitted, please wait 21 days for your income statement to be tax ready' and redirects the victim to the legitimate my.gov.au site, a technique designed to suppress suspicion by ending the interaction on a real, trusted domain.

The combination of full credentials, live MFA/OTP interception, security-question answers, DOB/PII, and government photo-ID capture goes beyond simple account takeover: it supplies everything needed for synthetic-identity fraud, fraudulent tax-return filing, and redirection of Centrelink/ATO payments. This matches the 'Identity re-verification' template documented as one of four rotating myGov-impersonation templates driving the highest-volume government-impersonation phishing wave hitting Australian inboxes in 2026, per independent 2026 reporting. It also continues a documented lineage of MailGuard-tracked multi-stage myGov/ATO credential-harvesting kits: a May 2025 MailGuard campaign ('Multi-Stage Super Scam Mimics myGov to Harvest Credentials') used a 10-stage flow from a different sender (mnadeau@pshift.com, subject 'Action Required Under Section 12B – Personal Records Audit') landing on pazenesaction.org.es, harvesting myGov credentials, 2FA SMS codes, name/DOB/driver's-license/Medicare/TFN details, an ID-document selfie, and superannuation-fund login credentials, before also redirecting to the genuine myGov site — the same operational template (progressive multi-step harvest ending in a real-domain redirect) as this campaign, differing mainly in step count and the addition of the driver's-license-photo-upload step in this variant. The MailGuard source article for this specific threat discloses no threat-actor attribution and no additional infrastructure beyond the sasinm.com sending domain, and BeaconBeagle returned no C2 infrastructure correlation for that domain.

MITRE ATT&CK techniques used in TL-2026-2556

Defense Evasion

T1036 Masquerading; T1684.001 Impersonation

Collection

T1056.003 Input Capture: Web Portal Capture

Credential Access

T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle

Execution

T1204.001 User Execution: Malicious Link

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1585.002 Establish Accounts: Email Accounts; T1608.005 Stage Capabilities: Link Target

Reconnaissance

T1598.003 Phishing for Information: Spearphishing Link

Remediation for Fake myGov 'Secure Message' Phishing Scam Targets

Immediate actions

  • Do not click links in unsolicited 'myGov secure message' emails; navigate directly to my.gov.au or use the official myGovID app instead
  • Delete and report suspicious myGov/ATO-branded emails via Scamwatch (scamwatch.gov.au) and the ATO scam line (1800 008 540)
  • If credentials, SMS codes, security answers, PII, or driver's license images were already submitted, immediately reset the myGov password, notify Services Australia/ATO to flag the account for fraud monitoring, and engage IDCARE for identity-theft remediation
  • Block or quarantine mail from the sending domain sasinm.com and flag the 'You have (1) New Message' / 'myGov' display-name pattern at the secure email gateway

Workarounds

  • Always reach myGov services by typing my.gov.au directly into the browser or opening the official myGovID app rather than following a link in an email or SMS

Longer-term hardening

  • Enforce DMARC/DKIM/SPF and brand-impersonation/display-name-spoofing detection at the email gateway to catch spoofed 'myGov' senders
  • Run user awareness training covering multi-step phishing flows and real-time OTP-relay/adversary-in-the-middle kits that defeat SMS-based MFA
  • Where supported, migrate from SMS OTP to phishing-resistant authenticators (passkeys/FIDO2) for myGov and other sensitive government accounts
  • Monitor for and request takedown of newly registered myGov/ATO lookalike domains via Services Australia's scam-reporting channel

Timeline of Fake myGov 'Secure Message' Phishing Scam Targets

  • ATO and Services Australia first publicly warn of a myGov/myGovID impersonation email scam requesting identity verification via a fake login page, establishing this as a recurring threat pattern.
  • MailGuard reports a prior multi-stage myGov/ATO impersonation campaign ('Action Required Under Section 12B – Personal Records Audit', sender mnadeau@pshift.com, landing page pazenesaction.org.es) using a 10-step flow that harvests myGov credentials, 2FA SMS codes, name/DOB/driver's-license/Medicare/TFN details, an ID-document selfie, and superannuation login credentials before redirecting to the genuine myGov site — the same progressive-harvest-then-redirect template as this campaign.
  • Independent research documents an escalating 2025-2026 wave of AI-generated myGov phishing emails 'virtually indistinguishable' from genuine communications, with myGov impersonation described as Australia's most-reported scam category.
  • Researchers document four rotating myGov-impersonation phishing templates active in 2026, including an 'Identity re-verification' template requesting scanned Medicare cards and driver's licences for synthetic-identity fraud, matching this campaign's document-harvesting step.
  • Scamwatch and the ATO issue a joint public alert on ongoing ATO/myGov impersonation scams, warning that the ATO never sends emails or SMS with hyperlinks to a login page.
  • MailGuard identifies and publishes technical analysis of the fake myGov 'Secure Message' phishing campaign, detailing the seven-step credential/PII/SMS-code/driver's-license harvesting flow sent from workspace@sasinm.com.

Sources cited for Fake myGov 'Secure Message' Phishing Scam Targets

More in phishing

Detection coverage for TL-2026-2556

As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2556 across Splunk SPL, Microsoft KQL and Sigma, covering 3 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats