The Times Australia
The Times World News

.
The Times Real Estate

.

The $500 million ATO fraud highlights flaws in the myGov ID system. Here's how to keep your data safe

  • Written by Rob Nicholls, Associate professor of regulation and governance, UNSW Sydney
The $500 million ATO fraud highlights flaws in the myGov ID system. Here's how to keep your data safe

The Australian Tax Office (ATO) paid out more than half a billion dollars to cyber criminals between July 2021 and February 2023, according to an ABC report[1].

Most of the payments were for small amounts (less than A$5,000) and were not flagged by the ATO’s own monitoring systems.

The fraudsters exploited a weakness in the identification system used by the myGov online portal to redirect other people’s tax refunds to their own bank accounts.

The good news is there’s plenty the federal government can do to crack down on this kind of fraud – and that you can do to keep your own payments secure.

How these scams work

Setting up a myGov account or a myGov ID requires proof of identity in the form of “100 points of ID[2]”. It usually means either a passport and a driver’s licence or a driver’s licence, a Medicare card, and a bank statement.

Once a myGov account is created, linking it to your tax records requires two of the following: an ATO assessment, bank account details, a payslip, a Centrelink payment, or a super account.

These documents were precisely the ones targeted in three large data breaches in the past year: at Optus[3], at Medibank[4], and at Latitude Financial[5].

Read more: Why are there so many data breaches? A growing industry of criminals is brokering in stolen data[6]

In this scam, the cyber criminal creates a fake myGov account using the stolen documents. If they can also get enough information to link to the ATO or your Tax File Number, they can then change bank account details to have your tax rebate paid to their account.

It is a sadly simple scam.

How government can improve

One of the issues here is quite astounding. The ATO knows where salaries are paid, via the “single touch[7]” payroll system. This ensures salaries, tax and superannuation contributions are all paid at once.

Most people who have received a tax refund will have provided bank account details where that payment can be made. Indeed, many people use precisely those bank account details to identify themselves to myGov.

A photo showing several Medicare cards.
Medicare information is commonly used for identification purposes. Dave Hunt / AAP

At present, those bank details can be changed within myGov without any further ado. If the ATO simply checked with the individual via another channel when bank account details are changed, this fraud could be prevented. It might be sensible to check with the individual’s employer as well.

Part of the problem is the ATO has not been very transparent about the risks. If these risks were clearly set out, then calls for changes to ATO procedures would have been loud and clear from the cyber security community.

The ATO is usually good at identifying when a cyber security incident may lead to fraud. For example, when the recruitment software company PageUp was hacked in 2018[8], the ATO required people who may have been affected to reconfirm their identities. This was done without public commentary and represents sound practice.

Sadly, the millions of records stolen in the Optus, Medibank and Latitude Financial breaches have not led to a similar level of vigilance.

Another action the ATO could take would be to check when a single set of bank account details is associated with more than one myGov account.

A national digital identity would also help. However, this system has been in development for years, is not universally popular, and may well be delayed[9] until after the federal election due in 2024.

Read more: Australia's National Digital ID is here, but the government's not talking about it[10]

Protecting yourself

The most important thing to do is make sure the ATO does not use a bank account number other than yours. As long as the ATO only has your bank account number to transfer your tax rebate, this scam does not work.

It also helps to protect your Tax File Number. There are only four groups that ever need this number.

The first is the ATO itself. The second is your employer. However, remember you do not need to give your TFN to a prospective employer, and your employer only needs your TFN after you have started work.

Your super fund and your bank may ask for your TFN. However, providing your TFN to your super fund or bank is optional – it just makes things easier, as otherwise they will withhold tax which you will need to claim back later.

Read more: 'We have filed a case under your name': beware of tax scams — they'll be everywhere this EOFY[11]

Of course, all the usual data safety issues still apply. Don’t share your driver’s licence details without good reason. Take similar care with your passport. Your Medicare card is for health services and does not need to be shared widely.

Don’t open emails from people you do not know. Never click links in messages unless you are sure they are safe. Most importantly, know your bank will not send you emails containing links, nor will the ATO.

Read more https://theconversation.com/the-500-million-ato-fraud-highlights-flaws-in-the-mygov-id-system-heres-how-to-keep-your-data-safe-210459

The Times Features

What are physician assistants? Can they fix the doctor shortage?

If you’ve tried to get an appointment to see a GP or specialist recently, you will likely have felt the impact of Australia’s doctor shortages[1]. To alleviate workforce sho...

Do men and women agree on how easy it is for each other to find a job or a date?

Typically, you don’t have to write a cover letter before attending a candlelit dinner. But there are some eerie emotional parallels between finding a job and finding a date. ...

Australia’s clinical guidelines shape our health care. Why do so many still ignore sex and gender?

You’ve heard of the gender pay gap. What about the gap in medical care? Cardiovascular diseases – which can lead to heart attack and stroke – are one of the leading causes[1...

Don't Get Burned—Smart Insurance for Your Investment Property

Real estate investment offers lucrative opportunities even though it brings operational risks. Real estate investment protection fundamentally depends on obtaining the correct insu...

Why it’s important to actively choose the music for your mood

Many of us take pleasure in listening to music[1]. Music accompanies important life events and lubricates social encounters. It represents aspects of our existing identity, a...

The Link Between Heart Health and Ageing Well

Millions of Australians are at risk of heart disease, but fewer realise that keeping their heart healthy can also help protect their brain, memory, and cognitive function, redu...

Times Magazine

Improving Website Performance with a Cloud VPS

Websites represent the new mantra of success. One slow website may make escape for visitors along with income too. Therefore it's an extra offer to businesses seeking better performance with more scalability and, thus represents an added attracti...

Why You Should Choose Digital Printing for Your Next Project

In the rapidly evolving world of print media, digital printing has emerged as a cornerstone technology that revolutionises how businesses and creative professionals produce printed materials. Offering unparalleled flexibility, speed, and quality, d...

What to Look for When Booking an Event Space in Melbourne

Define your event needs early to streamline venue selection and ensure a good fit. Choose a well-located, accessible venue with good transport links and parking. Check for key amenities such as catering, AV equipment, and flexible seating. Pla...

How BIM Software is Transforming Architecture and Engineering

Building Information Modeling (BIM) software has become a cornerstone of modern architecture and engineering practices, revolutionizing how professionals design, collaborate, and execute projects. By enabling more efficient workflows and fostering ...

How 32-Inch Computer Monitors Can Increase Your Workflow

With the near-constant usage of technology around the world today, ergonomics have become crucial in business. Moving to 32 inch computer monitors is perhaps one of the best and most valuable improvements you can possibly implement. This-sized moni...

Top Tips for Finding a Great Florist for Your Sydney Wedding

While the choice of wedding venue does much of the heavy lifting when it comes to wowing guests, decorations are certainly not far behind. They can add a bit of personality and flair to the traditional proceedings, as well as enhancing the venue’s ...

LayBy Shopping