June 30 means a lot of things for Australian businesses. Reconciliations, super contributions, invoices to get out the door, BAS lodgements to finalise. It's a busy, pressured period where decisions get made quickly and emails get acted on without a second glance.
Cybercriminals know this. And every year, they plan for it.
The lead-up to the end of financial year is consistently the peak period for scams and cyber attacks targeting Australian businesses. The combination of financial pressure, high transaction volumes, and staff trying to clear their desks before June 30 creates exactly the kind of environment where a well-timed phishing email can do serious damage. Banks, cyber security researchers and government agencies are all warning businesses to be on high alert right now.
Why EOFY Is Such an Attractive Window for Scammers
It comes down to opportunity. At this time of year, businesses are transferring money, paying suppliers, processing payroll runs, chasing outstanding invoices and managing superannuation obligations. There's more financial activity happening than at any other point in the calendar, and the stakes are higher for everyone involved.
That heightened activity creates cover. A fraudulent invoice that arrives in a busy accounts inbox during EOFY chaos is far more likely to get processed without scrutiny than the same email sent in February. Scammers are not just opportunistic, they are strategic, and they deliberately time their campaigns to land when businesses are at their most stretched.
Business email compromise (BEC), fake invoice scams, and payment redirection fraud all spike significantly in May and June each year. These are not random attacks. They are targeted, timed, and often highly convincing.
What the Attacks Actually Look Like Right Now
The tactics in play this EOFY are more polished than they were even a couple of years ago. Here is what security researchers and banks are seeing most commonly:
Phishing emails impersonating the ATO, myGov and HR teams
These arrive looking like official correspondence. The sender name might be "Australian Taxation Office" or "myGov Notifications", the logo looks right, and the message references something plausible like a tax refund, an overdue lodgement, or a payment summary being available for download. The goal is to get you to click a link or open an attachment.
Security researchers have tracked well over 100 separate tax-themed phishing campaigns running globally during this period, with a significant number specifically targeting Australian recipients. The volume goes up every year.
The ATO will never email, SMS or contact you through social media to ask for personal or financial information, or to direct you to click a link. If a message claims to be from the ATO and asks you to do either of those things, it is a scam.
Fake login pages that steal more than just your password
When someone clicks the link in a phishing email, they are typically taken to a convincing replica of a myGov, ATO or Microsoft 365 login page. These pages are not just capturing passwords. Many of them now operate as real-time relays, meaning they pass your credentials directly to the attacker's system the moment you type them in, request the actual multi-factor authentication (MFA) code from the real service, and then show you a fake error while they use your session in the background.
This is why MFA alone is no longer a complete defence against phishing. If someone enters their credentials on a fake site, the attacker can capture the MFA code in the same session before it expires. A successful attack of this kind can give a criminal access to your email, cloud storage, financial accounts, and anything else connected to that login.
Remote access software installed without the victim realising
Another common attack chain involves persuading someone to install a remote access tool under a false pretext. A call from "ATO compliance", a follow-up email from "IT support", or an attachment described as a "tax declaration form" can all be used to get legitimate remote access software installed on a business device.
Once that software is running, the attacker has quiet, persistent access to everything on that machine. They can observe activity, harvest credentials saved in browsers, access financial systems, and move funds. Many victims do not discover anything is wrong until bank statements arrive.
You Do Not Need to Make It Complicated
One thing worth saying plainly: some of the most effective protective measures are also the most straightforward. Before worrying about sophisticated security tooling, make sure the basics are genuinely in place across your business.
Password hygiene is a good example. Analysis of compromised Australian business accounts consistently shows that huge numbers of them are protected by passwords like "admin", "password" or "123456". These are not edge cases. Tens of thousands of accounts use variations of these, and attackers have automated tools that try them within seconds of obtaining a username or email address.
A strong password is long, random and unique to each account. If remembering that across dozens of systems sounds impractical, that is exactly what password managers are built for. They generate and store strong credentials for you, so there is no reason to reuse anything.
Enabling multi-factor authentication on your email, Microsoft 365 and any business banking systems should be treated as non-negotiable at this point. It is not a perfect defence against everything, but it blocks the vast majority of automated attacks cold.
5 Practical Steps to Protect Your Business This EOFY
-
1Treat unsolicited messages with suspicion by default The ATO does not request personal or financial information by email, SMS or social media, and it will not direct you to click a link to verify your details. If a message claiming to be from a government agency asks you to do any of these things, do not engage with it. Report it to Scamwatch and delete it.
-
2Never trust a phone number that calls you Scammers can spoof caller ID to display legitimate-looking numbers. If you receive an unexpected call from someone claiming to be the ATO, your bank or even your IT provider, hang up and call the organisation back using a number you find independently on their official website. Genuine ATO calls display as "No Caller ID" and the agency will never threaten immediate legal action or demand payment over the phone.
-
3Slow down when someone is trying to rush you Creating urgency is one of the oldest tricks in the scammer's playbook. "Your account will be suspended in 24 hours", "immediate action required before June 30", "your refund will be cancelled if you do not verify now". These phrases are designed to short-circuit your judgement. A legitimate organisation will give you time to verify their identity. If something feels rushed, that is a reason to stop, not to hurry up.
-
4Verify any changes to payment details out of band Payment redirection fraud, where scammers intercept or impersonate a supplier to redirect payment to a different account, is common at EOFY when invoices are flying around. If a supplier, contractor or employee contacts you to update their bank details, always confirm the change by calling a known number for that person or business before processing any payment.
-
5Make sure your team knows what to watch for Most successful attacks reach businesses through their people, not through technical gaps. A five-minute team briefing before the end of June reminding staff about EOFY scams, what the ATO does and does not do, and who to contact if something looks suspicious can make a genuine difference. Your staff are the last line of defence, but they need to know what to look for.
The Bigger Picture for Melbourne Businesses
EOFY is a useful moment to take stock of your cyber security posture more broadly. The same gaps that make a business vulnerable to tax-time phishing make it vulnerable year-round. Weak passwords, no MFA, staff with no security awareness training, and no monitoring in place are not just an EOFY problem.
If your business does not have a clear picture of what protections are in place and where the gaps are, now is a good time to find out. The BITS team works with Melbourne businesses to assess their security baseline, close the most critical gaps, and put ongoing monitoring in place so that problems get caught before they become expensive.
If you want to talk through where your business stands, get in touch with the BITS team. We are happy to have an honest conversation about what is and is not in place, without the sales pitch.