Favicon
Media Releases

Australians urged to be alert for impersonation scams following record data breaches

By COBA
|

The Customer Owned Banking Association (COBA) is urging Australians to be vigilant following an increase in scam attempts due to recent data breaches.

When a data breach happens, hackers steal pieces of customers’ personal information. They might not get the entire bank account or card number, but they often get fragments – like a BSB number or the last three digits of a debit card or account number.

“We are seeing a surge in criminals impersonating bank staff and fraud departments, leveraging partial information from recent data breaches to pose as legitimate employees,” explained Martin Latimer, COBA’s Head of Financial Crimes and Cyber Resilience.

“A scammer will call you, pretending to be from your bank or a trusted company. To ‘prove’ they are who they say they are, they will read those stolen fragments back to you and ask you to confirm them, which is how they can often convince unsuspecting individuals that their call is genuine,” he added.

Once trust is established, the scammer may manipulate the customer into resetting their internet banking passwords and sharing their One-Time Password (OTP) under the guise of fraud protection, ultimately gaining full access to their accounts.

“Your customer-owned bank will never request your OTP, your online banking password or PIN over the phone, so it’s important to remain vigilant,” Latimer advised.

According to the Office of the Australian Information Commissioner (OAIC), Australia had a record number of data breaches in 2025 with over 1,205 data breach notifications.

To help you stay safe, COBA’s financial crimes team shares expert tips on what to do if your data has been leaked and how to protect yourself from scammers.

If you’re notified or suspect that your data has been compromised, you should immediately secure your accounts.

“If the notification you receive mentions a compromised email account, change the password immediately. If an impacted website is mentioned, change your login password and on any other sites where you might have reused it,” Latimer advises.

This leads to his next piece of advice: password best practice.

“We know how tempting it is to use the same password everywhere, but it’s your biggest security risk. Every single account needs its own unique, strong password. A password manager can make this surprisingly simple,” he says.

He also strongly recommends adding layers of protection to your most sensitive accounts, including activating two-step verification (2FA) for your personal email and all other online accounts, where available.

Following a data breach, it’s important to check your email regularly for alerts and notifications about your accounts.

Monitor for account activity, such as unauthorised logins, unexpected password reset notifications, and a sudden increase in the number of phishing emails. These are all signs that you could be the victim of a new data breach or that details from an old one have been sold.

“Even if the information isn’t used immediately, it can be sold and resold for future attacks, so you need to vigilant both in the immediate aftermath and on an ongoing basis,” Latimer advised.

When there has been a data breach, scammers will use the compromised information to launch targeted attacks, so it’s crucial to stay alert.

“Scammers use stolen contact details to launch phishing attacks via email, text message, or phone call. They might impersonate the organisation that was breached, or they may use the name of a trusted entity or a government agency. They might pretend to be from your bank. The aim is to get you to share your private information, or to click on a link,” Latimer explains.

If a sender or caller claims to be from your bank or a company, Latimer advises verifying their identity by contacting your bank or the company back on a number you sourced yourself from their official website. Never provide your online account passwords or any personal or financial information to unsolicited callers or contacts, even if they say they are from your bank.

STOP  – Don’t give personal information to anyone if you’re unsure. Scammers often create a sense of urgency to pressure you.

CHECK  – Ask yourself if the call, text, or email could be fake. Scammers are experts at impersonating organisations you know and trust.

PROTECT  – If you suspect an impersonation scam, terminate contact with the suspected scammer and call the genuine person or organisation on a number you have obtained yourself from a trusted source.

Reporting a scam is important to protect others and stop these criminals. Report the scam to National Anti-Scam Centre – Scamwatch.

ENDS

For further information or to arrange interviews, please contact Mira Palomaki on 0459 954 035 media@coba.asn.au

The Customer Owned Banking Association is the industry body for mutual banks, credit unions and building societies. For almost 180 years our sector has put customers first, returning profits to more than 5 million Australians who put their trust in customer-owned banks.

Hear it first

Four times a year we’ll send you helpful banking tips and inspiring stories from our members.