Buying your next home?
See our home loan tools, articles and resources to help you explore your home loan options. We'll help you get to a good place.
Stay informed on the latest scams, fraud, and security alerts. Learn about emerging cyber threats and important online risks as they arise. If you are a business, make sure to stay updated with the latest business security alerts that could impact you.
Explore the latest alerts below, and make informed decisions to help keep your personal and banking details safe.
Businesses: See latest security alerts
Type:
Although cheque usage is less common today, there are still instances where fraudsters deposit fake cheques into ATMs as part of schemes targeting individuals selling goods.
In these scenarios, a fake cheque is deposited into the seller’s account which may temporarily make it appear that funds have been received. However, the cheque has not actually cleared. This can lead the seller to believe the payment is valid and release the goods, only to later discover that the cheque was dishonoured.
Type:
Investment scams are on the rise, and they’re becoming more convincing than ever. Many of these scams begin with ads on social media that appear to be endorsed by well-known and trusted public figures.
Once you engage, the scammer may introduce what sounds like an incredible opportunity to grow your money —often promising returns that are far higher than what you’d expect from a genuine investment. Sometimes, though, the offer might only seem slightly better than what you're currently getting, making it even more convincing and harder to detect.
Here’s what to look out for:
Type:
Individuals and businesses should be aware of increased scam activity as sophisticated cyber criminals take advantage of the busy tax period. During this busy time, scammers may use sophisticated tactics to try and catch you off guard. There are various types of scams, and the intent is clear - they want to steal your money or personal information.
Cyber criminals attempt to take advantage of this time of year with tax-related impersonation scams, namely those appearing to originate from the Australian Tax Office (ATO) or other government services such as myGov.
If you are unsure about the authenticity of a call or message, contact the ATO or applicable government service to verify.
For more information about rebate, refund and EOFY scams visit Rebate and refund scams online.
Posted on 17 April 2025
Type:
Malware is any kind of malicious software or code designed to exploit a computer, including computer viruses, worms, trojans, spyware or other malicious programs. Malware can be installed on a device without the user's knowledge or permission, often through email attachments, malicious websites, or compromised software.
To help protect our customers, ANZ uses security software that may detect if malware is present. If malware is detected, ANZ might lock your CRN from accessing Internet Banking. To get your CRN unlocked and proceed with Internet Banking, you will need to contact us.
Posted on 23 June 2025
Type:
The ASD's ACSC has sent a critical alert relevant to Australian organisations using Citrix Netscaler ADC and NetScaler Gateway Products (CVE-2025-5349 and CVE-2025-5777).
Citrix has identified the following vulnerabilities affecting Netscaler ADC and NetScaler Gateway Products:
Posted on 19 May 2025
Type:
The ASD's ACSC has published an alert regarding 2 vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM).
The 2 vulnerabilities the ASD's ACSC is tracking in Ivanti EPMM are:
When chained together, these vulnerabilities can provide unauthenticated attackers Remote Code Execution.
All versions of Ivanti EPMM prior to and including 12.5.0.0 are vulnerable.
Posted on 17 April 2025
Type:
The ASD's ACSC has published a critical alert regarding vulnerabilities affecting exploitation of existing Fortinet Vulnerabilities.
Customers are encouraged to update their devices and investigate for potential compromise.
Fortinet has released information regarding their observation of active exploitation of previously known vulnerabilities affecting Fortinet devices, including:
Fortinet have previously released patches for these vulnerabilities.
The observed post exploitation activity relates to either unpatched devices or those that were compromised prior to patching.
Posted on 08 April 2025
Type:
The ASD's ACSC has published a critical alert regarding vulnerabilities affecting Pulse/Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways (CVE-2025-22457).
Ivanti has released information regarding a critical unauthenticated buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways (CVE-2025-22457).
Ivanti has observed active exploitation associated with this vulnerability.
Affected products include:
Pulse Connect Secure 9.1X is end of support as of 31 December 2024.
App Store is a service mark of Apple Inc. Google Play and the Google Play logo are trademarks of Google LLC