Fraud protection.
Now it's personal.
ANZ Falcon® technology monitors millions of transactions every day to help keep you safe from fraud.
Falcon® is a registered trademark of Fair Issac Corporation.
Stay informed on the latest scams, fraud, and security alerts. Learn about emerging cyber threats and important online risks as they arise. If you are a business, make sure to stay updated with the latest business security alerts that could impact you.
Explore the latest alerts below, and make informed decisions to help keep your personal and banking details safe.
![]()
Businesses: See latest security alerts
![]()

Posted on 27 November 2025
Type:
Scammers are sending extremely convincing fake emails pretending to be from Services Australia and Centrelink. These scams have already hit over 270,000 inboxes nationwide targeting a wide range of organisations including schools, hospitals, law firms, corporations, and even government agencies.
The emails look real and often mention various Australian benefit systems like Superannuation or Family Tax Benefits. These emails are mostly written and sent using various techniques to avoid security or spam filters.
They deceive people into clicking links and entering personal details, which can lead to identity theft, account compromise, or even ransomware attacks.

Posted on 13 November 2025
Type:
A scam has been identified where individuals are receiving SMS messages impersonating ANZ Rewards. These messages may claim that rewards points are about to expire and include a link to redeem them.
Be cautious of SMS messages, emails or phone calls, claiming to be from ANZ. They may ask you to log in to your account through a link, provide sensitive banking details, download software, transfer money or open another account.
Remember, we will never ask you to:
![]()

Posted on 06 November 2025
Type:
ASD’s ACSC has identified corporate network breaches that started in employees accessing work resources or systems from personal devices infected with malware called information stealers.
Info stealers, are a type of malware designed to collect information from a victim’s device.
Organisations that allow employees, contractors, managed service providers or other entities to access their network remotely, including with Bring Your Own Device (BYOD) hardware, need to be aware of the risks and protect themselves from this threat.

Type:
The ASD's ACSC has published a critical alert regarding the following vulnerability in the Microsoft Windows Server Update Service:
The vulnerability impacts Microsoft Windows Server Update Service in Windows Server (2012, 2016, 2019, 2022 and 2025).

Posted on 17 October 2025
Type:
The ASD's ACSC has published a critical alert regarding multiple high-severity vulnerabilities in F5 products and an incident impacting F5.
According to the ASD’s ACSC, F5 have released an advisory regarding a cyber security incident that has affected certain F5 systems with recommendation on what customers can do to help protect themselves.
In addition to this advisory, F5 has issued its October 2025 quarterly security notification summarising multiple critical vulnerabilities identified across its product portfolio.

Type:
The ASD's ACSC has published a critical alert regarding vulnerabilities within Australia impacting Cisco ASA 5500-X Series models, that are running Cisco ASA Software or FTD software:
A number of versions of Cisco software releases are affected, including those within the following ranges:

Type:
The ASD's ACSC has published a high alert regarding increased targeting of online code repositories.
Threat actors have been observed gaining access to online code repositories and have been noted to do the following after gaining access to privileged systems and accounts:
This access provides threat actors a better understanding of internal processes and systems, increasing an organisation’s attack surface and enabling future, novel attacks.

Type:
The ASD's ACSC has published a critical alert regarding vulnerabilities affecting SonicWall SSL VPNs in Australia (CVE-2024-40766)
According to the ASD’s ACSC, the vulnerability can result in Akira ransomware targeting vulnerable Australian organisations through SonicWall SSL VPNs.
The vulnerability enables an attacker to achieve unauthorised access and in specific conditions causes the firewall to crash. The vulnerability affects the following SonicWall devices:

Posted on 01 September 2025
Type:
The ASD's ACSC has published an alert regarding multiple vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) products:
Citrix reports active exploitation of these vulnerabilities has been observed.
![]()
App Store is a service mark of Apple Inc. Google Play and the Google Play logo are trademarks of Google LLC