Fraud protection.
Now it's personal.
ANZ Falcon® technology monitors millions of transactions every day to help keep you safe from fraud.
Falcon® is a registered trademark of Fair Issac Corporation.
Stay informed on the latest scams, fraud, and security alerts. Learn about emerging cyber threats and important online risks as they arise. If you are a business, make sure to stay updated with the latest business security alerts that could impact you.
Explore the latest alerts below, and make informed decisions to help keep your personal and banking details safe.
Businesses: See latest security alerts
Posted on 16 July 2025
Type:
We would like to remind our customers to be wary of scams involving digital wallets.
Digital wallets allow you to make transactions with your mobile or wearable device instead of a physical card.
While digital wallets are safe, if scammers have access to your card details and one-time passcodes (OTP), they can add your card to their own device (or third party) and spend or withdraw your money without your permission.
Type:
We have been made aware of an increase in bank impersonation scams. Be cautious of SMS messages or phone calls, claiming to be from ANZ. They may ask you to transfer money, open another account, provide your sensitive banking details or click on a link.
Remember, we will never ask you to:
Type:
The ASD's ACSC has published a critical alert regarding vulnerabilities within Australia impacting Cisco ASA 5500-X Series models, that are running Cisco ASA Software or FTD software:
A number of versions of Cisco software releases are affected, including those within the following ranges:
Type:
The ASD's ACSC has published a high alert regarding increased targeting of online code repositories.
Threat actors have been observed gaining access to online code repositories and have been noted to do the following after gaining access to privileged systems and accounts:
This access provides threat actors a better understanding of internal processes and systems, increasing an organisation’s attack surface and enabling future, novel attacks.
Type:
The ASD's ACSC has published a critical alert regarding vulnerabilities affecting SonicWall SSL VPNs in Australia (CVE-2024-40766)
According to the ASD’s ACSC, the vulnerability can result in Akira ransomware targeting vulnerable Australian organisations through SonicWall SSL VPNs.
The vulnerability enables an attacker to achieve unauthorised access and in specific conditions causes the firewall to crash. The vulnerability affects the following SonicWall devices:
Posted on 01 September 2025
Type:
The ASD's ACSC has published an alert regarding multiple vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) products:
Citrix reports active exploitation of these vulnerabilities has been observed.
Type:
We have seen an increase of cyber criminals gaining unauthorised access to data stored in customer relationship management (CRM) systems through social engineering.
Social engineering is a tactic used by cyber criminals to extract sensitive information, often via social media or phone calls (“vishing”). This data may be used to impersonate employees or vendors to gain access to company information or systems. Attackers typically exploit emotions like fear, urgency, or excitement to pressure individuals into bypassing standard procedures. If a communication seems suspicious or asks for unusual actions, avoid sharing information, uphold business security protocols, and end the interaction immediately.
Posted on 21 July 2025
Type:
The ASD's ACSC has published a critical alert regarding vulnerabilities affecting Microsoft Office SharePoint Server products (CVE-2025-53770).
According to the ASD’s ACSC, the vulnerability may allow an unauthorised attacker to execute code over a network.
Posted on 10 July 2025
Type:
The ASD's ACSC has published an alert regarding 2 vulnerabilities affecting Citrix Netscaler ADC and NetScaler Gateway Products.
The following vulnerabilities have been identified:
According to the ASD’s ACSC, these vulnerabilities can lead to memory overflow issues, resulting in unintended control flow and Denial of Service due to insufficient input validation.
Posted on 23 June 2025
Type:
The ASD's ACSC has sent a critical alert relevant to Australian organisations using Citrix Netscaler ADC and NetScaler Gateway Products (CVE-2025-5349 and CVE-2025-5777).
Citrix has identified the following vulnerabilities affecting Netscaler ADC and NetScaler Gateway Products:
App Store is a service mark of Apple Inc. Google Play and the Google Play logo are trademarks of Google LLC