24/05/2024
We have been advising customers (for a while now) to not just scan random QR codes. You just do not know where they will take you.
This one for example, takes you to a page that looks like the My.Gov.au website. However, it's not.
Even with Multi Form Authentication (MFA) they can intercept (various means) and hijack the MFA. Basically, if it doesn't have your number in it (maybe some numbers are blocked out) then don't enter your details.
Know how to spot a scam
• The sent from email address
o This one is not from a .gov.au address
o Sometimes it may show the email address you expect, however if you go over the email address the return address may be different
• Government agencies, don’t (usually) send links (QR codes) in email
o They want you to go to the website yourself so you know you are going to the right place
• There’s usually spelling mistakes or grammatical errors
o You wouldn’t believe how many checks they go though for Government emails
• This QR code takes you to an website that has taken all the log in details from MyGov and does look real
o In your browser check the address before entering any log in information
o I wouldn’t normally click on any links, however you can hover over them on a computer and see where they will take you, this one just opens another window and takes you to the same page
• If in doubt, don’t do it.
o We all can get caught out, I know I have clicked something and then went “what are you doing”
o Contact who the email is meant to be from
Don’t use the contact details in the email or the website it has taking you to, look it up yourself.