ATO confirms some systems targeted by fraudulent actors
What happened
The ATO confirmed malware delivered via malicious links has affected some tax practitioners and says its own systems were not compromised. The scam vector is inbound communications—job applications, CVs and emails—that can install unauthorised software and expose agent accounts; practitioners are advised to report suspected breaches. Watch supplier notifications and credential or access changes tied to agent services for operational impact
Why the category manager should care
Prioritise verification of suppliers that integrate with ATO agent services and require evidence of endpoint controls before routing sensitive payroll or lodgement work
Key facts
- Malware delivered via malicious inbound links (job applications, CVs, emails)
- ATO recommends affected practitioners report breaches using published guidance