Over 70,000 Fake Bank Scam Emails Flood Aussie Inboxes
BBB Team

A  highly sophisticated callback scam has been uncovered, which cybercriminals are posing as Australia’s Big Four banks to defraud companies across the education, legal, and insurance sectors. In July 2025 alone, more than 70,000 scam attempts were detected, with many more likely undetected and ongoing.

Banks Impersonated and Sectors Targeted

Mimecast’s Threat Research Team identified that scammers are impersonating major Australian banks including Westpac, Commonwealth Bank, and Macquarie, with hyper-realistic notifications in an attempt to trick unsuspecting victims into calling fraudulent support numbers. The criminals, from undisclosed locations, are targeting high-value institutions, the majority being in the education sector, but also the legal and insurance sectors.

“These attacks stand out from the rest because of the precision by the attackers towards high-value targets such as large universities and top law firms. Also, because of the attention to detail by the scammers when creating the fraudulent bank notifications,” said Garrett O’Hara, Senior Director, Solutions Engineering at Mimecast.

How the Scam Operates

The attack methodology centred on sophisticated email templates designed to mimic legitimate bank account statements. Recipients receive professionally crafted emails showing unauthorised transactions of around $1,500, creating immediate urgency and concern.

The emails contain specific transaction details including the fake merchant names of ‘Infinite Holdings’ or ‘Smart Apps’, or Victorian locations such as Lockington and Pomonal, along with authentic-looking reference codes.

The emails prompt recipients to call phone numbers that were controlled by scammers, who then impersonate bank representatives to extract personal financial details or direct victims to make fraudulent transfers.

“This campaign is particularly concerning because it blends two powerful tactics – the trust Australians place in their banks and the urgency created by fraudulent transaction alerts,” said Garrett O’Hara, Senior Director Solutions Engineering at Mimecast. “The impersonation of Australian banks combined with a callback request makes this a highly effective and worrying evolution of social engineering scams.”

An Evolving Threat Landscape

While callback scams are not new, they have traditionally involved fake subscription notifications from services like PayPal. Mimecast’s latest threat intelligence indicates a significant shift towards bank impersonations as emails, and the notifications becoming increasingly realistic.

“We see this threat evolving to target a much larger number of Australians, so awareness about it is very important,” Garrett added.

Recognising the Warning Signs

The warning signs and common traits of this scam include the subject lines of ‘Alert Completed Details Enclosed,’ ‘Financial Summary Sent Recently,’ ‘Invoice Completed Recently,’ or ‘Your Recent Payment: Summary Notification’. The fraudulent contact numbers used by scammers include ’03 8256 7521’, 02 5621 1059’, and ‘1800 458 259’.

“Legitimate banks will not request urgent callbacks via email,” Garrett added. “Organisations should require staff to independently verify banking communications through official bank channels and ensure that any phone numbers are checked against legitimate banking contact details.

“The scale of the attack we have detected demonstrates that Australian businesses are firmly in the sights of scammers. Organisations that proactively train staff and put in place strong verification processes will be far better placed to avoid falling victim.”

Reporting and Support

Anyone who believes they’ve been targeted should contact police, report it to ScamWatch.gov.au, or call the national cyber security hotline at 1300 CYBER1 (1300 292 371). Reports can also be made at cyber.gov.au

Author

  • BBB Team

    The BBB Team look after Business Business Business and help our business owners, learn, connect, network and do.

Related Articles

Create Stunning Business Videos in Minutes with Animoto

Create Stunning Business Videos in Minutes with Animoto

Animoto is the game-changer you’ve been waiting for. It’s a drag-and-drop video maker designed for busy people who need professional business videos without the steep learning curve. Stop putting off video marketing because it feels too hard or too expensive.

Blueprint to Your First 100 Followers

Blueprint to Your First 100 Followers

Getting your first 100 followers feels impossible because you lack momentum. It’s not about luck; it’s about strategy. This blueprint cuts through the noise, offering practical steps, from leveraging your existing circle to smart commenting, to move past zero and start growing your brand with intention.

Smart Tax Planning in Australia: Beyond 30 June Tactics

Smart Tax Planning in Australia: Beyond 30 June Tactics

If your tax planning starts in late May, you’re already behind. Smart tax planning in Australia isn’t about last-minute deductions. It’s about understanding timing and character, not just income amounts.

Pin It on Pinterest

Share This