10 February, 2016
09:47 AM


RSS Feed


Banks targeted by SMS phishing scam

By Editor


We are warning all mobile phone users of a persistent and sophisticated SMS phishing campaign currently underway that is targeting mobile banking customers in both Australia and New Zealand.

The SMS messages are short and to-the-point, containing URLs that direct the recipient to a fake mobile banking website, which is almost indistinguishable from the real thing.

The sophistication and scope of the campaign is indicated by the extensive use of internet domains that closely resemble the legitimate domains of Australian and New Zealand banks. Often these domains will be active for only a very short time, replaced shortly thereafter with another ‘plausible’ bank domain.

For example, the ACMA has received reports of SMS targeting ANZ bank customers as follows*

  • Account notification: hXXp://m.anzmobilebank. com/
  • Account notification: Verify your identity hXXp://m.anzmobilebank. com/
  • Account Notification: hXXp://anz-notification. Com
  • Account Notification: hXXp://mobile-anz. Info
  • Dear ANZ Customer, Notification: hXXp://anz-mobile. Center
  • Internal message received: hXXp:/anzmobilebank. com
  • Notification: hXXp://anz-mobile. Center
  • Verify your identity: hXXp:/anzmobilebank. com

If the URL is followed, the customer will be presented with a fake website presenting a series of webpages.

The following screenshots are examples of a current and sophisticated fake ANZ mobile banking website scam. You can see how legitimate each screen looks, especially as they’ve tried to tailor their design to reflect the same ‘look’ and ‘feel’ of the ANZ bank’s branding.

ANZ mobile banking scam screenshot jpg

Many Australian and New Zealand banks are being targeted by this constantly evolving campaign.

It appears that the criminals behind this campaign are constantly refining their messages and the associated fake imitation banking websites to increase their chance of success. In the fake ANZ mobile banking website scam, you can see how they have even used a fake ‘loading’ page to simulate standard mobile banking transactions.

We have direct evidence of the extent of the current SMS phishing campaign, thanks to Australian consumers who have received these SMS messages and reported them to our SMS spam reporting number, 0429 999 888. These reports have also enabled us to assess how the technical aspects of the campaign are evolving and how the criminals are progressively targeting different Australian banks. The current list of unique SMS phishes related to this campaign are listed at the end of this blog.

If you have even the slightest concern that you may have inadvertently responded to one of these phishes and passed on your banking credentials or personal information to the criminals behind the campaign, we recommend that you immediately contact your financial institution to seek their advice. We also recommend that you report the incident to the government’s Australian Cybercrime Online Reporting Network.

Useful tips to help stay protected

To help minimise your chances of being duped by these and other phishing campaigns, we recommend that you:  

  • don’t open SMS or emails from unknown or suspicious sources
  • never follow hyperlinks contained in these messages
  • always carefully check the authenticity of a website that requests your user credentials
  • never reuse the same login credentials on any web service
  • where available, use two-factor authentication on your accounts.

We encourage all Australian consumers to forward any suspicious or spam-related SMS messages to our hotline on 0429 999 888.

More information

Visit the Australian Government’s Stay Smart Online website to help educate yourself on the ways you can avoid having your personal information compromised.  

Subscribe to our Cybersecurity news to keep up-to-date with the latest trends from the Australian Internet Security Initiative (AISI). This has a particular focus on malware, phishing and botnet activities.

We also provide statistical information on our other cyber security activities, with detailed trend data on malware reports and service vulnerabilities currently being reported through our AISI program.

SMS messages reported to the ACMA associated with this phishing campaign

You can find a full list of all the SMS messages targeting Australian financial institutions that have been reported to us by Australian consumers below.

We have reported all these SMS messages to each of the affected financial institutions.


  • Account notification: hXXp://m.anzmobilebank. com/
  • Account notification: Verify your identity hXXp://m.anzmobilebank. com/
  • Account Notification: hXXp://anz-notification. Com
  • Account Notification: hXXp://mobile-anz. Info
  • Dear ANZ Customer , Notification: hXXp://anz-mobile. Center
  • Internal message received hXXp:/anzmobilebank. com
  • Notification:  hXXp://anz-mobile. Center
  • Verify your identity http:/anzmobilebank. com

Bank of Queensland:

  • Bank of Queensland Support: Update your profile: hXXp://boq-mobile. Net
  • Message received from BOQ Support hXXp://boq-mobile. Net
  • Dear Bank of Queensland customer, You have received an internal notification. hXXp://boq-mobile. Net
  • Verify your identity hXXp://boq-mobile. net

Bendigo Bank:

  • 1 new Secure Email hXXp://mobile.bendigobank. info
  • Account notification hXXp://bendigo-bank. mobi
  • Account review hXXp://mbendigobank. com
  • Account verification hXXp://mbendigobank. com
  • Customer review  hXXp://mbendigobank. com
  • Dear Customer, You have received a payment. Login Bendigo MobileBank: hXXp://m.bendigo. online
  • New payment received hXXp://mobile.bendigo. online
  • Message received hXXp://bendigo-bank. mobi
  • Notification: Payment received hXXp://mobile.bendigobank. info
  • Payment received. Access your online statement. hXXp://mobile.bendigo. online

GE Money:

  • New payment received hXXp://www.gemoneymobile. net
  • You have 1 message from customer support hXXp://www.gemoneymobile. net

Heritage Bank:

  • Heritage Bank Notification hXXp://heritagebank. mobi

Macquarie Bank:

  • Dear customer, Confirm your mobile phone number: hXXp://macquarie-mobile. com


  • Account notification hXXp:// com
  • Account notification hXXp://nab-login. com/
  • Account security notification hXXp://nab-login. com/
  • Dear NAB Customer, You have received an internal notification. hXXp:// direct
  • Dear NAB Customer, You have received an internal notification. hXXp://online.mobilenab. com
  • Dear NAB Customer, You have a new message. hXXp:// direct
  • Dear NAB Customer, You have received a notification. hXXp:// direct
  • Verify your identity: hXXp://nab-mobile. net
  • Notification:  hXXp://mobile-nab. net
  • Internal message received hXXp:// direct
  • Notification:  hXXp://nabmobile. info
  • Notification:  hXXp:// net
  • Your online statement is ready hXXp:// net
  • Verify your identity: hXXp://nab-m. com
  • Verify your identity hXXp://nab-login. com/

St George:

  • Business account notification #2912 hXXp://stgeorge-mobile. com
  • Dear Business Customer, You have received a new alert from StGeorge Bank  hXXp://stgeorge-mobile. com
  • Dear Customer,  You have received a notification from StGeorge Bank hXXp://bbonline.stgeorge-mobile. com
  • St.George Bank notification #882 hXXp://bbonline.stgeorge-mobile. com
  • StGeorge Bank: account notification #441 hXXp://bbonline.stgeorge-mobile. com

Suncorp Bank:

  • Notification received hXXp://mobile.suncorpbank. net/



*We have slightly altered the original URLs to protect against inadvertent use of these links.

Add your comments
  • Maureen Hunt

    12/02/2016 12:33:20 PM

    I received a link on my mobile yesterday at 2:15pm, it read:
    I did not click on link but I have entered the URL on the internet and an internet banking Login page appeared:
    Welcome to NAB Internet Banking on your mobile. Full version.
    NAB ID
    Forgot your password?
    Register for NAB Internet Banking
    Terms of use
    I deleted the text.
    It may not be a scam but I have no reason for NAB to be contacting me.
  • Phillip Daddy

    24/03/2016 2:38:54 PM

    I am not a customer but today I received the following Phishing SMS :
    "ANZ Account Locked.
    Click the button below to unlock your account"
    • In reply to Phillip Daddy

      The ACMA

      31/03/2016 11:10:09 AM

      Hi Phillip, well done on spotting the fake URL. Delete the SMS immediately!
  • Catherine

    31/03/2016 12:07:06 PM

    i have received text from westpac +61447125396 saying i had received a notification with the  following link,
    i am not a westpac customer so i suspect it is a scam, regards Catherine
    • In reply to Catherine

      The ACMA

      1/04/2016 11:17:23 AM

      Hi Catherine, good call to be careful, especially when you're not a customer! 
  • Alan Tolliday

    5/04/2016 8:49:18 AM

    I have this morning at 6am received a SMS containing the following URL  
    As I don't have any accounts with Westpac, I deleted the SMS. 
    I tried to check the URL on the net and Google Chrome blocked the site as unsafe. I Googled the URL name which lead me to this site, i.e. confirming what I thought, the SMS is a phishing scam.
  • Sharon Blennerhassett

    5/04/2016 11:17:27 AM

    I received a text from +1 844 710 5809 this morning telling me my Westpac account was ready to be viewed........I don't have an account with this bank. 
    I didn't open it just deleted it.
  • Jeremy Apps

    12/04/2016 3:29:38 PM

    Just reporting an SMS phishing attempt I just received on my work mobile:
    FROM: +61 476 929 269
    E*TRADE customers can now trade on the go. Track your portfolio and tap to buy, sell or modify your order using the Grow by ANZ app. Download at
    Not an ANZ customer.
  • The ACMA

    13/04/2016 8:19:11 AM

    A reminder that the Stay Smart Online Alert Service is a free service for Australian internet users, to explain recent online threats and how they can be managed.
    Click here to sign up to the alert service:
  • John HUNT

    4/05/2016 7:47:21 PM

    I have received 3 of these in the last week. 
     1) 28/04 at 7:31. Your statement is ready from +61428482059
     2) 04/05 at 6:05. Account Update from +61429136650
     3) 04/05 at 7:58. Balance update from +61437581767
    I do not have accounts with any of these organisations.
  • Ming Liu

    30/05/2016 12:46:24 PM

    Got a SMS from 0427 659 225 , Very bad one. 
    Dear ANZ bank Customer,
    We have detected some unusual activity, We urgently ask you to follow the account review link:
  • Dirk Wachter

    8/06/2016 2:05:44 PM

    I received a phishing SMS today, which is not on the above list of known scams, from +61428971830.
    It claims to be from ANZ and attempts customers to browse to which looks like a legitimate ANZ login page for Online Banking.
    "Dear Customer, We have detected some unusual activity. We urgently ask you to follow the account review link: ..."
    • In reply to Dirk Wachter

      The ACMA

      8/06/2016 4:11:35 PM

      Hi Dirk,
      If you think the SMS is a phishing scam, delete the message. Before you do so, you can report the SMS to the ACMA by forwarding it to 0429 999 888 or make a complaint online at
  • Michael Russell

    16/06/2016 1:52:53 PM

    Received a phishing message on my mobile from: (partial URL).Not even a NAB customer. Sent them an appropriate reply and then deleted the message; but would be good to have somewhere to report them, Their number is +61481072087.
    • In reply to Michael Russell

      The ACMA

      16/06/2016 3:03:16 PM

      Hi Michael, there are a few ways to report these messages.
      You can forward the message to the ACMA's Spam SMS service on 0429 999 888. 
      Report the message to SCAMwatch at
      Report the message to ACORN - the Australian Cybercrime Online Reporting Network - at
  • Kaya

    16/11/2016 2:07:18 AM

    Informative post, thanks for sharing.
    [][color=white]Great post[/color][/url]
  • Michiel

    15/12/2016 9:39:41 AM

    Received a text message allegedly from Commonwealth Bank just now to verify my phone number incl a link to a fake website (it has a .top domain in the link) - Easy to spot as I'm not even a customer ... but if you are, beware! 
    • In reply to Michiel

      The ACMA

      16/12/2016 12:14:19 PM

      Sure sounds like a fake. Well spotted, Michiel.
  • Steave Gaskill

    30/01/2017 9:36:49 PM

    I got a message stating that A transaction of AUD 489.24 was made with your bank account on 30/1/2017. If unauthorised follow this link
    If you copy and paste this link on web browser it will open a website look like CBA website but if you click on any link on this page, it will not open. It is a fake site page. Only three spaces work at this page, user id, password and sign in button. Rest other places/link items do not work. 
    While CBA website all links work.
    Thank you!!
    • In reply to Steave Gaskill

      The ACMA

      2/02/2017 1:18:58 PM

      Hi Steave, thanks for this information. If you suspect this is a scam, you can report the message to the ACCC's ScamWatch program at
  • Claudia

    1/02/2017 7:05:48 PM

    I received a similar SMS as Steave Gaskill today from number +61 416 409 459:
    "A transaction of AUD 475.49 was made with your bank account on 01/02/17 12:04:08pm. If unauthorised follow this link."
    Deleted text and warned all family members. The scam is obviously doing the rounds at the moment.
    • In reply to Claudia

      The ACMA

      2/02/2017 1:19:48 PM

      Hi Claudia, thanks for following up Steave's information with your own experience. If you suspect this is a scam, you can report the message to the ACCC's ScamWatch program at
  • Josie

    9/02/2017 5:13:00 PM

    I received same SMS as Claudia from +61481986878
    A transaction of AUD 614.95 was made with your bank account on 2017/02/09 11:14:08.
    If unauthorised follow this link http//
    Text deleted
    • In reply to Josie

      The ACMA

      10/02/2017 11:47:16 AM

      Hi Josie, good work spotting this fake. If you receive a scam SMS, never click on the link – delete it immediately.
  • Peter Humphris

    15/02/2017 11:41:18 PM

    "suspicious transaction of AUD 790.2 reported 12/02/17 01:54:47pm if unauthorised follow this link
    from phone number +61474096574
    Have added number to my "spam numbers"
    and deleted message
    • In reply to Peter Humphris

      The ACMA

      17/02/2017 11:33:18 AM

      Hi Peter, well done spotting this fake. If you receive any others, delete them too! You can also report these messages to the ACMA by forwarding to 0429 999 888  
  • johanna christenson

    22/02/2017 9:28:43 PM

    I am with the WestPac Bank and have just been scammed somehow i have had $450 taken out of my Bank account tonight! i didn't open any links but everytime i go onto Mobile Banking i am asked to reset my password 
    • In reply to johanna christenson

      The ACMA

      24/02/2017 11:50:34 AM

      Hi Johanna, if you think it's a scam, you can report it to the ACCC's ScamWatch program at
  • Mel

    11/05/2017 7:19:29 PM

    I had a scam claiming to be from commonwealth via sms. Saying important message your netbank account has been locked. To restore please visit immediately. It is only affecting the optus network. I called commonwealth and they are aware of this. I thought it was odd as I have not been with them for a while now.
  • Simon

    5/06/2017 10:01:23 AM

    Thanks ACMA! I got one of these too but deleted it straightaway. Grrrrrr.
  • shafinaz

    6/06/2017 9:27:42 AM

    Hi Catherine, good call to be careful, especially when you're not a customer!
  • Jessica Reid

    18/07/2017 10:55:55 AM

    I received one at 6am this morning telling me that there had been an unauthorised transaction on my bank card for Bank SA for something called "GODADDY EUROPE".  It said "if this is a genuine transaction, reply yes. If it is a faudulent transaction reply No".  I rang BankSA who reported no such transaction on my account.  I did not reply to the text.  
Back to top