A message from myGov. A warning from Amazon. A reminder that your frequent flyer points are about to expire.
These messages can appear routine, but new analysis from the TrendLife Threat Research team reveals how scammers are impersonating the organisations Australians and New Zealanders know and trust.
TrendLife researchers analysed 236,839 scam detections across Australia and New Zealand between January and early August 2026, identifying the government services, brands and institutions most frequently used to deceive consumers.
The findings show that scam activity is heavily concentrated. Government impersonation represented 38% of all detections, followed by rewards-point scams at 23.7% and Amazon impersonation at 12.9%. Together, these three categories accounted for almost three-quarters of all scam activity identified.
Scammers are targeting familiar names
Impersonation scams work because the messages often resemble communications people receive in everyday life.
A tax notification, an account security warning or an expiring-points reminder may not immediately seem unusual. Scammers exploit that familiarity, combining a trusted name with urgency, fear or the promise of a reward.
Most messages then direct the recipient to a malicious link, often hidden behind a shortened URL, QR-code redirector or look-alike website address.
Here are the 10 most-detected impersonation categories identified.
1. Government and essential services
- Government impersonation was the largest category, with 90,095 detections.
- Messages posed as myGov, the Australian Taxation Office, Medicare, Centrelink and health funds. Common claims included that a new passkey had been created, a tax refund was waiting or an account required verification.
- The links typically led to fake login or payment pages designed to capture government credentials, identity information or card details.
2. Rewards and loyalty programs
- Rewards-point scams accounted for 56,241 detections.
- The category was dominated by Qantas Frequent Flyer and Air New Zealand Airpoints, which together represented approximately 98% of rewards-related activity.
- Messages warned that points were about to expire and directed recipients to imitation loyalty portals, where they were asked to log in or enter payment information.
3. Amazon
- TrendLife researchers recorded 30,608 Amazon impersonation detections.
- Messages commonly claimed that someone had signed in from an unfamiliar location. Concerned recipients were directed to fake Amazon login pages designed to steal account credentials and payment information.
4. Toll providers
- Toll impersonation accounted for 24,412 detections, using names such as Linkt and E-Toll.
- Messages claimed that a small toll remained unpaid and warned of escalating fees, debt recovery or registration restrictions. The supposed payment page then captured the recipient’s card details.
5. Police, courts and fines
- Police and fine-related impersonation generated 17,094 detections.
- These messages referred to overdue traffic fines and used deadlines, official-sounding reference numbers and threats of additional penalties or prosecution to pressure recipients into paying.
6. Apple
- Apple-related scams produced 6,740 detections.
- Some claimed there was a problem with an Apple ID or Apple Pay account, while others asked recipients to purchase gift cards and share the codes.
7. Banks and financial institutions
- Bank impersonation accounted for 5,896 detections.
- Messages included fake security alerts, invoices, payment reminders and late-fee warnings, directing recipients to imitation banking pages or requesting direct transfers.
8. Betting and gambling brands
- TrendLife identified 3,512 detections impersonating betting companies.
- These messages generally promoted deposit bonuses or limited-time offers, using the promise of a reward to encourage immediate sign-ups or payments.
9. Subscription services
- Streaming and subscription scams accounted for 2,045 detections.
- Messages claimed that a payment had failed or an account needed updating, leading to fake login and payment pages.
10. Delivery companies
- Delivery impersonation represented 196 detections.
- Messages claimed that a parcel had been delayed because of an incorrect address, missed delivery or unpaid redelivery fee.
What the research tells us
Scam activity peaked in March 2026, when the TrendLife Threat Research team recorded 58,641 detections.
The increase was driven by a major rewards-points campaign occurring alongside growing government, toll and Amazon impersonation activity.
While the organisations being impersonated changed over time, the tactics remained consistent: create urgency, introduce a financial consequence or reward, and direct the recipient to a link.
A familiar sender name or logo is not proof that a message is genuine. Consumers should avoid logging in or making payments through unexpected messages. Instead, open the organisation’s official app or enter its known website address directly.
Scammers want people to react before they investigate. As trusted names increasingly become part of the deception, pausing to verify a message is becoming an essential part of everyday digital life.
