Recourse

Where to report a problem in Australia

Six bodies cover this area, and each handles something different. Sending a report to the wrong one costs time, so this page matches the problem to the organisation and says what each can actually do.

Software vendors handle faults with their software. Almost everything else in this area — a scam call, a fraudulent charge, personal information exposed in a breach, a fake warning page — is handled by a public body, at no cost, through a published channel. The descriptions below reflect each body's own stated role; the links go to their own sites, which are where the current reporting forms live.

Matching the problem to the body

Where each kind of problem is handled
SituationWhere it goesWhat that achieves
A scam approach by call, message or email Scamwatch, run by the National Anti-Scam Centre Feeds the national picture of what is circulating and informs public warnings
Cybercrime: an account taken over, a device compromised, extortion ReportCyber, via the Australian Cyber Security Centre Routes the report to the relevant law enforcement agency
Money has left an account Your bank or card issuer, immediately, then Scamwatch The only route with any prospect of stopping or recovering a transfer
An organisation has mishandled or exposed your personal information Office of the Australian Information Commissioner Privacy complaints under the Privacy Act 1988; administers the Notifiable Data Breaches scheme
Misleading advertising, a refund refused, a disputed charge ACCC, and your state or territory consumer protection agency Informs enforcement under the Australian Consumer Law; the state agency may assist directly
Online abuse, image-based abuse, child safety online eSafety Commissioner Complaints schemes with powers to seek removal of material

What each body does

Australian Cyber Security Centre

The ACSC is the Australian Government's lead on cyber security for the public, publishing practical guidance for individuals, families and small business, alerts about active issues, and step-by-step material on subjects such as ransomware, account compromise and securing devices. It operates ReportCyber, the national reporting channel for cybercrime, which routes reports to the appropriate law enforcement agency. Its guidance is free, carries no advertising, and is the reference this site points to rather than paraphrasing.

Scamwatch and the National Anti-Scam Centre

Scamwatch collects scam reports from the public and publishes what is currently circulating, including the approaches used in fake technical support calls and warning pages. Reporting a scam you did not fall for is still useful: the reports are what make the published picture accurate, and they are read by people trying to work out whether the message in front of them is genuine.

Office of the Australian Information Commissioner

The OAIC regulates privacy under the Privacy Act 1988 and the Australian Privacy Principles. It handles complaints about how an organisation has managed personal information, and administers the Notifiable Data Breaches scheme, under which organisations covered by the Act must notify affected individuals and the Commissioner about a data breach likely to result in serious harm. The usual sequence is to raise the matter with the organisation first and to come to the OAIC if it is not resolved.

Australian Competition and Consumer Commission

The ACCC administers the Australian Consumer Law, which covers misleading or deceptive conduct in trade and the consumer guarantees that apply to goods and services sold in Australia. It does not resolve individual disputes as a rule, and its reports inform enforcement; the consumer protection agency in each state and territory is the body that may assist with an individual matter. Its guidance on consumer rights is set out on its own site.

eSafety Commissioner

eSafety covers online safety: cyberbullying affecting children, adult cyber abuse, image-based abuse, and the safety of children online. It runs complaints schemes with powers to seek the removal of material, and it publishes guidance for parents and carers. It is the right body for monitoring applications installed on a person's device by someone else, which sits outside what a security product will usually classify as malicious.

The scam that uses this category's own vocabulary

Fake technical support is worth describing specifically, because it borrows the language of security software. The approach is consistent: a warning appears — a full-screen page, a pop-up, sometimes an unsolicited telephone call — claiming that infections have been detected and that help is available on a number shown. The number reaches the people who produced the warning. What follows is a request for remote access to the device, and then a payment for a problem that did not exist, sometimes with genuine software installed afterwards to make the visit look legitimate.

Three facts that settle it every time

A web page cannot scan a device; it can only display a claim. A genuine security product reports through its own interface, not through a browser window and never with a telephone number. No vendor, telecommunications company, bank or government department detects an infection on a home device and rings the owner about it unprompted.

The response is the same in each case: close the page or end the call without ringing the number, do not grant remote access, and report the example to Scamwatch. If remote access was granted, or a payment was made, the ACSC's guidance on what to do after a compromise and a call to your bank are the first two steps, in that order of thoroughness but with the bank first if money moved.

What to gather before reporting

  • Dates and times, as close as you can establish them.
  • The channel: telephone number, email address, website address, or application.
  • Screenshots of what was displayed, including any reference number shown.
  • What was sent, granted or paid, and through which method.
  • Any correspondence with the organisation involved, kept as it was received.

Reports are more useful with this material and still worth making without it. Where an approach was not acted on, a report costs a few minutes and adds to a national picture that other people rely on.

If the problem is with software you bought

A fault in a product you have paid for follows a different path. The first step is the vendor's own support channel, with a written record kept of what was reported and when. If that does not resolve it, the consumer guarantees under the Australian Consumer Law apply to software sold in Australia, and the ACCC publishes what those guarantees cover and where a complaint can be taken. Disputed or unexpected charges are covered on our page about licences and subscriptions, which sets out the three figures worth establishing before any subscription begins and the routes available when a renewal appears without warning.

What reporting does and does not do

A report to Scamwatch or ReportCyber is not an individual investigation, and neither body will usually come back with an outcome on a single matter. What they do is aggregate: patterns identified across many reports inform public warnings, enforcement priorities and disruption work. The route with any prospect of recovering money remains the financial institution, contacted as quickly as possible, which is why it appears first in the table above.

A complaint to the OAIC or to a state consumer agency is different in kind — those are processes about your own situation, with their own steps and timeframes, set out on their sites.

For the vocabulary used in the warnings and messages described here, see the glossary, particularly scareware, phishing and social engineering. For why software addresses only part of this, see what detection cannot reach.