News
The National Disability Insurance Agency (NDIA) has confirmed that cyber criminals have gained access to some NDIS participant accounts through myGov, using phishing activity and by persuading account holders to voluntarily hand over login details.
In a statement dated 27 July, the NDIA said it was working with Services Australia, which administers myGov, to manage and respond to the ongoing issue. The agency said it was implementing additional security measures to protect accounts and prevent unauthorised access, and would notify individuals if evidence emerged that their myGov account had been compromised.
The NDIA has advised participants and nominees to regularly check their NDIS accounts for unusual activity, monitor NDIS plan funds for unrecognised payments, and watch their bank accounts for suspicious transactions.
The agency also urged people to be cautious of unsolicited contact by email, SMS, messaging apps or phone, and not to click on suspicious links. It reiterated that the NDIS will never request personal details by SMS, and advised against sharing passwords, multi-factor authentication codes or personal information with unknown or untrusted parties.
Participants have also been encouraged to change online account passwords regularly, enable multi-factor authentication where possible, and consult the NDIS "What is a scam" page and the Services Australia myGov scams page for further guidance.
The NDIA directed people with concerns about their personal information to contact IDCARE, a national identity support service.
The NDIA did not specify the number of accounts affected or the timeframe over which the phishing activity occurred.
