NDIS warns of myGov phishing scheme compromising participant accounts

The NDIS has confirmed that cyber criminals have used myGov to gain unauthorised access to some NDIS participant accounts.

  • Attackers gained access through phishing activity and by persuading people to hand over their login details, the NDIA said on 27 July 2026.
  • The agency is adding extra security measures and working with Services Australia, which runs myGov, to respond to the ongoing issue.
  • Affected participants will be notified directly if evidence shows their account was compromised.
  • NDIS is urging participants and nominees to check their accounts regularly for unusual activity or payments they didn’t request.

Why it matters: NDIS accounts hold sensitive personal and financial information, so a breach like this raises real risk of fraud or unauthorised plan spending for people who may already face extra barriers to resolving account problems.

Source: NDIS →