The NDIS has confirmed that cyber criminals have used myGov to gain unauthorised access to some NDIS participant accounts.
- Attackers gained access through phishing activity and by persuading people to hand over their login details, the NDIA said on 27 July 2026.
- The agency is adding extra security measures and working with Services Australia, which runs myGov, to respond to the ongoing issue.
- Affected participants will be notified directly if evidence shows their account was compromised.
- NDIS is urging participants and nominees to check their accounts regularly for unusual activity or payments they didn’t request.
Why it matters: NDIS accounts hold sensitive personal and financial information, so a breach like this raises real risk of fraud or unauthorised plan spending for people who may already face extra barriers to resolving account problems.
Source: NDIS →