Fake 'Australian Federal Police' Calls: When the 'Proof' Is a Real Government Email

A scam caller posing as the AFP made a genuine, fully-authenticated email from cyber.gov.au land in a Perth inbox as 'proof' he was real. Here's how the trick works and why a verified email never verifies the caller. From Computer Mechanics, Perth IT specialists since 1997.

Garry BloomGarry Bloom · Founder & CEO
20 August 2026
5 min read
Cybersecurity
Scams
Social Engineering
Phishing
Perth Business

On Monday, a member of our team took a call from someone claiming to be a Detective Constable with the AFP cyber crime unit. Calm, polite — and, like all of these, a scam. But it had a twist we hadn't seen before: to "prove" he was a genuine officer, the caller made a real email from a real government address (report.cyber.gov.au) land in our inbox mid-call. It passed every security check. Here's how that trick works, and why a genuine, fully-verified email still tells you nothing about who's on the phone.

The call itself

The usual theatre: an apology for interrupting, reassurance that "you're not in any trouble," a warrant executed over the weekend, a suspect arrested for "fraud and cyber-enabled financial theft," and a seized database of 600+ people's details — including yours. A name, a badge number, the correct public address of AFP headquarters in Canberra. Unhurried, because the first call exists only to make you believe the caller is police. The real target surfaced about nine minutes in: cryptocurrency "recovery phrases of 12 or 24 words." That is the hook — your seed phrase.

The clever part: a "verification" email that was genuinely real

When we asked how we could verify him, he said an email would confirm we were "speaking with a verified officer." Moments later one arrived — subject "ReportCyber – One Time Password (Do Not Share)", from noreply@report.cyber.gov.au. And it was legitimate: it passed SPF, DKIM and DMARC, all aligned to the real report.cyber.gov.au domain.

The email that "verified" the caller — and it was genuinely from ReportCyber: From noreply@report.cyber.gov.au · Subject "ReportCyber – One Time Password (Do Not Share)" · DMARC: Pass · SPF: Pass · DKIM: Pass. Every check passed. It really was from ReportCyber. It still proved nothing about the caller.

Here is what actually happened, and you can see it for yourself. On the ReportCyber portal (reportapp.cyber.gov.au), the options to "resume a saved report" or "check the status of an existing report" ask for an email address and then email a one-time code to it — the normal way of getting you back into your own report. The scammer simply entered our address there. The genuine ReportCyber system did exactly what it is designed to do and emailed us a real one-time code, which he then held up as "proof" he was an officer.

That is the crucial detail: the code is sent to whatever address is typed in, and it confirms nothing about who typed it. If you want to see the effect for yourself, enter your own email on that page and you'll receive the very same "verified" email the scammer relied on. Only ever use your own address — sending these to anyone else is exactly the behaviour we're warning about.

Why a genuine email proves nothing

Two things make this dangerous:

  1. Anyone can make that email arrive. A one-time-password email is an automated system message. Enter your address into a public government portal and you get one. Receiving it says nothing about who triggered it — or who is on the phone.

  2. Its only purpose was to make the caller look legitimate. A genuine email from a real gov.au address, arriving exactly when he said it would, is powerful theatre — designed to turn "a stranger claiming to be police" into "someone the government just verified." It does no such thing. The email confirms only that it came from ReportCyber. It says nothing about who is on the phone. Treat an unexpected verification email as a sign that someone has typed your address into a form somewhere — not as proof of anyone's identity.

"But it passed every security check — doesn't that prove it's real?"

It proves the email came from ReportCyber. It says nothing about the caller — and the scam relies on you blurring those two questions.

One specific thing is worth clearing up, because it trips people up: a sending server in another country is not a red flag. This email was sent from a US-based server, which sounds alarming — but Australian government and business email is routinely sent through global cloud platforms (this one went via a major US email service). What proves an email is authentic is SPF, DKIM and DMARC — not the geography of the server. Judge by "where's the server" and you will flag huge amounts of genuine mail and miss the real signals.

The tells that did give it away

  • The AFP does not cold-call people to say their data has appeared in a breach.

  • The offence was described as "fraud by false representation" — a charge under the UK's Fraud Act 2006, which has no equivalent in Australian law.

  • The rank "Detective Constable" and phrases like "pop into your local station" are British, not Australian.

  • The request that matters: no real investigator needs your seed phrase, password, one-time code, or remote access.

  • Caller ID showed a Canberra landline — meaningless, because caller ID is trivially spoofed.

This is the same playbook as the ATO and myGov impersonation scams hitting Perth businesses — an authority you trust, a plausible story, and a push toward one irreversible action.

What to do if you get one of these calls

  • Hang up. No obligation, no penalty.

  • Don't call back on the number that called you, or any number the caller gives you. To check whether the AFP wants you, look up their number independently.

  • Never share a one-time code, password, PIN, seed phrase, or remote access — whatever "proof" is offered. A one-time code is a key to an account, not a verification prop, that ReportCyber email even carries a Do Not Share warning for a reason.

  • Expect a second call. These run in stages, a "supervisor" or "fraud liaison officer" often follows within days.

Where to report it

Reporting matters even if you lost nothing — it is how the pattern gets recognised.

  • ReportCyber (Australian Cyber Security Centre) — cyber.gov.au/report

  • Scamwatch (National Anti-Scam Centre) — scamwatch.gov.au

  • IDCARE, for free identity-exposure support — idcare.org

If you already shared something

Act fast: move a disclosed seed phrase to a new wallet with a new phrase immediately (a disclosed phrase cannot be un-shared), call your bank on the number on your card if you shared details or a code, disconnect and have any device checked if you granted remote access, change passwords on any account you named and turn on multi-factor authentication. Then report it.

If you're not sure, ask before you act

A call like this is designed to make a genuine-looking email feel like proof. If you ever receive a verification email you didn't request — or you're unsure a call is real — stop and check first. As a Perth business's managed IT and cyber security team, that is exactly the kind of thing we would rather look at ten times over than clean up once. Get in touch and we'll help you tell genuine from fake. We've kept Perth businesses secure since 1997.

Garry Bloom
Written by
Garry Bloom
Founder & CEO · 25+ years in IT

Garry founded Computer Mechanics — the business behind IT Support Perth — in 1997. With more than 25 years in IT management and support across internal and external service environments, he leads the team's technical direction and its cybersecurity and managed-IT strategy for Perth businesses.

Meet the IT Support Perth team →
Garry Bloom
20 August 2026
5 min read
Cybersecurity
Scams
Social Engineering
Phishing
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Remote Access Scams: How Fraudsters Impersonate 'IT Support' to Rob Perth Businesses

ASIC says remote access scams have cost Australian small businesses $4.9 million, with callers posing as IT support to get onto your PC. Here's how Perth businesses can spot and stop it. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Payment Redirection Scams Are Costing Australian Businesses Millions: A Perth Guide

Payment redirection and invoice scams are the most common fraud reported by Australian small businesses, with losses in the hundreds of millions. Ahead of Scams Awareness Week 2026, here's how Perth businesses can stop them. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

A Perth Business's Server Dies — and the Backup Hadn't Run in Weeks

A representative walkthrough of how we recover a Perth business after a server failure — and what we do when the backup everyone trusted had silently stopped running. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
ATO & myGov Impersonation Scams Are Surging: What Perth Businesses Must Know
Scams
Cybersecurity

ATO & myGov Impersonation Scams Are Surging: What Perth Businesses Must Know

ATO impersonation scam reports jumped 12% in June 2026. Here's how the scam targets Perth business owners and five steps to protect your business. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/6/2026
Call us