
On Monday, a member of our team took a call from someone claiming to be a Detective Constable with the AFP cyber crime unit. Calm, polite — and, like all of these, a scam. But it had a twist we hadn't seen before: to "prove" he was a genuine officer, the caller made a real email from a real government address (report.cyber.gov.au) land in our inbox mid-call. It passed every security check. Here's how that trick works, and why a genuine, fully-verified email still tells you nothing about who's on the phone.
The call itself
The usual theatre: an apology for interrupting, reassurance that "you're not in any trouble," a warrant executed over the weekend, a suspect arrested for "fraud and cyber-enabled financial theft," and a seized database of 600+ people's details — including yours. A name, a badge number, the correct public address of AFP headquarters in Canberra. Unhurried, because the first call exists only to make you believe the caller is police. The real target surfaced about nine minutes in: cryptocurrency "recovery phrases of 12 or 24 words." That is the hook — your seed phrase.
The clever part: a "verification" email that was genuinely real
When we asked how we could verify him, he said an email would confirm we were "speaking with a verified officer." Moments later one arrived — subject "ReportCyber – One Time Password (Do Not Share)", from noreply@report.cyber.gov.au. And it was legitimate: it passed SPF, DKIM and DMARC, all aligned to the real report.cyber.gov.au domain.
The email that "verified" the caller — and it was genuinely from ReportCyber: From
noreply@report.cyber.gov.au· Subject "ReportCyber – One Time Password (Do Not Share)" · DMARC: Pass · SPF: Pass · DKIM: Pass. Every check passed. It really was from ReportCyber. It still proved nothing about the caller.
Here is what actually happened, and you can see it for yourself. On the ReportCyber portal (reportapp.cyber.gov.au), the options to "resume a saved report" or "check the status of an existing report" ask for an email address and then email a one-time code to it — the normal way of getting you back into your own report. The scammer simply entered our address there. The genuine ReportCyber system did exactly what it is designed to do and emailed us a real one-time code, which he then held up as "proof" he was an officer.
That is the crucial detail: the code is sent to whatever address is typed in, and it confirms nothing about who typed it. If you want to see the effect for yourself, enter your own email on that page and you'll receive the very same "verified" email the scammer relied on. Only ever use your own address — sending these to anyone else is exactly the behaviour we're warning about.
Why a genuine email proves nothing
Two things make this dangerous:
Anyone can make that email arrive. A one-time-password email is an automated system message. Enter your address into a public government portal and you get one. Receiving it says nothing about who triggered it — or who is on the phone.
Its only purpose was to make the caller look legitimate. A genuine email from a real gov.au address, arriving exactly when he said it would, is powerful theatre — designed to turn "a stranger claiming to be police" into "someone the government just verified." It does no such thing. The email confirms only that it came from ReportCyber. It says nothing about who is on the phone. Treat an unexpected verification email as a sign that someone has typed your address into a form somewhere — not as proof of anyone's identity.
"But it passed every security check — doesn't that prove it's real?"
It proves the email came from ReportCyber. It says nothing about the caller — and the scam relies on you blurring those two questions.
One specific thing is worth clearing up, because it trips people up: a sending server in another country is not a red flag. This email was sent from a US-based server, which sounds alarming — but Australian government and business email is routinely sent through global cloud platforms (this one went via a major US email service). What proves an email is authentic is SPF, DKIM and DMARC — not the geography of the server. Judge by "where's the server" and you will flag huge amounts of genuine mail and miss the real signals.
The tells that did give it away
The AFP does not cold-call people to say their data has appeared in a breach.
The offence was described as "fraud by false representation" — a charge under the UK's Fraud Act 2006, which has no equivalent in Australian law.
The rank "Detective Constable" and phrases like "pop into your local station" are British, not Australian.
The request that matters: no real investigator needs your seed phrase, password, one-time code, or remote access.
Caller ID showed a Canberra landline — meaningless, because caller ID is trivially spoofed.
This is the same playbook as the ATO and myGov impersonation scams hitting Perth businesses — an authority you trust, a plausible story, and a push toward one irreversible action.
What to do if you get one of these calls
Hang up. No obligation, no penalty.
Don't call back on the number that called you, or any number the caller gives you. To check whether the AFP wants you, look up their number independently.
Never share a one-time code, password, PIN, seed phrase, or remote access — whatever "proof" is offered. A one-time code is a key to an account, not a verification prop, that ReportCyber email even carries a Do Not Share warning for a reason.
Expect a second call. These run in stages, a "supervisor" or "fraud liaison officer" often follows within days.
Where to report it
Reporting matters even if you lost nothing — it is how the pattern gets recognised.
ReportCyber (Australian Cyber Security Centre) — cyber.gov.au/report
Scamwatch (National Anti-Scam Centre) — scamwatch.gov.au
IDCARE, for free identity-exposure support — idcare.org
If you already shared something
Act fast: move a disclosed seed phrase to a new wallet with a new phrase immediately (a disclosed phrase cannot be un-shared), call your bank on the number on your card if you shared details or a code, disconnect and have any device checked if you granted remote access, change passwords on any account you named and turn on multi-factor authentication. Then report it.
If you're not sure, ask before you act
A call like this is designed to make a genuine-looking email feel like proof. If you ever receive a verification email you didn't request — or you're unsure a call is real — stop and check first. As a Perth business's managed IT and cyber security team, that is exactly the kind of thing we would rather look at ten times over than clean up once. Get in touch and we'll help you tell genuine from fake. We've kept Perth businesses secure since 1997.



