Reference
Online safety help in Australia
Which government service covers what, when to contact each, and what reporting does and does not achieve.
Security software addresses one part of a much larger picture, and for several of the problems people actually encounter it is the wrong tool entirely. Money that has already left an account, an intimate image shared without consent, an organisation that will not say what it did with your personal information — none of these is a scanning problem. Australia has separate public bodies for each, they are free to use, and knowing which is which saves time at a point when time matters.
This page describes each service as what it is, and links to it. It does not paraphrase their advice; where you need guidance on a specific situation, the service's own site is the authority and this page is only a directory.
Which service covers what
| Service | Covers | Typical situation |
|---|---|---|
| Australian Cyber Security Centre | Cyber security guidance and incident reporting | An account has been taken over; a device is affected by ransomware; you want baseline guidance |
| Scamwatch | Scam reporting and current scam alerts, through the National Anti-Scam Centre | A message, call or website has tried to obtain money or details from you |
| eSafety Commissioner | Online abuse, image-based abuse, child safety and online harms | Someone is being harassed online, or an intimate image has been shared without consent |
| Office of the Australian Information Commissioner | Privacy regulation and privacy complaints | An organisation mishandled your personal information, or will not give you access to it |
| ACCC | Competition and consumer law, including consumer guarantees | A business will not honour a refund or has made misleading claims about a product |
Australian Cyber Security Centre
The ACSC is the Commonwealth's point of contact for cyber security. Its public site carries guidance written for individuals, families and small businesses, and it is where cyber incidents are reported. The guidance covers the measures that sit underneath any software purchase: keeping systems updated, using multi-factor authentication, choosing passphrases, and backing up.
It is worth reading before choosing a product rather than after, because it makes clear how much of a household's practical position is determined by free measures rather than paid ones. Nothing on this site contradicts it, and where the two differ, the ACSC is the source to follow.
Scamwatch and the National Anti-Scam Centre
Scamwatch collects reports of scams and publishes what current approaches look like. The alerts are the useful part for most readers: seeing the actual wording of a current impersonation attempt is a better preparation than any general warning, because scams are recognisable by their pattern and the patterns shift.
Reporting is done through the report form on the Scamwatch site. A report does not recover money on its own, and it is honest to say so; what it does is contribute to the picture that lets the centre and other agencies act on patterns, and it is quick.
One pattern worth knowing about specifically, because it intersects with this site's subject: technical support impersonation. A caller or a web advertisement claims a problem with your computer and offers to fix it, usually asking for remote access or payment. Contact routes for any software you own are inside the software or on the vendor's own website, and a support number found through a search result or an advertisement should be treated with suspicion.
eSafety Commissioner
eSafety handles online harms rather than fraud: cyberbullying affecting children, adult cyber abuse, image-based abuse, and illegal or restricted online content. It has complaint schemes for each, and it can act on material in ways an individual cannot.
This is the service people are least likely to know about when they need it, and the one where speed helps most. If the problem is someone's behaviour towards a person rather than an attempt to obtain money, eSafety is the starting point.
Office of the Australian Information Commissioner
The OAIC regulates privacy in Australia under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Its role covers how organisations collect, use, store and disclose personal information, and it receives complaints from individuals about that handling. It also administers the Notifiable Data Breaches scheme, under which organisations must notify affected individuals and the Commissioner about breaches likely to result in serious harm.
The usual route is to raise the matter with the organisation first and give it a chance to respond; if that does not resolve it, the OAIC's site explains how to bring a complaint. This site's own privacy policy sets out the same route for anything you send to the publisher.
ACCC and state fair trading
The ACCC administers the Australian Consumer Law, which is the framework behind consumer guarantees and behind the prohibition on misleading or deceptive conduct in trade. For a software subscription that does not do what was represented, or a business that will not honour its own refund terms, this is the relevant area of law. The ACCC's site also directs consumers to the consumer affairs or fair trading body in each state and territory, which handles many individual disputes.
What to do first, in four common situations
Money has left your account
Contact your bank or card issuer immediately — speed affects what can be done. Then report to Scamwatch. Buying software at this point does not reverse a payment.
An account has been taken over
Regain access and change the password to a unique one, turn on multi-factor authentication, and check for forwarding rules or recovery addresses that were added. The ACSC publishes step-by-step guidance for account compromise.
Someone is being harassed or an image has been shared
Keep the evidence, do not engage, and go to eSafety, which has a complaint scheme for each of these categories.
A business mishandled your personal information
Ask the organisation in writing what happened and what it holds. If the answer is unsatisfactory, the OAIC takes complaints about privacy handling.
Have this ready when you report
Dates and times, the exact wording of the message or the address of the website, any reference numbers, what you did in response, and screenshots. Reports are processed faster when they are specific, and details are harder to reconstruct a week later than to save now.
What none of these services will do
Australian government agencies do not telephone people out of the blue to say a device is infected, do not ask for remote access to a computer, and do not request payment in gift cards, cryptocurrency or bank transfers to resolve a matter. A contact claiming to be from any of the bodies on this page can be verified by hanging up and reaching the organisation through the address printed here rather than through any number the caller supplies. Treating an unexpected approach as unverified until you have checked it independently costs a minute and removes most of the risk in this category.
What reporting achieves
It is worth being plain about this, because inflated expectations put people off reporting the second time. A report rarely recovers money directly and rarely results in a visible individual outcome. What it does is make patterns visible: the same scam reported a thousand times is a pattern that agencies, banks and platforms can act on, and alerts published from those reports are what warn the next person. Reporting is a contribution to a system rather than a personal remedy, and it still takes only a few minutes.
Related reading on this site
- How antivirus software works — including what it cannot do.
- How to choose antivirus software in Australia — consumer guarantees and the purchase sequence.
- About this site — who publishes it and how coverage is decided.