Byteway provides IT and cyber security for Australian businesses, and every year we watch the same thing happen as winter arrives: a sharp rise in scams aimed at finance teams. It is not superstition and it is not the cold. Australia’s winter lines up with the end of the financial year and the opening of tax season, and that calendar, not the weather, is what makes June to October the most dangerous stretch of the year for business payments.
This guide explains why the spike happens, what it means for whoever handles your money, and the small set of habits that carry a finance team through the busiest and riskiest weeks of their year.
Executive summary
In Australia, winter is scam season because the financial year ends on 30 June and tax return season opens on 1 July, which is when tax scams, rebate scams and payment fraud all spike. The ATO recorded 7,420 impersonation scam reports in July 2025, a 75 per cent jump from June, and consistently sees its highest scam volumes between July and October. The driver is not the season itself. It is that finance teams are flooded with legitimate large transactions and deadline pressure, which is exactly the cover attackers exploit. The defence is process discipline, applied hardest when everyone is busiest.
Why does scam activity spike in the Australian winter?
The link is the financial calendar, not the temperature. Three things collide between June and October.
End of financial year (30 June). The lead-up is the busiest payment period of the year for many businesses. Suppliers push to be paid, invoices pile up, and finance teams process a high volume of large transactions under time pressure.
Tax return season opens (1 July). Suddenly millions of Australians are expecting communication from the ATO, waiting on refunds, and thinking about their tax. That expectation is precisely what a fake ATO message exploits.
Peak ATO scam months (July to October). The ATO consistently records its highest volumes of scam reports across these months. In July 2025 it received 7,420 impersonation scam reports, a 75 per cent increase from June. Banks see the same pattern. ANZ reported rebate scams surging around 50 per cent in July during a recent tax season, with extortion-style scams rising sharply through June and July as well.
So the “season” is real, but it is a calendar effect. Scammers are not more active because it is cold. They are more active because your finance team is buried, your staff are expecting tax messages, and large payments are moving in volume. Busy, distracted and expectant is the ideal condition for a scam to slip through.
What kinds of scams spike, and who they target?
Winter scam season is not one threat. It is several, aimed at slightly different people.
Aimed at your staff and individuals:
- Fake ATO refund messages. A text, email or call saying a refund is ready, click to claim. The ATO does not send unsolicited messages with links.
- Fake tax debt or penalty threats. Urgent messages claiming you owe money and must pay immediately, often threatening consequences.
- myGov and rebate scams. Cloned login pages harvesting credentials, or promises of a rebate that require your card details.
Aimed at your finance team and business:
- Business email compromise and invoice fraud. EOFY generates many legitimate bank-detail changes and large payments, which is exactly when a fraudulent invoice or a “we’ve updated our bank details” email is most likely to be paid without a second look.
- Impersonation of your accountant or payroll provider. Messages spoofing the people your finance team genuinely expects to hear from at this time of year, referencing BAS, PAYG or lodgement.
- Fake EOFY deals and supplier offers. Urgency-driven “end of financial year” offers designed to rush a purchase or a click.
The common thread is that every one of these borrows the legitimacy of the season. A fake ATO email works in July because real ATO emails are expected in July. A fraudulent invoice works at EOFY because real invoices are flooding in at EOFY.
Why finance teams are the real target?
Step back and the strategy is clear. Attackers go where the money moves, at the moment it moves fastest.
Your finance team in June and July is processing more payments, larger payments, and more changes than at any other time of year, under real deadline pressure. Every legitimate “please pay this before end of financial year” email is cover for a fraudulent one. Every genuine bank-detail update makes the fake one look normal. The sheer volume of real activity is what hides the fraud.
This is why the same payment redirection fraud that runs all year becomes especially dangerous now. The control that stops it, verifying bank-detail changes by phone on a known number, is exactly the control most likely to be skipped when someone is trying to clear a hundred invoices before 30 June. The pressure that defines the season is the pressure that erodes the defence.
Who do tax-time scams target in a business?
Finance teams, bookkeepers and anyone who approves payments, alongside individual staff expecting tax refunds. Attackers exploit the EOFY surge of large, legitimate transactions to slip fraudulent invoices and bank-detail changes past busy staff, and impersonate the ATO, accountants or payroll providers whose messages are genuinely expected at this time of year.
What it means for your finance team, in practice?
The lesson is not “be more suspicious in winter”. Vigilance that switches on seasonally is unreliable. The lesson is that your process needs to be strong enough to hold under the exact pressure that peaks now.
Here is what that looks like.
Verification does not get suspended because it is busy. The rule that every bank-detail change is confirmed by phone on a known number has to hold hardest in June, precisely when it is most tempting to skip. If anything, tighten it now.
Slowing down is protected, not punished. Tell your finance team explicitly that taking the extra minute to verify, even at the busiest moment, is exactly what you want, and they will never be blamed for it. The season’s pressure pushes people to be fast and accommodating, which is what the scam relies on.
The ATO’s own rules are the giveaway. The ATO does not send unsolicited SMS or email with links, does not ask for details via those links, does not demand immediate payment, and does not threaten arrest or ask for gift cards or cryptocurrency. Any message that does any of these is a scam, full stop. Share this with your whole team before July.
Expect the impersonation of trusted names. Your staff should treat an unexpected message from “the ATO”, “our accountant” or “payroll” with more caution in tax season, not less, because those are the exact identities being spoofed right now.
Multi-factor authentication matters most when phishing peaks. Since fake login pages harvesting credentials are a core winter tactic, MFA on email and finance systems is the safety net that limits the damage when someone does click. It also supports your Privacy Act reasonable-steps obligations.
Byteway Expert Insight
What we notice is that the businesses caught out in winter are not caught by anything new. They are caught by the ordinary scams that run all year, landing at the one time their defences are naturally weakest. The finance manager who would normally ring a supplier to check a bank-detail change is, in late June, trying to clear the backlog before the deadline, and just this once processes it on trust. That once is the whole game.
So our advice to clients before every tax season is not to invent new controls. It is to reinforce the ones they already have, right when the pressure is about to test them. Brief the finance team in May or early June, not July. Remind everyone what the ATO will and will not do. Make it explicit that verification is non-negotiable even at the busiest moment, and that nobody will be criticised for slowing a payment down. It is a fifteen-minute conversation that prevents the most expensive mistake of the year.
The season does not create new threats. It removes the friction the old ones usually run into. Put the friction back deliberately, and winter becomes far less dangerous.
How Byteway helps?
Byteway prepares finance teams for scam season with a pre-tax-time briefing and the controls that hold under pressure: multi-factor authentication, email security, a payment verification process, and staff awareness of the specific tax-season tactics. The goal is a finance team that stays protected precisely when it is busiest.
Where we fit:
- We brief your finance team on the specific scams that spike at EOFY and tax time.
- We put multi-factor authentication and email security in place, so phishing and credential theft are contained.
- We help set a payment verification process that survives the June rush.
- It connects to your wider managed IT and cyber security, so the protection is maintained year round, not just remembered in winter.
Get your finance team ready before the rush
Winter scam season is predictable, which is the good news. You know when it is coming, which means you can prepare for it rather than react to it. The businesses that sail through are the ones that reinforced their process before the pressure arrived.
Byteway runs a pre-tax-time security briefing for finance teams, and puts the underlying controls in place so your busiest weeks are also your safest. It connects to our cyber security and managed IT services, so it is maintained all year.
Book a finance-team security briefing before tax time. We will prepare your people and check your controls before the season tests them.
Frequently asked questions
Why is winter scam season in Australia?
Because Australia’s winter contains the end of financial year on 30 June and the start of tax return season on 1 July. Tax impersonation scams, rebate scams and business payment fraud all spike from June to October, when finance teams are busiest and staff are expecting tax-related messages. The driver is the financial calendar, not the weather.
When do tax scams peak in Australia?
The ATO consistently records its highest scam report volumes between July and October. In July 2025 it received 7,420 impersonation scam reports, a 75 per cent rise from June. The lead-up through June, around EOFY, is also high risk for business payment fraud because of the volume of legitimate transactions.
How can I tell a fake ATO message?
The ATO does not send unsolicited SMS or emails containing links to log in, does not ask for personal details through such links, does not demand immediate payment, and never threatens arrest or asks for gift cards or cryptocurrency. Any message doing these things is a scam. When unsure, contact the ATO through official channels you find yourself.
Why are finance teams targeted at tax time?
Because EOFY is when the most money moves, in the largest amounts, under the most time pressure. That surge of legitimate large payments and bank-detail changes is the perfect cover for fraudulent ones, and busy staff are more likely to skip verification. Attackers deliberately time invoice fraud to this period.
What is the most important protection for my business in scam season?
A payment verification rule that holds under pressure: every bank-detail change confirmed by phone on a number you already have, ideally with a second approver, applied even at the busiest moment. Combine it with multi-factor authentication on email and finance systems, and a team briefing before July.
Should we brief staff, and when?
Yes, and before the season starts, ideally May or early June. Remind everyone what the ATO will and will not do, reinforce the payment verification rule, and make clear that slowing down to verify is expected and protected. Briefing in July, once the scams are already arriving, is later than ideal.
Does this only affect big businesses?
No. Small businesses are heavily targeted, and false billing is the most reported scam type for small businesses in Australia. Smaller finance teams often have less process and more pressure, which increases the risk. The controls in this article are designed to be practical for a small team.