
On Monday last week, more than 10,000 Australians opened an email from the National Anti-Scam Centre.
It wasn't a newsletter. It was a notification. British police had been investigating an organised crime group that targeted people who use cryptocurrency exchanges and hardware wallets. Arrests were made. And when investigators went through what the group held, they found the contact details of thousands of Australians sitting in it.
So the NASC wrote to them, and the core of the message was this: your details may still be circulating among criminal networks, and you should expect to be approached.
Sit with that for a second. Not "you were scammed." Not "you lost money." Just: your name is on a list, the list has been copied, and the people who have it are not finished.
This is the part of cybercrime that almost nobody explains properly. And this week - Scams Awareness Week, 24 to 28 August, running under the theme "No one's just a number" - is exactly the right time to explain it.
Because to the person about to ring you, you are precisely that. A number. Row 41,207.
Four breaches. One week. All of them yours.
Last week wasn't unusual. That's the uncomfortable part.
Oz Hair and Beauty. An extortion group published customer data from the online beauty retailer, and on 19 August the breach was loaded into Have I Been Pwned: two million unique email addresses, alongside names, phone numbers, suburb and postcode, and purchase history. Cyber Daily reported the stolen set at around 2.1 million records, including the last four digits of active gift cards. The company has said its investigation indicates the data was held by a third-party provider.
Quest Apartment Hotels. On 17 August, Quest identified unauthorised access to a database through a vulnerability at a third-party service provider. Customers were emailed on 19 August. Exposed: full names, email addresses, contact details, and a small number of dates of birth, from records predating June 2025. Quest's own advice to customers is worth repeating, because it tells you what they expect to happen next - don't click unexpected links or open attachments, even if they appear to come from the hotel.
A Melbourne medical group. The Rhysida ransomware crew listed a nine-clinic Victorian GP practice on its leak site on 12 August, claiming around 20,000 patient records containing names, dates of birth, Medicare numbers and clinical notes. That figure is the attackers' claim and hasn't been confirmed by the practice, which has said it is investigating and has notified the regulator.
A Melbourne dental clinic. A separate group claims 37 gigabytes taken from a suburban dental practice, spanning 2003 to 2025 - X-rays, referrals, treatment records, consent forms. Again, an attacker's claim. The clinic declined to comment.
And behind all of that, still working its way through the country: Origin Energy, which confirmed in late July that around 900,000 current and former customers were affected. By Origin's own account, the exposed data may include name, address, date of birth, contact phone number and account information - along with the last four digits of a credit card, or the last three digits of a bank account.

You cannot opt out of most of this. You didn't choose the dental clinic's IT vendor. You didn't audit the beauty retailer's third-party database provider. You bought shampoo, you booked a room, you got your teeth cleaned, you paid an electricity bill. That's the whole extent of your involvement.
Which is why the guilt reflex - I should have been more careful - is misdirected here. Being careful was never on offer.
The breach is not the attack
Here's the thing that changes how you think about all of it.
When a breach is announced, the media covers it like the event is over. Data was taken; here's the number; here's the statement. And then coverage stops, because nothing else appears to be happening.
But a stolen customer database is not the crime. It's the shopping list. The crime happens weeks or months later, when someone works down the list and calls you.
And when they do, they will not sound like a scammer. They'll sound like someone who already knows you. They'll have your full name and use it correctly. They'll know your suburb. They'll know you're an Origin customer, or that you stayed at that apartment hotel in March, or that you bought a particular brand of hair product last spring.
That knowledge is the entire weapon. Every piece of true information they open with buys them a little more of your trust, and trust is the only thing they actually need. By the time the request arrives - click this, confirm that, move your money to a safe account - you've already decided they're legitimate. You decided it in the first fifteen seconds, based on the fact that they knew things.
The gap between the breach and the call is the reason people never connect the two. Nobody thinks this is about the shampoo I bought last year. They think my bank is calling.

What changed this year
Two things, and both of them landed in the news last week.
On 17 August, ASIC published its annual scam takedown figures, and they are genuinely startling. In the last financial year the regulator removed 19,400 online scams - a 182% increase on the year before. Fake investment platforms taken down: 7,051, up 151%. Phishing links removed: 5,476, up 279%.
ASIC also named the public figures most often impersonated in AI-generated investment scams - a list that includes the Prime Minister, Alan Kohler, Dick Smith, Gina Rinehart, Jacqui Lambie and Pauline Hanson - with $7.4 million in losses attributed to those impersonations alone.
ASIC Chair Sarah Court put the problem plainly: "AI is making investment scams more convincing and harder to detect. A simple online search is not enough to verify whether an opportunity is legitimate."
And she added the line that matters most for anyone still using the old advice: "The presence of polished content, familiar branding or convincing testimonials does not mean an investment is legitimate."
That's the second change, and it's the bigger one. The old tells are dead. Spelling mistakes, clumsy grammar, dodgy logos, stilted phrasing - every one of those was a symptom of a human criminal with limited English and limited time. Generative tools removed that constraint entirely. The fakes are clean now.
The ABC demonstrated exactly this last week, publishing an investigation into a global fraud operation that had been producing fake ABC News articles as scam lures - counterfeit stories, on counterfeit pages, using the ABC's own branding to make an investment look credible. More than 4,000 Australians were targeted.
So when a stolen list meets tooling that can generate a flawless personalised approach at scale, you get where we are now: a convincing message, addressed to you by name, referencing something true about your life, wrapped in a brand you recognise.
Checking whether something looks real stopped being a useful skill. What's being asked of you is now the only reliable test.
The three lists you're probably on
The breach list. Your details from a company that got hit. This is the big one, it's usually accurate, and it's cheap to buy.
The "sucker list." This one is genuinely nasty. Criminals keep and trade the details of people who have already been scammed, because a person who fell for one thing is considered a warmer prospect for the next. It's what powers recovery scams - someone contacts you claiming they can get your lost money back, for a fee. The ACCC has been warning about this for years, and older Australians are hit hardest, both in volume and in average loss.
If you have ever been scammed, you should assume you are on this list, and treat any unsolicited offer of help recovering the money as a second attempt on the same person.
The scraped list. Everything about you that was never breached at all, because it was already public. Social profiles, community club pages, school newsletters, birthday posts, real estate listings, the photo captioned with your dog's name - which is also, statistically, somebody's password.

Six things worth doing this week
Not a lecture. Six things, roughly in order of how much protection they buy you per minute spent.
1. Find out what's already out there. Put your email address into SelfCybr's free Digital Identity Health Check. It tells you which breaches your details have already turned up in, in plain language, and what's worth doing about each one. It's free, there's nothing to install, and your details don't leave Australia.
It tends to be a useful shock - and it makes everything below feel a great deal less abstract.
If you'd like a second opinion, `haveibeenpwned.com` is the best-known international reference and is also free.
2. Lock-down your email before anything else. Turn on two-factor authentication on your email account today, and use an authenticator app or passkey rather than SMS if it's offered. Your email is not one account among many - it's the master key. Anyone holding it can reset everything else you own.
3. Stop reusing passwords. The reason a five-year-old beauty-retailer breach matters is that the password in it might still open your banking. A password manager solves this permanently, and there are good free options.
4. Agree a family code word. One word, agreed out loud, never written down or texted. If someone rings sounding like your daughter, your grandson, your business partner - distressed, urgent, needing money right now - you ask for the word. Voice cloning is a consumer-grade tool in 2026, and Scamwatch's own guidance is that a few seconds of a recording is enough. This costs nothing and it is the single best defence against the most frightening version of this crime.
5. Put a ban on your credit file. If your identity documents have been exposed, you can request a free credit ban with Equifax or Experian - illion is now part of Experian. Better still, you can ask one credit reporting body to pass the request on to the other two, so it's a single phone call. A ban stops new credit being opened in your name, runs for 21 days, and can be extended. Most people have never heard of it, and it's one of the most effective things available.
6. Have the conversation. Ring the person in your family who lives alone. Tell them what a real call sounds like, and what one doesn't. Give them permission - explicitly - to hang up on anyone, including you.

When someone knows things about you
The hardest version of this is the phone call from a person who has your data in front of them.
Here's what makes it survivable: knowing things about you is not identification. It never was. It just feels like it, because in ordinary life only people who know us know things about us. That instinct is correct almost every day, and completely wrong on the one day it matters.
So you don't have to work out whether the caller is real. You just have to move the conversation somewhere you control:
"I'm going to hang up and call you back on the number on my card."
That's it. That's the whole defence. A real bank, a real government agency, a real utility will not be remotely bothered - they are trained for it and they hear it constantly. Anyone who argues, escalates, warns you not to hang up, or tells you the matter is too urgent to wait has just answered the question for you.
The pressure not to hang up is the scam. No legitimate call is ever ruined by you ringing back on a number you looked up yourself.
If it's already happened
Say this part out loud, because it's the bit that stops people acting: this is not a failure of intelligence, and there is nothing to be embarrassed about.
Australians reported $2.18 billion in losses across more than 274,000 reports involving a financial loss in 2025. These are professional operations with call scripts, org charts and quality control, engineered to work on careful people having a busy day. Shame is the reason most people wait — and waiting is the only thing that reliably makes it worse.
- Call your bank now, on the number on the back of your card. Ask them to stop or reverse the payment and freeze the account. Minutes matter here more than certainty.
- Change the password on the affected account, and anywhere else you used the same one.
- Report it to Scamwatch at `scamwatch.gov.au`, and to `cyber.gov.au`.
- Call IDCARE on 1800 595 160 if identity documents were involved. Free, Australian, and they will build you a response plan.
- Tell someone. The people who recover fastest are the ones who said it out loud early.
And one warning specific to this week: if you have already been scammed, expect a second approach offering to recover your money. Government agencies do not charge fees to recover funds. The NASC has been explicit that it will never request money or sensitive information, and will never send a text with links, attachments or a number to call.
No one's just a number
That's the theme of Scams Awareness Week this year, and it's a better line than most campaign slogans get.
Behind each of those 274,000 loss reports is a real household. Someone's mum, someone's neighbour, someone who had an ordinary Tuesday interrupted by people who do this for a living and go home at five.
The criminals genuinely do see a spreadsheet. Row 41,207, aged 68, Perth, Origin customer, mobile number confirmed working. That's the whole of you, as far as they're concerned.
Everyone else in your life sees a person. The gap between those two views is where this crime lives - and closing it takes about five minutes and one phone call to someone you love.
Make that call this week.
How we help
SelfCybr helps Australian individuals and families see what's exposed, fix it, and learn how to stay ahead of it. No jargon, no shame, no data sold — ever. Australian-owned, Australian-hosted.
Sources and further reading
- National Anti-Scam Centre / Scamwatch — National Anti-Scam Centre contacts more than 10,000 Australians following international cryptocurrency scam investigation, 17 August 2026
- Scamwatch — Scams Awareness Week 2026 ("No one's just a number", 24–28 August)
- ASIC — Media release 26-195MR, ASIC warns scammers are using AI to spin vast webs of deception, 17 August 2026
- ABC News — Fake ABC News articles are promoting scams. The money leads to an international fraud network, 20 August 2026
- ABC News — Quest Apartment Hotels customers' personal data exposed in security breach, 19 August 2026
- ABC News — Origin Energy believes 900,000 customers' data accessed in breach, 28 July 2026
- Have I Been Pwned — Oz Hair and Beauty breach entry, added 19 August 2026
- Cyber Daily — reporting on the Oz Hair and Beauty, SIA Medical Centre and Brighton East Dental incidents, 18–20 August 2026
- Cyber Daily - Patient data potentially compromised in alleged dental clinic data breach, 18 August 2026
- ACCC / National Anti-Scam Centre — Targeting Scams report, 30 March 2026
- ACCC — Criminals targeting victims of previous scams promising financial recovery
