Nothing you type leaves your phone. Recent checks are remembered on this device only.
Cooee could not reach the network, so this is the copy your phone saved on 2026-09-08 — the checks all still work, but if an organisation has changed a number since then, this will not know.
Fraud line first. Tap a number to call it. This is not a complete list — these organisations publish other legitimate numbers too, so a number missing from here is not evidence of a scam.
Commonwealth Bank
Call 13 2221, or message in the CommBank app. Forward suspicious emails and texts to hoax@cba.com.au.
Message 'Report fraud' in the ANZ app (24/7), or call 13 22 73 for cards, 13 33 50 for internet and business banking. Forward hoax messages to hoax@cybersecurity.anz.com.
Call 1300 236 344, or 1800 035 383 (24/7) for a lost or stolen card. Bendigo states it will never call you from +61 3 5485 7872 or +61 3 5485 7123 — both are used to impersonate them.
Bendigo Bank says it will never call you from these numbers.
If one of them shows as your caller, the caller ID has been forged. Listed so you can recognise them — not as a number to ring.
(03) 5485 7872 Lost or stolen cards from overseas — Bendigo will never call from this number
(03) 5485 7123 Known impersonation number — Bendigo will never call from it
Bank of Queensland
Call 1300 55 72 72 — the same line handles fraud and scam reports and lost or stolen cards, including after hours.
Call 1800 052 743 for scams and fraud, 24/7. ING states that its staff will never call and ask you for your card or account details over the phone, or ask you to enter them into your keypad.
Call 13 17 19, or +61 8 9449 2840 from overseas. Bankwest is part of the Commonwealth Bank group; suspicious emails and texts can be forwarded to hoax@cba.com.au.
Call 13 12 21 in business hours. Outside them, the Fraud Bureau Service on 1300 705 750 — a service shared by many mutual banks, not Teachers Mutual’s own line.
Call 1800 033 139. Defence Bank publishes a warning that scammers impersonate its own fraud team, so do not use any number you were given — use that one.
Agencies impersonated often enough to be worth checking. Read the note under each one: some publish a policy about how they call you, which is stronger evidence than any list of numbers. This is not a complete list — these organisations publish other legitimate numbers too, so a number missing from here is not evidence of a scam.
Australian Taxation Office
If you are not sure a call, email or SMS is really the ATO, do not respond — call 1800 008 540 to check. The ATO will never threaten you with arrest, demand you stay on the line, or ask for payment by gift card, crypto or cash delivery.
Australian Taxation Office publishes that its calls show no caller ID at all. In their words: “Phone calls from the ATO will show as No Caller ID.”
The numbers above are Australian Taxation Office’s own and ringing them is right. But it also settles the
other direction: any number displayed as Australian Taxation Office calling you has been forged — these
ones included, because an organisation’s own published numbers are the obvious ones to imitate.
There is no number Australian Taxation Office will ring you from.
Services Australia publishes a line per programme rather than one fraud number. For a debt you are unsure about, call the Centrelink debt recovery line on 1800 076 072 — never a number given to you by the caller. For myGov specifically, call the Online Services Support Hotline on 132 307 and select option 1.
VicRoads takes reports through the message form on their site. Links in their genuine texts and emails use go.vic.gov.au, and their emails come from info@vicroads.vic.gov.au.
Your telco is who to tell if your number has been ported away from you without your knowledge, which is how a scammer gets past a code sent by text. This is not a complete list — these organisations publish other legitimate numbers too, so a number missing from here is not evidence of a scam.
Telstra
Call 13 22 00, Telstra's general customer service line. Their contact page publishes no separate fraud number.
Billing and disconnection threats are a common approach. Your retailer’s own number is on your bill as well as here. This is not a complete list — these organisations publish other legitimate numbers too, so a number missing from here is not evidence of a scam.
EnergyAustralia
Call 133 466. Their contact page publishes no separate fraud number — an overdue-bill demand pressing you to pay immediately is the common impersonation, and a real retailer will let you call back on the number on your bill.
Impersonated most often at claim time and around premium increases. Several publish a “we will never ask you” statement — read that under the organisation, it is stronger than any list of numbers. This is not a complete list — these organisations publish other legitimate numbers too, so a number missing from here is not evidence of a scam.
Medibank
Call 132 331. Medibank publishes no reporting address and asks that scam messages go to Scamwatch.
Bupa says it will never call you from this number.
If one of them shows as your caller, the caller ID has been forged. Listed so you can recognise it — not as a number to ring.
(03) 9454 8814 Bupa says scammers display this number — it is not theirs
nib
Call 13 16 42. Forward phishing emails and calls to nib@nib.com.au with “phishing” in the subject.
A super balance is the largest sum most people have and the hardest for them to check, which is why these are impersonated. Every fund here says the same thing: they will never ask for your login details. This is not a complete list — these organisations publish other legitimate numbers too, so a number missing from here is not evidence of a scam.
AustralianSuper
Call 1300 300 273. AustralianSuper publishes no reporting address.
An unpaid-toll text is the most impersonated message in the country. Linkt publishes the numbers it may actually call you from — ten of them, all ordinary landlines, because its 13 number cannot dial out at all. This is not a complete list — these organisations publish other legitimate numbers too, so a number missing from here is not evidence of a scam.
Linkt
Report it on Linkt’s own form at linkt.com.au/contact-us/report-scam, then delete the message. They ask for the mobile number that sent it — that is what they pass to the telcos to have blocked. Linkt publishes no email address for reports.
EastLink asks you not to report it to them at all — their own page says “You do not need to report it to EastLink.” Do not click, do not reply, and delete it.
A missed-delivery message asking for a small fee is one of the most reported scams in Australia. This is not a complete list — these organisations publish other legitimate numbers too, so a number missing from here is not evidence of a scam.
Australia Post
Call 13 76 78 (13POST). Their published customer lines carry no separate fraud number — a missed-delivery text asking you to pay a fee or confirm details is the common scam, and Australia Post does not ask for payment that way.
For help after the fact — recovering identity documents, and working out what to do next. This is not a complete list — these organisations publish other legitimate numbers too, so a number missing from here is not evidence of a scam.
IDCARE
Call 1800 595 160 for free support if your identity or personal information has been misused.
A few minutes, and it is what the national scam figures are built from. Worth doing even if you lost nothing.
Your bank
Stop transactions and freeze accounts. Do this first if money has moved. Use the number on the back of your card or in the bank's own app — never a number the caller gave you.
What the National Anti-Scam Centre is warning about right now. The ones marked Matched automatically carry a rule written against that alert’s own words, so if what you describe when you check a number fits one, the answer says so — at most 2, most recent first, because an alert is context rather than evidence about any number. The rest are here to be read, and never reach an answer.
The National Anti-Scam Centre contacted more than 10,000 Australians via email after their contact details were identified during a United Kingdom police investigation into an organised crime group targeting cryptocurrency exchange and hardware wallet users across multiple countries.
With tax time 2026 fast approaching, Scamwatch and the Australian Taxation Office (ATO) are reminding Australians to be aware of communications claiming to be from the ATO or ‘myGov’.
Following the successful money laundering prosecution of the director of Blue Star Exchange Pty Ltd, the National Anti-Scam Centre contacted around 1,500 victims via email today.
Scammers are targeting people who use food delivery platforms, including restaurants, customers and delivery workers. They may pretend to be DoorDash, Uber Eats, a restaurant or a customer.
This scam alert is a joint alert from the Australian Communications and Media Authority (ACMA) and the National Anti-Scam Centre’s Scamwatch warning consumers of mobile fraud.
Scammers are setting up fraudulent websites offering personal loans.
Published by Scamwatch, National Anti-Scam Centre (ACCC) and read from its own alerts page, last on 2026-09-07. This is a copy taken on that date, not a live feed — check the page itself for anything newer. An alert describes a pattern that is current; it says nothing about any particular number, and Cooee never treats one as proof that a caller is a scammer.
If a stranger rang knowing your name and your bank, they may not have guessed. 14 recorded breaches, most recent first.
We do not check your email address here, and it is worth saying why. Every service that will tell you whether an address appears in a breach takes that address in plain text and keeps it. This page promises that nothing you type into it leaves your phone, and that promise is worth more than this feature. So the list below is the other way round: recognise the organisations you had an account with. That requires typing nothing about yourself.
If you do want an address checked, Have I Been Pwned is the one to use — run by a security researcher, free, and it will not sell you anything. You will be handing it your email address, which is the trade.
High
Qantas
Airline · 5.7 million people
A third-party call centre platform was reached by social engineering. Names, email addresses, phone numbers, dates of birth and frequent flyer numbers. Qantas stated no credit card details, financial information or passport details were held in that system.
Date of birthPhone numberNameEmail address
Why high: Unchangeable, and one of the three things almost every identity check asks for.
Reported to the OAIC and the Australian Cyber Security Centre Outcome source
A fertility clinic. Medicare numbers, private health insurance details, medical history and fertility treatment records were exfiltrated and later published.
Health recordsIdentity documentsDate of birthPhone numberHome addressName
Why severe: Sensitive information under the Privacy Act, and permanent. There is no version of your medical history you can reissue.
Reported to the OAIC; Supreme Court of NSW injunction restraining dissemination of the data Outcome source
Names, dates of birth and email addresses held in a cloud platform run by a third-party supplier. Ticketek stated no card or account details were involved.
Date of birthNameEmail addressGender
Why high: Unchangeable, and one of the three things almost every identity check asks for.
Ransomware attack on an electronic prescription provider. Prescription records — the medicines people were dispensed — along with names, addresses, Medicare and healthcare identifier numbers.
Health recordsIdentity documentsDate of birthPhone numberHome addressName
Why severe: Sensitive information under the Privacy Act, and permanent. There is no version of your medical history you can reissue.
MediSecure entered administration in June 2024 Outcome source
Around 7.9 million Australian and New Zealand driver licence numbers, plus roughly 53,000 passport numbers and a smaller set of financial statements.
Identity documentsBank or card detailsDate of birthPhone numberHome addressNameEmail address
Why severe: A passport, licence or Medicare number cannot be quietly changed. Replacing one costs money and weeks, and the old number stays useful to whoever holds it.
OAIC and New Zealand Privacy Commissioner joint investigation Outcome source
Customer names, dates of birth, Medicare numbers and health claims data — including the procedures people had claimed for — were taken and later published.
Health recordsIdentity documentsDate of birthPhone numberHome addressNameEmail address
Why severe: Sensitive information under the Privacy Act, and permanent. There is no version of your medical history you can reissue.
OAIC alleges Medibank seriously interfered with the privacy of 9.7 million Australians; civil penalty proceedings on foot Outcome source
Names, dates of birth, phone numbers, email and home addresses taken from current and former customers. For about 2.1 million people the records included passport, driver licence or Medicare numbers.
Identity documentsDate of birthPhone numberHome addressNameEmail address
Why severe: A passport, licence or Medicare number cannot be quietly changed. Replacing one costs money and weeks, and the old number stays useful to whoever holds it.
OAIC civil penalty proceedings on foot in the Federal Court Outcome source
There is no official list of Australian data breaches. The OAIC runs the Notifiable Data Breaches scheme and publishes the totals — 532 notifications in January to June 2025, 58% of them criminal attacks — but never names the organisation. So this list is compiled from public disclosures and each entry carries its source. A name missing from it means nobody here has recorded it, not that the organisation was never breached.
Tick the ones you actually use, print it, and cut along the line. It fits behind a bank card. Everything on it is a number the organisation publishes itself — nothing here is a number anybody has told you to ring.
CooeeReal numbers, checked 2026-09-08
If someone rings about your money: hang up and ring the number below yourself. Never a number they gave you.
Tick some organisations above and they will appear here.
IDCARE 1800 595 160 — free help if your details were taken. Numbers change: check daviddef.github.io/Cooee
In order. The first two are the ones that stop money moving; the rest can wait until tomorrow if it is late.
First
Ring your bank on the number from your own card — not one from the message. A payment can sometimes be stopped while it is still moving, and that chance falls away by the hour. Every bank’s fraud line is under Lists.
First
If identity documents were involved, ring IDCARE on 1800 595 160. Free, national, and they write you a response plan. This is the highest-value call there is and almost nobody knows it exists.
Today
Put a ban on your credit file. Free, and you must do it separately with each of Equifax, Experian and illion. It stops credit being taken out in your name, which is the loss that actually costs money.
Today
Change the password on any account named in the message, and turn on two-step verification — using the provider’s own app or website, never a link from the message.
This week
Report it. ReportCyber for anything you lost money to, Scamwatch for the pattern. It takes a few minutes and it is what the national figures are built from. Both are under “Who to tell”.
This week
Forward the message to the organisation itself. Sixteen of the ones we hold publish an address for exactly this — hoax@cba.com.au, phish@nab.com.au, scams@auspost.com.au and the rest. Name the organisation in a check above and the address appears.
Expect it
The calls will come. A leaked phone number paired with a name and a provider is the input a convincing scam call needs. It is why a stranger can know things about you they should not. “Where your details may already be” lists what has leaked and when.
On what you can get back: a company that leaks your data can be fined up to $50 million, and that money goes to the Commonwealth rather than to you. Individuals who complain to the Information Commissioner have recently been awarded roughly $1,500–$3,000 for distress, after complaining to the company first and waiting a year or more. There is no right to sue under the Privacy Act. That is the honest position, not a discouragement — complaining is still what makes the penalties happen.
Ranked by how much they actually change, not by how often they are repeated. Nothing here is a product we are paid to name — we do not recommend antivirus, because on a current phone it is close to the least useful thing on this list.
Biggest
Turn on two-step verification everywhere that offers it, starting with your email. Your email is the master key: whoever holds it can reset everything else. Use an app or a passkey rather than SMS codes where you can — a code by text can be intercepted by someone who ports your number away.
Biggest
Never act on a number, link or address that arrived in the message itself. This single habit defeats almost every scam on this site, because every one of them depends on you using the contact details they supplied. Look the number up yourself, or open the app.
Big
Put a ban on your credit file before anything happens. Free, renewable, and it blocks the most expensive kind of identity fraud outright. Equifax, Experian and illion, separately.
Big
Use a password manager and stop reusing passwords. Reuse is why one breached shop becomes a drained account. “Where your details may already be” shows which leaks included passwords.
Worth it
Keep your phone’s updates on automatic. On both iPhone and Android this closes the holes that malicious links rely on, and it is the reason antivirus matters far less on a phone than it did on a PC.
Worth it
Ask your telco for a port-out lock or extra account security. Taking over your mobile number is how somebody gets past a code sent by text. Telco numbers are under Lists.
Worth it
Tell one other person how you will contact them about money. Scams that work on families work by isolating one person. A rule agreed in advance — “I will never ask you for money by text” — costs nothing.
The Australian Signals Directorate publishes free step-by-step guides for securing phones, accounts and email at cyber.gov.au/protect-yourself. They are the national authority on this and they are not selling anything. If someone has already been targeted, IDCARE on 1800 595 160 is free and will write you a plan.
The number your phone displays is supplied by whoever placed the call, and it can be set to anything. Seeing your bank’s real number does not mean your bank is calling.
There is a useful tell. Numbers starting 13, 1300 and 1800 are inbound service lines — under the Australian numbering plan they cannot make outgoing calls at all. So if one of those shows as your caller, the caller ID has definitely been forged.
Some organisations go further, and where they do it is written in a red panel under that organisation in the lists above. A few publish specific numbers they will never ring you from — those are listed there to be recognised, not to be rung. And some publish that none of their calls display a number at all, which settles it for every number they have: a caller ID naming them is forged whatever it shows, including their own real numbers.
The reverse is also true: those same numbers are perfectly safe for you to ring. The direction is what matters.