MPM Logo
We're currently experiencing technical issues with our client portal (web and app). Rest assured our tech experts are investigating and we're working to fix it as swiftly as possible.

How to spot a scam: tips for NDIS participants

A laptop keyboard is illuminated by the laptop screen.

Scammers are getting more sophisticated in their attempts to steal peopleโ€™s private information and move their National Disability Insurance Scheme (NDIS) funding into their own pockets. This can be done using a variety of simple but increasingly common tactics, like a text message, email or phone call from a scammer masquerading as a disability provider.

You have to be careful to keep your funding secure, so weโ€™re here to guide you on some of the most common scams reported.

Phishing attacks

Scammers use phishing to steal confidential information through fraudulent messages so they can commit a crime.

In phishing attacks, people typically receive a text message, email or phone call claiming to be from their bank, a company, or a person โ€“ and theyโ€™re usually asked to click a link to transfer funds or provide information, like a credit card number.

If youโ€™re contacted in this way and asked to provide confidential information โ€“ like your NDIS participant number โ€“ it could be a scam. Be sure to report it to the National Disability Insurance Agency (NDIA) by calling the NDIS Fraud Reporting and Scams Helpline on 1800 650 717 or by emailing fraudreporting@ndis.gov.au.

Watch out for

  • Unexpected requests for information โ€“ legitimate companies will never ask for private information, including passwords and PINs, in an unsolicited text message, email or phone call.
  • Urgency โ€“ if the text message, email or phone call creates urgency to act, itโ€™s likely to be a scam. Scammers create urgency because they want their target to act quickly and not think too much about what theyโ€™re being asked to do.
  • Suspicious content โ€“ if you receive a text message or email that contains spelling errors or incorrect details, or if it doesnโ€™t look quite right, it could be a scam.

Compromised email attacks, impersonation scams and accounting fraud

A compromised email attack is type of phishing attack that involves a scammer taking over the email account of a business and tricking a person into sending them money or providing confidential information. For example, a scammer may pretend to be a disability provider and send you an email to ask for your myGov password or your NDIS participant number.

When a scammer claims theyโ€™re someone theyโ€™re not to get hold of confidential information, money or funding, this is known as an impersonation scam.

Scammers are also known to set up fake email addresses that look legitimate but arenโ€™t. Often, they include the name of a well-known company to help to convince a person to share private information.

Another type of cybercrime is email spoofing, which involves a scammer changing an email template to make it look the same as an email from a legitimate sender. They do this so they can get confidential information or money.

When a cybercriminal uses email spoofing to submit fake invoices to a plan manager, this is known as accounting fraud.

Watch out for

  • Emails claiming to be from legitimate companies, that request private information (like your NDIS participant number or credit card details), or that ask you to make a payment โ€“ these emails are usually written in a way that creates urgency to act.
  • SMS notifications from My Plan Manager that alert you to an invoice you werenโ€™t expecting, or which doesnโ€™t seem quite right โ€“ if this happens, please call us on 1800 861 272 from 8am-5.30pm (SA time), Monday to Friday, so we can investigate. If you arenโ€™t currently receiving SMS notifications from us, you can call and ask us to switch them on.

Remote access scams

When a scammer โ€“ claiming to be from a legitimate company โ€“ contacts a person and convinces them to hand over control of their electronic devices remotely (by installing malicious software or enabling remote login), thatโ€™s known as a remote access scam.

Remote access scams can be initiated via a phone call, email, or text message, or even through pop-up ads that claim the user has a virus and include a phone number to call to fix it.

Remote access scammers gain access to personal information of the person they contact โ€“ information like their NDIS participant number, bank account details or credit card number. Often, they try to intimidate the person or use technical words to confuse them and create a sense of urgency.

Watch out for

  • Unsolicited contact โ€“ remote access scams typically start with a text message, email or phone call to try to convince the person thereโ€™s a problem with their device or a payment.
  • A pushy or agitated caller โ€“ if you receive a call from someone who becomes noticeably frustrated or forceful when you question what they ask you to do, thereโ€™s a good chance itโ€™s a scam.
  • Unusual requests โ€“ if you receive a call, email or text message asking you to log into a bank account, make a payment, or provide security codes or passwords, itโ€™s likely it is a scam.

For more information on scams, click the links below.

If you receive a text message, email or phone call that asks you to share your information, and itโ€™s unexpected or doesnโ€™t look quite right, be sure to stop and think before you do anything.

The NDIA explains how to report suspicious behaviour here. Alternatively, you may wish to contact the NDIS Quality and Safeguards Commission.

You may also like...

Three people sit around a table, talking

Is NDIS plan management best for you?

A man using a braille keyboard with a laptop.

What's the deal with assistive technology in the NDIS?

Street signs that reads 'HELP, ADVICE, SUPPORT, GUIDANCE'.

What exactly does a plan manager do?

A mum and her daughter sit next to each other on a sofa. Both have laptops.

How to get a copy of your NDIS plan

magnifiercrossmenu linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram