Online tax returns have become the preferred way for many Australians to lodge their taxes. While convenient, submitting sensitive personal and financial information over the internet requires careful attention to security.
Cybercriminals increasingly target taxpayers through scams and identity theft attempts. Knowing how to protect yourself during online tax returns is essential to avoid serious consequences.

This step-by-step guide will help you secure your identity when lodging your tax return online in Australia. For verified information on this topic, you can also check the original source provided by the Australian Taxation Office.
Understanding the Risks of Online Tax Filing
Before focusing on protection methods, it’s helpful to understand the risks involved in submitting tax returns online.
Common Online Tax-Related Threats
- Phishing scams: Fake emails or websites that impersonate the ATO to steal login details
- Identity theft: Criminals use stolen personal information to file fraudulent tax returns and claim refunds
- Malware: Software that infects your device to capture sensitive data
- Unsecured networks: Public Wi-Fi or unsecured connections that allow data interception
Step 1: Use a Secure and Trusted Platform
The first step to secure your identity during online tax returns in Australia is choosing a reliable platform.
Lodging Through myGov and the ATO
- The ATO’s official myGov portal is the safest option for lodging your return online
- The site uses strong encryption and multi-factor authentication
- Always access myGov directly via the official URL, not through email links
Registered Online Tax Agents
- Using a tax agent registered with the Tax Practitioners Board offers added security
- Online tax agents use secure portals and comply with privacy laws
- Verify agent credentials before submitting your details
Step 2: Protect Your Login Credentials
Your login details are the key to your tax account, so protecting them is critical.
Create Strong Passwords
- Use passwords with at least 12 characters including letters, numbers, and symbols
- Avoid common words, personal information, or simple sequences
- Use a unique password for your myGov account, separate from other online accounts
Enable Two-Factor Authentication (2FA)
- 2FA requires a second verification step, such as a text message code or authentication app
- This adds a strong layer of protection even if your password is compromised
Keep Passwords Private
- Do not share your passwords or write them down where others can find them
- Beware of phishing attempts asking for login credentials
Step 3: Secure Your Devices and Network
The safety of the device and network you use matters greatly.
Keep Your Software Updated
- Regularly update your computer, phone, and apps to patch security vulnerabilities
- Use antivirus and anti-malware software
Avoid Public Wi-Fi
- Public or unsecured Wi-Fi networks can allow hackers to intercept your data
- Use a trusted private network or a Virtual Private Network (VPN) when filing your tax return
Log Out After Each Session
- Always log out from your myGov or tax agent portal after completing your session
- Close your browser window completely
Step 4: Be Alert to Phishing and Scams
Phishing remains one of the most common methods used by scammers to steal tax information.
Recognising Phishing Attempts
- Emails or messages claiming urgent action or threats related to your tax return
- Requests for personal details or login information via email or SMS
- Links that look similar but have incorrect URLs or suspicious domains
What to Do If You Suspect a Scam
- Do not click on suspicious links or attachments
- Report phishing attempts to the ATO via their official channels
- Forward scam emails to reportemailfraud@ato.gov.au
Step 5: Keep Your Personal Information Confidential
Protect your personal data beyond just your login credentials.
Limit Sharing Personal Details
- Only provide your Tax File Number (TFN) and identity details on official, secure sites
- Do not share your TFN or other sensitive information on social media or over the phone unless you initiated the contact
Shred Physical Documents
- Dispose of printed tax documents and receipts securely by shredding
- Avoid leaving sensitive information lying around your home or workplace
Step 6: Verify Your Tax Return Details Carefully
Errors in your tax return can attract unwanted attention or cause delays.
Double-Check Your Income and Deductions
- Ensure all income sources are accurately reported
- Claim only eligible deductions with proper evidence
Monitor Your Tax Account Regularly
- Log in to your myGov account regularly to check for unusual activity
- Report any discrepancies to the ATO immediately
Step 7: Use Strong Security Practices for Email and Communication
Your email is often a gateway to sensitive accounts.
Secure Your Email Account
- Use strong passwords and two-factor authentication for your email
- Be cautious of email attachments and links from unknown senders
Communicate Only Through Official Channels
- Only respond to ATO or your tax agent via verified contact methods
- Avoid providing personal information via phone or email unless you initiated contact
Step 8: Keep Records and Backups Securely
Proper record-keeping supports your tax return and protects your data.
Maintain Digital Copies Securely
- Store scanned copies of receipts and tax documents on encrypted devices or cloud services with strong security
- Backup files regularly to prevent data loss
Retain Records for Required Period
- The ATO requires you to keep tax records for at least five years
- Keep documents organised to facilitate easy access if needed
Step 9: What To Do If Your Identity Is Compromised
Despite precautions, identity theft can still occur. Knowing how to respond is essential.
Immediate Actions
- Contact the ATO as soon as you notice suspicious activity
- Report identity theft to the Australian Cyber Security Centre
- Change passwords and secure your accounts immediately
Follow-Up Steps
- Monitor your credit report for unusual activity
- Alert your bank and financial institutions
- Seek advice from identity protection services if necessary
Conclusion
Securing your identity during online tax returns in Australia requires careful attention to each step of the process.
By using trusted platforms, protecting your credentials, securing your devices and networks, and remaining vigilant against scams, you can lodge your tax return safely.
Keep your personal information confidential, verify your tax return details, and know how to respond if your identity is compromised. Following this guide will help protect you from costly identity theft and ensure a smooth tax filing experience.
Frequently Asked Questions
How can I tell if an email about my tax return is a scam?
Look for poor grammar, urgent threats, requests for personal information, and suspicious links. Always verify by logging into your myGov account directly instead of clicking email links.
What makes two-factor authentication important for myGov?
2FA provides an additional verification step, making it harder for hackers to access your account even if they obtain your password.
What should I do if I accidentally provide my details to a scammer?
Report the incident to the ATO immediately, change your passwords, and monitor your financial accounts for suspicious activity.