The short version
Key points
- A legitimate myGov email shown in the video only advises that a new message is waiting and contains no links.
- The scam email impersonates a Medicare communication and includes a link to a fake myGov login page.
- The fake page can request names, dates of birth, addresses, phone numbers, identity document details and bank information.
- The scam then redirects the user to the genuine myGov login page, potentially making the earlier data collection less obvious.
- The safest first step is to open myGov directly rather than using a link in an email.
The legitimate myGov email
The video compares a genuine myGov notification with a phishing message. The legitimate email is short and says that a new message is available in the recipient’s myGov inbox. It does not include a link or provide additional information about the message.
The sender information shown in the video identifies the email as coming from my.gov, with a no-reply address. The important point is that the recipient is expected to log in to myGov independently, rather than using a link in the notification.
How the scam email looks
The suspicious email claims that a secure Medicare communication is waiting in the recipient’s myGov inbox. Unlike the genuine notification, it contains substantially more text, a reference code and a link.
The message uses wording and presentation intended to appear official. The video also notes the use of “member” rather than a personal name, and American spelling, including “authorized” with a zed. These details may be easy to overlook when the overall appearance resembles a government communication.
The email appeared to have been delivered through a mailing service and was signed using a domain that made it look more legitimate to email systems. This may have helped it reach the inbox rather than being automatically filtered as spam.
The fake login page
The link opened a website that looked very similar to the real Australian myGov login page. The video identifies the link as using the domain “gov.cutsrates.com”, followed by a session path, rather than the genuine myGov website.
One visible difference was that the fake page did not include the myGovID identification option shown on the real site. However, the page was convincing enough that a person who clicked the email could continue without immediately recognising the problem.
To demonstrate what happened, Pat entered invented login details. The page then appeared to request an SMS code, followed by more information. The video suggests that the fake service was passing information through to the real myGov service, while using the process to collect details from the victim.
What information the scam requests
The fake page requested a full name, date of birth, address and phone number. It also asked for identity document information, including a driver’s licence number and passport information, along with bank details such as a BSB and account number.
After these details were entered, the page requested another SMS code. It then returned the user to the genuine myGov login page. This final redirection could make someone believe that the first attempt had simply failed and that no information had been submitted.
The video warns that the combination of personal, contact, identity and banking details could be used for identity theft or other fraudulent activity. The demonstration used fabricated information, apart from a real bank account number that Pat said he remembered, so viewers should not reproduce the process with their own details.
What to do instead
Do not use links in unexpected myGov emails. Instead, open myGov directly using a known method and sign in there to check whether a message is waiting.
Compare the sender, wording and website address carefully, but do not assume that an email is safe simply because it reaches the inbox or looks official. If a message asks for extensive personal or financial information, treat it with particular caution.
The video is dated 16 March 2024. Its warning concerns the specific email and fake website demonstrated at that time, so the appearance, wording and web address of similar scams may differ.
TechManPat’s conclusion
I see this as a particularly convincing phishing scam because it imitates the myGov experience, collects several categories of sensitive information and then sends the user back to the real website. My advice is to treat unexpected myGov links with caution and always sign in through myGov directly rather than through the email.
This knowledge-centre summary is based on the linked TechManPat video and reflects the information available when it was published. Check current pricing, availability and policies before acting.



