identity.org.au

Security

Recognising scams and phishing

The patterns scammers use against digital-identity users, and the habits that defeat them.

Last updated 20 July 2026

Scammers target people, not cryptography. The wallet's design removes the most valuable prizes — there is no central password to steal and no document vault to raid — so scams against wallet users rely on tricking you into approving things or revealing things. These are the patterns to recognise.

The approval push

You get a call, text or email creating urgency: “your identity is compromised, approve this verification now to secure it.” The goal is to make you approve a consent request the scammer initiated.

Only approve requests you started yourself, moments ago, in a service you are actively using. There is no legitimate reason for anyone to phone you and ask you to approve a wallet request.

The fake wallet app

A copycat app or website imitates the wallet and asks you to “verify” by scanning your documents into it. The real wallet is open source and has no official app-store listing — treat any store listing or download link sent to you as hostile. Check sources against the official repository linked from this site's about section.

The impersonated service

A phishing email pretends to be a service you use and links to a lookalike site that asks you to connect your wallet. Before approving anything, check the request details your wallet shows you: the requesting service's identity is part of the consent screen. If the name does not match who you think you are dealing with, decline.

Habits that defeat all of these

  • Slow down. Urgency is the scammer's only real tool. Nothing about your identity requires action in the next five minutes.
  • Read the consent screen. Your wallet states who is asking, for what, and why — every time.
  • Never share your screen or read out codes while dealing with your identity.
  • Remember what can never happen: no one from identity.org.au, DETIO Foundation or VirtEngine will ever contact you asking for approvals, codes, documents or remote access.
  • Report attempts to Scamwatch (scamwatch.gov.au) and, for wallet-related phishing, to [email protected].