Gridware Logo

Our Last Census Faced 1 Billion Attempted Cyberattacks. What will hackers try next week?

By Ahmed Khanji Updated 6 August 2026 3 min read

in 𝕏
Our Last Census Faced 1 Billion Attempted Cyberattacks. What will hackers try next week?

On Tuesday 11 August, millions of Australians will complete the 2026 Census.

Around 85% of responses are expected to be submitted online, making it one of the largest digital events Australia will run this year.

Most people will only interact with the Census for a short time. They’ll open the online form, answer the questions and submit it. Behind that process is a large network of systems responsible for collecting and protecting sensitive information from households across the country.

This makes cybersecurity risks a major part of delivering the Census successfully.

Where the risks come from

One of the biggest challenges with the Census is that everyone knows exactly when it’s happening. Cybercriminals know when Australians will be expecting messages from the government and when the Census website is likely to be at its busiest.

There are two main ways they could take advantage of this.

The first is by targeting the technology behind the Census. Attackers might try to disrupt the online form, find vulnerabilities or access Census information. The last Census gives us some idea of the scale. In 2021, the ABS reported repelling approximately one billion attempted cyberattacks.

The other risk is impersonation. Scammers can pretend to represent the ABS through fake calls, emails or text messages. Because Australians are already expecting Census communications, these scams are usually much easier to believe.

How the ABS is preparing

The Australian National Audit Office reviewed the ABS’s cybersecurity preparations earlier this year.

The audit identified four areas for improvement. These covered risk management, cybersecurity advice, security documentation and risks within the wider ABS technology environment. The ABS accepted all four recommendations.

The ABS also says the online Census service was developed using Secure-by-Design principles. Its preparations include ethical hacking, Australian-hosted cloud infrastructure and continuous monitoring through a 24-hour Security Operations Centre.

How to recognise genuine Census contact

The ABS has warned Australians about scammers impersonating the Bureau and requesting personal information.

According to the ABS, genuine Census text messages will use the sender name CENSUS. Other official ABS messages will use ABSGov.

The ABS will never ask for bank details, tax file numbers or passwords through a text message.

If you receive a message and are unsure whether it is genuine:

  • Do not click the link in the message.
  • Visit the official Census website or myGov directly.
  • Do not provide banking details, passwords or your tax file number.
  • Verify unexpected calls using the contact details on the official ABS website.

These precautions are worth sharing with family members, colleagues and anyone who could be uncertain about how the ABS will contact them.

Scammers don’t need to breach your organisation to use your name

Whenever an organisation asks customers to provide information online, scammers have an opportunity to impersonate it. They can copy its branding, invent a convincing request and reach customers without ever accessing the real platform.

This could happen during a customer survey, account migration, event registration or new client onboarding process. It could also involve a fake password reset, invoice, payment request or message asking customers to confirm their contact details.

These scams become more convincing when customers are already expecting to hear from the organisation. Businesses should explain what genuine communications will look like, what information they will request and where customers can safely verify a message. Staff also need a clear process for handling reports of suspicious contact.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.