Scams in the Shadows: The Growing Use of Private Chat Channels

The Cyber Sushi


(serving up the cold facts, with some phish bytes)

Welcome back! Here's what we are covering in this issue:

  • Scams in the Shadows: The Growing Use of Private Chat Channels
  • Building Safer Communities Through Trusted Voices
  • Behind the mask: The Guide to New and Trending Scams
  • Ask IDCARE: ‘Are eSIMS safer than traditional SIM cards?’

Scams in the Shadows: The Growing Use of Private Chat Channels

Scammers and cybercriminals are increasingly moving their activities from public websites and forums into private messaging apps such as WhatsApp, Telegram and WeChat. These platforms provide greater privacy, making it harder for scams and criminal activity to be detected.

IDCARE's latest analysis found that scams involving private chat channels are becoming more common and often result in greater harm to victims. In 2025, private messaging apps were involved in 11% of all scams reported to IDCARE, up from just 4% in 2023.

Over the past year, IDCARE supported almost 6,000 people who reported scams involving private chat channels. Victims of these scams lost, on average, more than $16,000 extra per incident compared with victims of similar scams that did not involve private messaging apps.

Relationship, employment and investment scams were the most common scam types using private chat channels, accounting for almost two-thirds of all cases. Typically, scammers make first contact through social media, dating platforms or online advertisements before encouraging victims to continue the conversation in a private messaging app.

Private chat channels allow scammers to build trust over time, isolate victims from friends and family, and create convincing environments using group chats, fake success stories and constant communication.

The findings highlight the importance of being cautious when someone asks to move a conversation from a public platform to a private messaging app. Taking time to verify who you are communicating with and seeking independent advice can help prevent significant financial and emotional harm.

Building Safer Communities Through Trusted Voices


April and May marked the completion of IDCARE's two major Community Outreach and Resilience Clinics (CROCs) for 2026, with teams travelling across the Northern Territory and Western Australia to deliver cyber safety and scam awareness education to communities, service providers, small businesses and frontline workers.

While every community is different, one clear lesson emerged from both trips: our most effective model is working through trusted local leaders and community representatives. Sessions delivered to council staff, community workers, support organisations and other influential local contacts consistently achieved the strongest engagement. These participants are well placed to share key messages within their own communities, creating a more sustainable and culturally appropriate approach to cyber safety education than traditional one-off presentations.

Across both outreach programs, participants were highly engaged and eager for practical advice on topics such as password security, scam prevention, social media safety, identity protection and emerging AI-enabled scams. Many attendees shared their own experiences, creating valuable opportunities for discussion and peer learning.

A particular highlight was the launch of our new Keeping Our Mob Safe Online booklet. The resource was enthusiastically received by both organisations and community members, who appreciated having practical, easy-to-understand information they could take away, share with family and friends, and use within their workplaces and communities. The booklet proved especially valuable in supporting conversations beyond the sessions themselves.

The Western Australia CROC also reinforced the value of partnering with established local organisations and trusted community networks, while the Northern Territory program demonstrated the strong impact that can be achieved when community leaders are equipped to become cyber safety champions.

Together, these outreach activities helped strengthen awareness of IDCARE's services, build new referral pathways, and most importantly, support communities to stay safer online through trusted local connections.

Behind the mask: The Guide to New and Trending Scams


The ‘Test My Game’ Scam

IDCARE has seen a resurgence of people being targeted through gaming-related platforms by messages that appear to come from friends or trusted contacts whose accounts have already been compromised.

The scam typically begins with a message such as ‘I’ve made a Minecraft mod, can you test it?’ or ‘I’ve just developed a game for university, would you mind having a look and telling me what you think?’ and because the message comes from someone the recipient knows, it often appears genuine.

The affected individuals are directed to click a link to download a file, game, or modification. Instead of legitimate software, the download installs information-stealing malware, predominately affecting Windows devices. Once installed, the malware can harvest login credentials, banking information, stored passwords, and gaming account details. In some cases, the affected individual will receive messages from the criminal asking for payment to return the account to them or delete the information that has been stolen.

Effected clients report:

  • Compromised gaming, and social media accounts
  • Theft of stored passwords and personal information
  • Unauthorised access to online banking and financial accounts
  • Stolen gaming accounts, virtual items, and unauthorised in-game purchases
  • Further spread of the scam through the victim’s own contacts


A key feature of this scam is that once an account is compromised, scammers use it to contact friends and connections, repeating the cycle and exploiting existing trust relationships.

Our Tips:

  • Be cautious of unexpected requests to test games, modifications, or software, even when they come from friends.
  • Verify requests through another communication channel before downloading anything.
  • Only download software from official sources.
  • Use multi-factor authentication on all supported accounts.
  • If you suspect you've downloaded malicious software, disconnect from the internet and run a reputable antivirus scan immediately.
  • Change passwords for important accounts, particularly email, banking, government, and gaming services, if a compromise is suspected.

Ask IDCARE: ‘Are eSIMS safer than traditional SIM cards?’


Have a Scam, Identity, or Cyber-Related Question? Ask IDCARE! 
Every day, IDCARE supports people affected by scams, identity theft, and cybercrime. Our team draws on extensive real-world experience and deep insight into the online criminal environment to help individuals understand risks and take action. 

In this edition of Cyber Sushi, we’re inviting you to submit your question – and the IDCARE team will answer it. Send your questions to [email protected]. 

Our question today comes from Larry 
I’ve recently upgraded to a phone that uses an eSIM instead of a physical SIM card. I’ve heard mixed opinions about whether eSIMs are safer or if they come with new risks. 

Are eSIMs actually more secure than traditional SIM cards? 

Answer:
Hi Larry, 

eSIMs (embedded SIMs) are generally considered at least as secure as traditional physical SIM cards, and in some situations can offer additional protection, but they are not risk-free. 

One of the main advantages of an eSIM is that it cannot be physically removed from your device. This makes it harder for a thief to simply take your SIM card and use it in another phone if your device is lost or stolen. In that sense, eSIMs add a layer of physical security compared to traditional SIM cards. 

eSIMs also use secure digital provisioning controlled by your mobile carrier, which makes them difficult to duplicate or ‘clone’ in the way older SIM-related scams might attempt. 

However, it’s important to understand that eSIMs do not prevent the most common mobile-related risks. For example, SIM swapping (also known as SIM hijacking) can still occur with eSIMs. This is when a criminal impersonates you and convinces a telco provider to transfer your number to a new SIM or eSIM they control. If successful, the criminal could be able to receive all calls and text messages, including one-time codes used for online banking or account logins. 

Like all mobile technology, eSIMs are also exposed to broader cyber risks such as phishing, malware, and account compromise, none of which depend on the type of SIM being used. 

So, while eSIMs can improve physical security and reduce some risks, the strongest protection still comes from good overall cyber safety practices. This includes using strong and unique passwords, enabling multi-factor authentication wherever possible, and being cautious of unexpected messages or requests for personal information. 

In summary, eSIMs are not inherently ‘safer’ or ‘less safe’ than physical SIM cards, they are simply a different technology with their own strengths. The biggest security factor remains how well your mobile account and online identities are protected. 

Kind regards, 
The Cyber Sushi Team

Join the global list of organisations making a real difference in people’s lives by supporting our service.

SBS Bank
HSBC
ANZ
Department of home affairs
Curtin University
Suncorp
Powercor Australia
ING
Regional Australia Bank
Culture Amp
Mercy Health
Queensland Country Bank
Sportsbet
NGM Group
City of Goldcoast
ConnectID
TPG
Western Sydney University
BOQ
Department of Premiere and Cabinet off of Digital Government
ABC
Coles
REA Group
Equip Super
Return to Work SA
Urban Utilities
Transurban
Westpac
Internal Affairs
Allianz
Commonwealth Bank
Bupa
Services Australia
Qantas
NAB
Australia Post
Victoria State Government
NBN
NDIS
Kiwi Bank
Tasmanian Government
Telstra
UTS
Makesure
Australian Super
Australia Post
Urban Utilities
Brisbane City Council

Copyright © 2025, IDCARE. All Rights Reserved.

ABN 84 164 038 966