Skip to main content
Scam Checker
Back to all scam alerts and blog posts

CommSec warns about app requests on social media

By Published
  • CommSec
  • Bank Impersonation
  • Social Media Scams
  • App Downloads

Warning dated 4 September 2026. Sources reviewed 8 September 2026.

CommSec's 4 September alert describes fake social posts requesting app downloads. The company says it never makes these requests through social media. Official warning.

If you already acted on the request, use the official contact details under Where to report below. Do not wait for a checker result before asking for help.

How This Scam Works

The request asks you to move from reading a social post to installing software. Before taking that step, separate the name on the post from the person controlling it. Familiar branding can explain why a request catches your attention; it does not answer whether the organisation authorised it.

CommBank separately warns about copied banking-page designs and social advertisements impersonating its brand. That supports checking the source independently. It does not establish what any app in CommSec's September warning contains. CommBank's alerts.

Fictional practice example: “CommSec customers: install our new app to continue.”

This short example is invented for discussion, not copied from a reported message. It contains no real download link. Ask what it wants you to do, where you would check that instruction, and whether you can complete that check without following the post. You can: leave it and contact the organisation separately.

For a practice discussion, cover the brand name and ask whether you would follow the instruction from an unfamiliar account. Then put the name back. This exercise helps separate familiarity from verification. Keep the example labelled fictional if you share it; it is not evidence for a scam report.

Who Is Being Targeted

CommSec's alert addresses its customers. It does not give a victim count or demographic breakdown. Whatever your experience with investing or technology, focus on the action being requested rather than deciding whether you fit a supposed “typical victim”.

If you are helping a relative, colleague or friend, start with what they actually did. “Did you only see it, or did you download something?” is more useful than asking why they believed it. Their answer helps organise the next conversation with support without assigning blame.

Offer help with navigation or note-taking while they remain in control of their own account. A useful role is to keep track of questions and actions, so they can concentrate on explaining the situation. You do not need their password to help them prepare.

Red Flags to Watch For

Focus on the requested action, not a spelling test:

  • An unexpected installation instruction. Check who is asking before following it.
  • A demand to keep using the post's links or contact details. Change the route of verification instead of asking the same account to vouch for itself.
  • Pressure to decide immediately. Make room to check before agreeing to a download, login or payment.
  • Requests for passwords, security codes or screen access. Do not hand these to an unexpected caller or message sender claiming to help.
  • A proposed transfer to a “safe” account. End the conversation and contact the bank independently.

The last three points reflect CommBank's general unexpected-contact guidance, not additional details of the September 4 posts. A message does not have to contain every warning sign before you pause.

What to Do Before You Click, Reply, or Pay

  1. Leave the post's instructions unfinished. Do not install an app to test whether the request is genuine. Stop before supplying information. Write down the question you need answered so that urgency does not decide it for you.
  2. Start a separate contact. Find CommSec through commsec.com.au or the official app you already use. Use its contact details. CommSec's access guidance.
  3. Describe the request precisely. For example: “A social post using your name asks me to download an app. Does your organisation issue that instruction?” Explain whether you have acted, rather than simply asking whether you have been scammed.

A reply from the original social account would leave the identity question unresolved. Even an explanation that sounds helpful is still coming from the source you are checking.

For your independent support conversation, have a short account of what happened: where you saw the request, approximately when, and what you selected. Say if you are unsure whether a download finished or an installation occurred. You do not need to investigate further through the suspect app to make your account sound more complete.

Useful questions for independently reached support include: “Which account needs attention first?”, “What information should I have ready?”, and “How should I refer to this conversation if I need to contact you again?” These are questions to ask, not promises about a particular support process. Keep any reference number in your own notes rather than posting it publicly.

What to Do If You've Already Been Affected

Choose the description that matches your actions. More than one may apply; tell support about each.

You only saw the post. Leave its links alone. There is no need to click again to confirm what it might do. You can discuss the request without installing anything.

You clicked but entered nothing. Stop interacting with the destination. Tell CommSec that you clicked and whether a file appeared to download. Do not describe the situation as either harmless or compromised based only on the click; the warning does not determine your device's condition.

You downloaded or installed an app. These are different steps, so describe which you remember. This article has not examined that software and cannot tell you what it does. Before entering more banking information on that device, contact official support and explain the installation. If you are unsure about the device, use another phone or device you already trust to make that contact. Do not use contact details presented by the questionable app.

Ask what immediate account-protection steps apply and how to obtain appropriate device help. Do not treat deleting the app as a complete answer if you also supplied credentials or paid. Those actions still need to be explained.

When describing an installation, separate what you remember from what you assume. “I tapped the button and saw a download complete” is different from “I opened an app and entered my login.” Avoid filling the gap with another experiment. Tell support where your recollection stops.

You entered account information or a security code. Tell support what kind of information you supplied, without repeating the secret in a public post or ordinary enquiry email. CommBank's general guidance advises password changes after disclosure. Its reporting instructions also cover affected cards and unfamiliar digital-wallet devices. Ask which steps apply, particularly if you installed software on the device you normally use. Account guidance, reporting instructions.

You made a payment. Contact the relevant account or payment provider promptly as well as CommSec. Have the approximate time, amount and transaction reference available through its official support route. Ask what can be done about that transaction. Reporting does not establish that money can be recovered, and this article cannot predict the outcome.

Where to Report

CommSec lists 13 15 19 in Australia, 8am–6pm Sydney time, Monday–Friday. Its alert says to contact it immediately after clicking, entering details or paying. For out-of-hours scam or fraud support, it lists 13 22 21 through CommBank Safe. Official assistance details.

If you received a suspicious message without acting on it, report it to hoax@cba.com.au. A report helps pass information to the organisation; it should not replace urgent account assistance after you acted.

Keep a brief record for your own use: dates, actions, transaction references and who you contacted through the official route. You can say “I don't know” where details are uncertain. Do not return to the suspect app to fill gaps.

If you need another country's public reporting channel, the global scam-reporting directory can help you find it. A report to an agency and a request to secure an account serve different purposes.

Frequently Asked Questions

Does this mean the official CommSec app is unsafe?

This guide has not tested the official app, examined the advertised software or authenticated a particular download. An installation's identity remains a question to resolve through the provider. Do not turn an unanswered question about one download into a conclusion about every app bearing that name.

What if a friend shared the post?

You can ask your friend about it, but their forwarding it does not answer whether CommSec issued the instruction. They may have the same unanswered question. Check through the organisation's own contact route before acting or passing on the download link.

Should I compare app-store logos and reviews?

They are not a substitute for checking this request independently. This guide has not assessed any store listing. Start with the organisation's official route and ask about the installation instruction instead of trying to settle the question through appearances alone.

What if someone calls me back and already knows my details?

Treat the new contact as another identity question. You can end the call and initiate your own contact through independently obtained details. Do not disclose a password or security code just because a caller has information about you.

Can a link checker settle it?

A link assessment cannot establish who controls a social account or authenticate software. An optional link warning-sign check may help you organise questions, but it should not delay a call about exposed details or a payment. Do not paste passwords, security codes or private account links into a checker.

What should I say if I feel embarrassed or cannot remember everything?

Begin with the part you know: “I followed an app-download request and need help checking my next steps.” Then distinguish what you saw from what you remember doing. A short, honest description is more useful than guessing. You can update it if you recall something later.

Related Scam Checker pages

Choose the resource that matches your next question:

  • How to spot a fake link: learn about misleading addresses without needing to open the suspect destination.
  • Have I been scammed?: organise recovery priorities after sharing information or making a payment.
  • Manual Scam Checker: optionally review a suspicious message for warning signs after removing private details. Results cannot prove something safe.

Scam Checker is independent of CommSec and CommBank. This article was drafted with AI assistance.

External sources and references