CDF Security Centre


Your security is our priority. Learn about the latest scams, how to spot them, and more about what we're doing to help keep your funds safe.

Think you’ve been scammed?
Call us on
1800 134 135 or contact our team today.

Contact CDF

CDF Security Centre

Your security is our priority. Learn about the latest scams, how to spot them, and how CDF Online's built-in security features help keep your funds safe.

Think you’ve been scammed? 
Call us on 1800 134 135 or contact our team today.

Contact CDF

I've been scammed


How to report a scam?

If you’re concerned you may have fallen victim to a scam, here’s what we recommend:




Reporting scams can help others. Visit Scamwatch and Australian Cyber Security Centre who fight cybercrime.

Stop all communications with the suspected scammer

Email us or call 1800 134 135 as soon as possible

Change your CDF Online password

OCTOBER 2026 - CYBER SECURITY AWARENESS MONTH


Take a Second. Stay Secure.

Practical advice to protect you, your information and organisation, built around CDF's own framework: Pause. Check. Protect.

Learn more

How we're keeping you safe


Protecting your funds is a shared responsibility. We encourage all clients to maintain strong internal processes for verifying payments and confirming account details before transferring funds, particularly when receiving a request to update or change payment information.


We understand that even well-managed processes can be vulnerable to sophisticated scammers. That's why CDF provides the following additional security features to help keep you protected.

Suspicious Transactions

As soon as a suspect transaction is detected by CDF, we will try to contact you to verify the transaction before it is processed.


Payee Check

A security feature that provides an additional check of payee account details for eligible payments, helping reduce the risk of payments being sent to the wrong account.


Multi-factor authentication

Multi-factor authentication (MFA) is a security measure that requires two or more proofs of identity to verify a user, providing an additional layer of security. Boost your account safety and register for SMS Multi-Factor Authentication (MFA) today.

Register for CDF multi-factor authentication

Pictured: CDF Staff

FAQs


  • I think my CDF account/s has been hacked or compromised, what should I do?

     If you think you’ve been a victim of a scam or are worried about the security of your accounts with CDF, please contact our team as soon as possible.

  • What are the best practices for creating and managing strong passwords?

    There are multiple ways to you can create and manage strong passwords such an enabling a One Time Password (OTP) or utilising Password Managers. Learn more: Fortify Your Digital Fortress: The Power of Strong Passwords 

  • What does CDF never ask for?

    Our team will never ask you for any of the following: your password, PIN or SMS verification passcodes, remote access to your device, sensitive information, test transactions or to transfer funds to another account.

  • What happens after I report a scam?

    When you report a scam, our operations, risk and cyber experts act fast to shut it down and prevent any potential loss or damage. We will always advise the outcome of your report and remain in contact throughout the process.

3 Simple Tips for Greater Security


1. Pause: Does something feel off? Never share money or personal information if you're unsure.


2. Check: Ask yourself, could this call, email, or text be a scam? Contact the organisation directly using a number or address you know to be genuine.


3. Protect: Trust your instincts and act quickly. Hang up, delete the email, or block the number. Report the issue and if you've shared any passwords, change them immediately.

Pictured: CDF Staff

Tips, Stories & Latest News 


August 25, 2026
Australians reported 481,523 scams in 2025 , with 274,577 reports involving financial losses totalling $2.18 billion . Behind those numbers are scams that are becoming increasingly difficult to spot. For organisations, one of the most convincing can begin with something as routine as an invoice. Invoice fraud is becoming increasingly sophisticated. The email may come from a supplier you know. The invoice may look exactly like previous ones. The amount is correct, the project is familiar, and the message may even sit inside a genuine email thread. The only thing that's changed is the bank account. That one change can redirect thousands of dollars into a cyber criminal's hands. How it happens Invoice fraud, also known as payment redirection fraud, is a common form of Business Email Compromise (BEC). Criminals gain access to a real email account - through phishing, stolen credentials, malware or a data breach - then quietly monitor it. They learn who approves payments, how invoicing cycles work, and wait for the right moment to intercept a genuine transaction and simply change the bank details. Because nothing else changes, it's very hard to spot. Example of What a Scam Looks Like
July 6, 2026
Cyber criminals are constantly looking for the easiest way into your systems, and unfortunately, passwords alone are no longer enough. Even strong passwords can be compromised through phishing emails, data breaches, malware or social engineering attacks. Once a criminal has your password, gaining access to email, cloud platforms, financial systems and sensitive information can be alarmingly straightforward. This is where Multi Factor Authentication (MFA) becomes one of the most effective cyber security controls available. Think of it as a second lock on your front door: a stolen password may open the first, but MFA prevents criminals from walking straight in.
April 1, 2025
In a world where the threat of fraud is constantly evolving, staying safe online is not just good practice — it’s essential. CDF recently helped identify and stop a fraud attempt on a client account that could have led to the loss of a significant amount of money. Here’s how it unfolded and what you can learn to protect your own digital security at home and at work. The power of human firewalls This situation, involving a current CDF customer, showcases a recent prevented fraud attempt: CDF received a transfer request from a registered client’s email address The transfer request involved making a payment to a new account, which the client had not previously transacted to CDF staff followed internal processes, requesting additional verification from the client When the fraudster couldn't provide further information, the staff member called the client directly This phone call revealed the email account had been compromised In this attempt, it was the human element that added the extra layer of security to an already robust internal process – it demonstrates the importance of proper security procedures when handling transfer requests, especially to new bank accounts. " Technology like emails can be compromised and used for fraud. Staying proactive, adhering to processes, and maintaining regular training is critical ," says CDF Information Security Manager, David Huang.

Help & Support


If you need to get in contact with us, there are a number of ways we can help. Our team are available to assist from Monday to Friday 9am - 5pm (AEST).

1800 134 135

PO Box 174 East Melbourne VIC 8002

How can we help?

Fill out the form below and our team will get back to you shortly.