Active Phishing Content Hosted on IPFS – Impersonating myGov Australia

I’m reporting an active phishing page hosted on IPFS that is impersonating myGov Australia.

IPFS URL (CID):
hxxps://ipfs.io/ipfs/bafybeibqvn6o3ymompjdlij6a6wyislzlsei2snz5yckyuyqsaznawr2vq

  • Live for ~403 hours

  • Served via public IPFS gateway

Indicators:

  • Page copies myGov login interface

  • Credential harvesting confirmed (fake data proceeds)

  • Validated with myGov – content is not authorized or owned by them

  • Backend analysis confirms delivery via IPFS

This content poses a real risk of credential theft and identity fraud.

Requesting review and guidance on gateway-level blocking / CID mitigation as per IPFS abuse handling practices.

@afcc a dedicated channel exists for reporting abuse like this, please use that:

https://about.ipfs.io/#reporting-abuse

If you reported it via email and it was not taken down, use the web form linked there.