eScript SMS in Australia —
Scam or Legitimate?
Since eScripts replaced paper prescriptions, scammers have used the same SMS format to steal personal and financial details from Australians. The messages look identical. Here's how to tell the difference instantly — and what to do if you've already clicked.
Store your real eScripts safely in MediRemind — free on iOS and Android.

In May 2024, MediSecure — one of Australia's two authorised eScript delivery platforms — suffered a data breach affecting approximately 12.9 million Australians. Prescription data including names, medications, and contact details was exposed. Scammers can now send fake eScript SMS messages that include your actual name and medication — making them far more convincing than generic phishing. This is not a hypothetical risk.
What is an eScript SMS?
A legitimate eScript SMS is sent automatically by your GP's prescribing software the moment they write a digital prescription. It contains a unique QR code link — you present it at any Australian pharmacy to have your medication dispensed. No paper, no printing.
These messages are sent through government-approved prescription delivery platforms: eRx (erx.com.au) and the Australian Digital Health Agency platform (scripts.digitalhealth.gov.au). Your GP's software — Best Practice, Medical Director, Cliniko, Genie, and others — connects to one of these platforms to send the token.
What a legitimate eScript SMS looks like
The format varies slightly between platforms but always follows this pattern:
"Your prescription from Dr [Name] is ready. Tap the link to view your eScript token: https://erx.com.au/token/XXXXXXXX. Show this at any pharmacy."
"[Patient name], your prescription has been sent electronically. Your token: https://scripts.digitalhealth.gov.au/.... Present at pharmacy."
Arrives within hours of a GP consultation you actually attended
Link goes to erx.com.au, scripts.digitalhealth.gov.au, or your GP's known clinical software domain
Contains your name and the name of your prescribing doctor
Does NOT ask for payment, banking details, passwords, or personal ID
Does NOT tell you to download a separate app to 'unlock' or 'access' the prescription
Does NOT ask you to confirm your Medicare number, date of birth, or address to proceed
The sending number is Australian (04xx or an SMS short code registered to a health provider)
Red flags — how to spot a fake eScript SMS
The link goes to a domain you don't recognise — anything other than erx.com.au, scripts.digitalhealth.gov.au, or your GP's known systems
The SMS asks you to enter credit card, banking, or Medicare details to 'activate' or 'receive' the script
You receive an eScript for a medication you didn't discuss with your GP
The prescription is for a controlled drug (opioids, benzodiazepines, stimulants) sent out of nowhere — real scripts for these are tightly controlled
The SMS creates urgency: 'expires in 2 hours', 'respond now', 'your prescription will be cancelled'
The sender number is international, withheld, or doesn't match any you've received from your GP clinic before
The message includes a shortened URL (bit.ly, tinyurl, etc.) rather than a full health platform domain
You're asked to pay a 'dispensing fee' via the link before collecting the medication
The message says your medication is 'on hold' or 'pending verification' and asks you to click to release it
Legitimate vs scam — side-by-side comparison
| Feature | ✓ Legitimate eScript SMS | ⚠ Scam SMS |
|---|---|---|
| Link domain | erx.com.au or scripts.digitalhealth.gov.au | Unknown domain, shortened URL, or lookalike |
| Payment requested? | Never — dispensing is handled at the pharmacy counter | Yes — often asks for a fee to 'release' the script |
| Personal info required? | None — just show the QR code | Asks for Medicare number, DOB, card details |
| Timing | Sent within hours of a GP appointment | Random — no recent GP visit |
| Medication | Something you discussed with your doctor | May be random, or a controlled drug |
| App download required? | Never — QR link opens in browser | Often asks you to install an unknown app |
| Urgency language? | No — prescriptions are valid for 12 months | Yes — 'expires soon', 'act now' |
| Sender number | Australian number or known health SMS short code | International, withheld, or random |
Store your real eScripts in MediRemind — so you always know exactly which scripts are genuine before you get to the pharmacy
Free · Secure · Works at every chemist in Australia
Why are eScript scams so convincing in 2026?
Australia's PBS dispenses over 300 million prescriptions per year. Since the nationwide rollout of eScripts, Australians are conditioned to expect prescription SMS messages — so the message format alone triggers no suspicion. A convincing eScript SMS has dramatically higher click rates than a typical phishing message because recipients expect it.
The 2024 MediSecure breach made this significantly worse. With millions of Australians' names and medication histories now in circulation on dark web marketplaces, scammers can craft messages that include your correct name, your GP's suburb, and a medication you actually take. These are no longer generic blasts — they can be targeted.
Common scammer objectives include: harvesting Medicare numbers for medical identity fraud, redirecting to fake online pharmacies that take payment without dispensing medication, harvesting credit card details, or installing malware via a fake "eScript app" download.
What to do if you receive a suspicious eScript SMS
If anything about the message feels off — timing, domain, urgency — don't click. A legitimate eScript will still be valid when you follow up with your GP.
Capture the full SMS including the sender number before you delete anything. This becomes evidence if you report it.
Use a number you already have for the clinic — not a number in the suspicious SMS. Ask whether they sent a prescription and confirm the link domain matches what they issued.
Go to scamwatch.gov.au and submit a report. The more reports filed, the faster the ACCC can issue public warnings and work with telcos to block the sending numbers.
This is the ACMA's SMS scam reporting number. Forwarding the message helps authorities track and shut down scam SMS campaigns.
If you believe it was targeted at you specifically (your name, your medication), report to the Australian Cyber Security Centre at cyber.gov.au/report. This is especially relevant post-MediSecure breach.
What to do if you already clicked a suspicious link
Lower risk. Close the browser tab immediately. Run a security scan on your device. Monitor your accounts for unusual activity over the next 30 days.
Contact Services Australia on 132 011 and report that your Medicare details may have been compromised. They can flag your account and monitor for fraudulent claims.
Call your bank immediately — most have 24/7 fraud lines. Ask them to freeze the card and reverse any unauthorised transactions. Change passwords on any linked accounts.
Delete the app immediately. If it requested device permissions (contacts, location, camera, microphone), factory reset is the safest option. Report to ACSC at cyber.gov.au/report.
The authorised eScript platforms in Australia
There are only a small number of government-approved platforms that can legitimately send eScript SMS messages in Australia. Any link from an eScript SMS should go to one of these domains:
If the link in the SMS goes anywhere other than these domains, treat it as suspicious until you have confirmed it with your GP directly.
Keep your real eScripts safe and organised in MediRemind — not in your SMS
Free to download · 30-day free trial
Frequently asked questions
Are all eScript SMS messages in Australia safe?
No. Scammers send fake eScript SMS messages to harvest personal details or redirect users to fraudulent websites. Always verify the link goes to a recognised Australian health platform before clicking, and never enter payment details to access a prescription.
What do I do if I already clicked a suspicious eScript link?
If you clicked but did not enter any personal information, the risk is lower. If you entered personal or financial details, contact your bank immediately, change any related passwords, and report to Scamwatch at scamwatch.gov.au and ACSC at cyber.gov.au/report.
Can scammers get my medications using a fake eScript?
Fake eScript links cannot access real prescription tokens from the Australian health system. A genuine eScript is issued by your GP through approved clinical software — a scammer cannot create a dispensable prescription. Their goal is typically to steal your personal or financial information.
How do I report an eScript scam in Australia?
Report to Scamwatch (scamwatch.gov.au), the ACSC (cyber.gov.au/report), and forward the suspicious SMS to 0429 999 888 (the ACMA SMS scam reporting number).
What legitimate platforms send eScript SMS messages in Australia?
The main authorised platforms are eRx (erx.com.au) and the Australian Digital Health Agency (scripts.digitalhealth.gov.au). Any link to a different domain should be verified with your GP before clicking.
Why are eScript scams so convincing?
Australians now expect SMS messages containing prescription links after a GP visit. After the 2024 MediSecure data breach, scammers have access to real names and medication data for millions of Australians, making fake messages highly personalised and harder to detect.
What happened in the MediSecure data breach?
In May 2024, MediSecure — one of Australia's eScript delivery platforms — suffered a major breach affecting approximately 12.9 million Australians. Prescription records including names, medications, and contact details were exposed. Scammers can use this data to send convincing fake eScript messages that include your correct details.
Keep your real eScripts safe and organised in MediRemind — not in your SMS
Free to download · 30-day free trial