How to spot a phishing scam
The bad ones are easy to spot. The good ones look exactly like the real thing, because they usually are the real thing, copied. Here's what still gives them away.
// overview
Forget the spelling mistakes.
The advice most people were given (look for bad grammar, dodgy logos, odd formatting) is now close to useless. Modern phishing emails are pixel-perfect, because the sender simply copied a genuine email and changed one thing.
What hasn't changed is the shape of the thing. A phishing email needs you to do something, quickly, without checking. Every single one of them, no matter how polished, has to create that moment. That's the tell.
So the question isn't "does this look real?" It's "is this email trying to rush me into something involving money, passwords or access?" If yes, slow down. That's the whole technique.
// what to look for
Six things that still give it away.
- 01
Urgency that doesn't fit
Your account will be closed today. The invoice is overdue. The parcel needs a fee within 24 hours. Real organisations rarely give you hours, and the ATO in particular will never threaten arrest by email or text.
- 02
A link that doesn't match
Hover over it on a computer, or press and hold on a phone, and read the actual address. If the email says your bank and the link says something else entirely, that's your answer.
- 03
A change to bank details
This is the big one for businesses. A supplier you genuinely use emails a genuine-looking invoice, with new account details. Treat any change of payment details as suspicious until proven otherwise.
- 04
A request that skips the normal process
The boss emails from a slightly odd address asking you to buy gift cards, or to pay something urgently while they're in a meeting. It plays on not wanting to bother them to check.
- 05
An attachment you weren't expecting
Particularly anything asking you to enable content or macros. If you didn't ask for it, don't open it, ring the sender instead.
- 06
A reply-to that differs from the sender
The display name says one thing, but the actual reply address is a free webmail account. Most email apps hide this by default; it's worth learning where yours shows it.
// the rule
One habit beats all the checklists.
If an email involves money changing hands or credentials being entered, verify it through a channel you already trust. Ring the supplier on the number from your last invoice, not the number in the email. Open your bank's app directly, rather than following a link.
This works because it doesn't require you to correctly identify a fake. It removes the need to judge at all. The scam depends on you staying inside the email; stepping outside it collapses the whole thing.
For businesses, write this down as an actual rule and tell your staff it applies to you as well. The reason invoice fraud works so often is that someone junior didn't feel able to question a payment request. Give them explicit permission to check, and you've closed the gap.
// if you clicked
Already clicked? Don't panic, do this.
Clicking a link is not the same as being compromised. Plenty of the time nothing has happened at all. But work through this quickly rather than hoping.
- If you entered a password: change it now, and change it anywhere else you used the same one
- Turn on MFA while you're in there: it locks the door even if the password is already out
- If money has moved: ring your bank immediately, before anything else. Hours matter
- If you installed something or gave remote access: disconnect from the internet and ring us
- Tell someone. If it's a work account, tell your manager or IT straight away. Nobody has ever been sacked for reporting quickly; plenty of damage has been done by people hoping it would go away
- Report it to Scamwatch, and to your bank if financial details were involved
// questions
Good questions, straight answers.
How did they know I bank with that bank?
Usually they didn't. The same email goes to thousands of people and some proportion happen to bank there. It feels targeted because it landed correctly, but it's almost always a numbers game.
Can you tell if my email account has been accessed?
Often, yes. Microsoft 365 and Google both keep sign-in logs showing where and when your account was accessed. We can go through them with you and check whether any forwarding rules have been quietly added, a common trick after a mailbox is taken over.
My supplier's email was hacked and we paid the wrong account. Can we get it back?
Sometimes, if you move fast. Ring your bank the moment you realise; they can occasionally recall a payment that hasn't been withdrawn. After that it becomes a police and insurance matter. Speed is genuinely the deciding factor.
Do spam filters not catch this?
They catch the obvious ones, and there's a lot they can do at the settings level that often isn't switched on. But a well-crafted invoice scam from a real, compromised business account looks legitimate to a filter, because technically it is. That's why the verification habit matters.
$ inspyred --book-a-callout
Got a question about this?
Ask a human.
Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.