How to spot a phishing scam

The bad ones are easy to spot. The good ones look exactly like the real thing, because they usually are the real thing, copied. Here's what still gives them away.

// overview

Forget the spelling mistakes.

The advice most people were given (look for bad grammar, dodgy logos, odd formatting) is now close to useless. Modern phishing emails are pixel-perfect, because the sender simply copied a genuine email and changed one thing.

What hasn't changed is the shape of the thing. A phishing email needs you to do something, quickly, without checking. Every single one of them, no matter how polished, has to create that moment. That's the tell.

So the question isn't "does this look real?" It's "is this email trying to rush me into something involving money, passwords or access?" If yes, slow down. That's the whole technique.

// what to look for

Six things that still give it away.

// the rule

One habit beats all the checklists.

If an email involves money changing hands or credentials being entered, verify it through a channel you already trust. Ring the supplier on the number from your last invoice, not the number in the email. Open your bank's app directly, rather than following a link.

This works because it doesn't require you to correctly identify a fake. It removes the need to judge at all. The scam depends on you staying inside the email; stepping outside it collapses the whole thing.

For businesses, write this down as an actual rule and tell your staff it applies to you as well. The reason invoice fraud works so often is that someone junior didn't feel able to question a payment request. Give them explicit permission to check, and you've closed the gap.

// if you clicked

Already clicked? Don't panic, do this.

Clicking a link is not the same as being compromised. Plenty of the time nothing has happened at all. But work through this quickly rather than hoping.

// questions

Good questions, straight answers.

How did they know I bank with that bank?

Usually they didn't. The same email goes to thousands of people and some proportion happen to bank there. It feels targeted because it landed correctly, but it's almost always a numbers game.

Can you tell if my email account has been accessed?

Often, yes. Microsoft 365 and Google both keep sign-in logs showing where and when your account was accessed. We can go through them with you and check whether any forwarding rules have been quietly added, a common trick after a mailbox is taken over.

My supplier's email was hacked and we paid the wrong account. Can we get it back?

Sometimes, if you move fast. Ring your bank the moment you realise; they can occasionally recall a payment that hasn't been withdrawn. After that it becomes a police and insurance matter. Speed is genuinely the deciding factor.

Do spam filters not catch this?

They catch the obvious ones, and there's a lot they can do at the settings level that often isn't switched on. But a well-crafted invoice scam from a real, compromised business account looks legitimate to a filter, because technically it is. That's why the verification habit matters.

$ inspyred --book-a-callout

Got a question about this?
Ask a human.

Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.

Hours
By Appointment · 7 days
Service area
Toowoomba & the Darling Downs
Service style
Mobile: we come to you