The old advice was to look for bad spelling and clumsy grammar. That advice is now actively unhelpful: modern phishing is written properly, uses the real company’s branding, and often arrives in a genuine-looking reply chain. Some of it comes from a real, compromised mailbox belonging to someone you actually know.
So look at what the email is asking you to do, because that still gives most scams away.
Signs to watch for
- Urgency or threats — “your account will be closed in 24 hours”
- A sender address that doesn’t match the real company
- Links that don’t go where they claim (hover to check first)
- Unexpected attachments, especially .zip or .html files
- Requests to “verify” passwords, payments or bank details
These two catch people most often.
Check the domain, not the display name. Anyone can set a display name to “Commonwealth Bank” or to your manager’s name. What matters is the bit after the @ — and specifically the end of it. Attackers register domains that read correctly at a glance: an extra word, a hyphen, .com where the real one is .com.au. On a phone, where the address is often hidden behind the display name entirely, tap to expand it before you act.
Hover before you click. The visible text of a link has nothing to do with its destination. On a computer, rest the cursor over it and read the address that appears at the bottom of the window. On a phone, press and hold to preview. If the address doesn’t match what the link says, don’t click it.
The golden rule
If a message pressures you to act fast, slow down. Real organisations don’t rush you into handing over credentials or moving money.
Almost every scam creates urgency, because people who feel rushed don’t stop to check. An account closing in 24 hours, an overdue invoice, a parcel about to be returned, a manager who needs something done before a meeting: all of these are designed to get you to act before you think.
The more urgent a message feels, the more carefully you should check it.
The one that catches businesses
For Australian small businesses, the most expensive kind of phishing is usually a fake invoice.
The pattern: an attacker gets into a mailbox, reads the mail for a while, then either sends a real supplier’s invoice with the bank details changed, or intercepts a genuine one. It arrives in a real conversation, from a real address, about a real job, so nothing looks out of place.
There is one reliable defence: any change to bank details gets confirmed by phone, on a number you already had (never the one on the invoice), before payment. Make it a rule that applies to everyone including the owner, so nobody has to make a judgement call under pressure.
What to do instead
- Don’t click — open the company’s site yourself in a new tab
- Confirm unusual payment requests by phone using a known number
- Report suspicious email to your IT provider and delete it
If someone has already clicked
It happens to careful people, so the important thing is to act quickly.
If credentials were entered: change that password immediately, then sign out all sessions — this is the step people miss, and without it the attacker keeps a live session even after the password change. Check the mailbox for forwarding rules the attacker may have added so they keep receiving copies of your mail.
If an attachment was opened: disconnect the machine from the network and call your IT provider before doing anything else.
Either way, tell someone straight away. People often wait an hour or two hoping it was nothing, and that delay does more harm than the click. If staff know they won’t be blamed for reporting a mistake, they report it sooner.
Good email filtering stops most of these messages. For the rest, half an hour with your team on what to look for costs very little.