Cyber Security
Phishing Scams: How to Spot a Fake Email, Text or Login Page
Phishing remains one of the most common ways cybercriminals gain access to email accounts, banking, business systems and personal information.
The principle is simple. Instead of trying to break through your security, the attacker tries to convince you to open the door for them.
A phishing message may appear to come from your bank, Microsoft, Australia Post, a supplier, a government department or even someone you work with. The message normally creates a reason for you to act quickly, such as an unpaid invoice, password expiry, suspicious login, failed delivery or account suspension.
Modern phishing can be extremely convincing. Good spelling, professional graphics and familiar company logos are no longer reliable indicators that a message is genuine.
What is phishing?
Phishing is a form of social engineering where an attacker impersonates a trusted person or organisation in an attempt to make you reveal information, open a malicious file or visit a fraudulent website.
According to the Australian Signals Directorate's Australian Cyber Security Centre, phishing messages commonly impersonate organisations people know and trust in an attempt to steal passwords, financial information or other sensitive data.
Common objectives include:
- Stealing your email username and password
- Obtaining banking or credit card details
- Capturing multi-factor authentication codes
- Installing malware or remote access software
- Convincing a business to pay a fraudulent invoice
- Taking control of an email or social media account
Common phishing scams
The story changes, but most phishing attacks use the same basic techniques.
Fake account warnings
You receive a warning claiming your Microsoft, Google, banking or other account has been locked, compromised or is about to expire.
The supplied link opens a fake login page designed to capture your username and password.
Delivery and parcel scams
A text message or email claims that a parcel could not be delivered or that a small fee must be paid before delivery.
The link may lead to a fake courier or Australia Post website that requests personal or credit card information.
Fake invoices
Businesses may receive invoices that appear to come from genuine suppliers or contractors.
More sophisticated attacks may involve an actual supplier's email account being compromised and legitimate invoices being altered to show the attacker's bank account details.
QR code phishing
Instead of providing a clickable link, the attacker includes a QR code that opens a fraudulent website on your phone.
QR codes can make suspicious destinations harder to identify before visiting them.
How to recognise a phishing message
Unexpected urgency. Messages telling you that something must be done immediately are designed to make you react before thinking.
Unexpected login requests. Be suspicious when an email asks you to sign in to an account you were not already trying to access.
Unusual sender addresses. The displayed sender name may be correct while the actual email address belongs to an unrelated domain.
Suspicious links. The words shown in an email do not necessarily match the website that will open when the link is clicked.
Changes to payment details. Any unexpected request to change bank account details should be verified independently before money is transferred.
Requests for passwords or security codes. A legitimate organisation should not unexpectedly ask you to send your password or multi-factor authentication code by email or text message.
Check where a link really goes
One of the most important habits you can develop is checking the destination of a link before opening it.
On a computer, hovering your mouse over a link will normally display the destination address. On a phone or tablet, pressing and holding a link can usually reveal the destination without opening it.
Pay particular attention to the actual domain name.
For example, a page may contain the words Microsoft Login, but the important part is the website address in your browser.
Attackers commonly use misspellings, additional words, unusual subdomains or domains that simply look similar to the genuine organisation.
When in doubt, do not use the link in the message. Open your browser and navigate to the organisation's website yourself.
Fake login pages can look almost perfect
A fraudulent login page can copy the logos, colours, fonts and layout of Microsoft, Google, a bank or almost any other online service.
The appearance of the page therefore tells you very little about whether it is genuine.
The website address is far more important.
Also remember that the padlock symbol and HTTPS do not mean a website is trustworthy. They indicate that the connection between your browser and that website is encrypted. A criminal can also obtain an HTTPS certificate for a fraudulent website.
Multi-factor authentication helps, but it is not foolproof
Multi-factor authentication, commonly called MFA or 2FA, provides an important additional layer of security.
However, some phishing attacks now attempt to collect both your password and your authentication code.
If you receive an unexpected authentication request, do not approve it. An unexpected approval request can be a warning that someone already has your password and is attempting to access your account.
Where available, stronger authentication methods such as passkeys or hardware security keys can provide greater resistance to phishing than traditional passwords and SMS codes.
AI is making phishing harder to recognise
Poor grammar and spelling were once useful indicators of a phishing email. That is becoming far less reliable.
Generative AI can help attackers create professional, personalised and grammatically correct messages in seconds. Information available through company websites, social media and other public sources can also be used to make an attack more believable.
This means phishing detection increasingly depends on context rather than spelling.
Ask whether the request itself makes sense, whether you were expecting it, whether the sender normally communicates this way and whether there is a safer way to verify the request.
Businesses need to be particularly careful with payment requests
Business email compromise can be far more difficult to detect than a traditional fake email.
In some cases, criminals gain access to a genuine email account and monitor conversations before intervening at the right moment.
A legitimate invoice may then be replaced or altered with different bank details.
Businesses should have a simple rule: significant changes to supplier bank details should be confirmed using a trusted phone number already held on record, not a phone number supplied in the email requesting the change.
What should you do if you receive a suspicious message?
Do not click links or open unexpected attachments.
Do not reply to the message to ask whether it is genuine.
Visit the organisation's website independently or use its official app.
Contact the sender using contact information you already trust.
If money is involved, independently confirm payment details before transferring funds.
Report suspicious messages through your email provider or organisation where appropriate.
What if you already clicked the link?
Clicking a phishing link does not automatically mean your account has been compromised, but you should consider what happened after you opened it.
If you entered a password into a suspicious website, change that password immediately using the genuine website or application.
If the same password has been used on other accounts, those passwords should also be changed.
Review recent account activity, enable multi-factor authentication if it is not already enabled, and sign out other active sessions where the service provides that option.
If banking or credit card information was entered, contact your financial institution promptly.
For a business account, notify the person responsible for IT or cyber security as soon as possible. Early action can make a substantial difference.
A simple rule that prevents many phishing attacks
When an unexpected message asks you to log in, pay money, provide information or take urgent action, stop and verify the request using a completely separate method.
Do not use the phone number, website address or contact details provided in the suspicious message itself.
A few seconds of independent verification can prevent an account takeover, fraudulent payment or much larger cyber security incident.
Further information
For current Australian government advice on phishing and cyber security, visit the Australian Signals Directorate's Australian Cyber Security Centre.