Why this matters
Phishing is the most common way cyber criminals get into Australian businesses and personal accounts. A phishing email pretends to come from someone you trust, such as your bank, Microsoft, Australia Post or a supplier, so you will click a link, open a file or enter your login details. Learning a handful of warning signs stops most of these attacks before they start.
What you'll need
- An email you are unsure about
- A few minutes to check it carefully
Step-by-step instructions
Step 1
Check the sender address, not just the name
The display name can say anything. Look at the actual email address next to it. On a phone, tap the sender name to reveal it.
- Misspelt domains such as "micros0ft.com" or "commbank-secure.net"
- A free email address (Gmail, Outlook.com) claiming to be a company
- A real company name followed by an unrelated domain
Step 2
Look for pressure and urgency
Phishing relies on rushing you. Be suspicious of any message that threatens consequences or demands immediate action.
- "Your account will be suspended in 24 hours"
- "Unpaid invoice, pay today to avoid fees"
- "Unusual sign-in detected, verify now"
Step 3
Hover over links before clicking
On a computer, rest your mouse pointer over a link without clicking. The real destination appears in the bottom corner of your screen or email app. On a phone, press and hold the link to preview it. If the address does not match the organisation, do not open it.
Step 4
Be careful with unexpected attachments
Invoices, voicemails, shipping notices and "shared documents" you were not expecting are common lures. Files ending in .zip, .html, .htm, .iso or Office files asking you to "Enable content" are especially risky.
Step 5
Watch for requests for credentials, money or codes
Legitimate organisations will not ask you to confirm your password, read out a verification code or change bank details by email. Any request to update payment details should be confirmed by phone using a number you already have.
Step 6
Verify through a separate channel
If you are still unsure, contact the sender directly using a phone number or website you know is genuine, not the details in the email. Then report or delete the message.
Troubleshooting
I already clicked the link. What should I do?
If you entered a password, change it immediately from a trusted device and turn on multi-factor authentication. If you opened an attachment, disconnect the device from the network and contact your IT provider. Do not delete the email, as it helps with the investigation.
Frequently asked questions
What is the most common sign of a phishing email?
An unexpected request that creates urgency, such as resetting a password, paying an invoice or confirming account details, combined with a sender address that does not match the organisation.
Can phishing emails come from people I know?
Yes. If a colleague's or supplier's mailbox has been compromised, attackers send phishing from their real address. Verify unusual requests by phone.
Summary
Slowing down and checking the sender, the links and the request itself is the most effective defence against phishing. When in doubt, verify separately and report the message.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.