Phishing is an email designed to get you to do one of three things: type your password into a fake page, open an attachment, or pay someone. The good ones do not look like scams. They look like a Microsoft notice, a delivery slip, a signature request, or a short note from your boss.
You do not need to be technical to catch most of them. You need three habits.
Try this first
- Look at the actual sender address, not the display name. The name shown at the top of an email is just a label, and anyone can type anything into it. On a computer, hover over or click the sender name to reveal the real address. On a phone, tap the sender name. You are looking for a domain that is close but wrong: microsoft-verify.com, xero.support, or your own company name with one letter changed. If the display name says a colleague but the address is a Gmail or Outlook.com address, that is your answer.
- Check where a link actually goes before you click. On a computer, rest your mouse pointer over the link without clicking and the real destination appears at the bottom of the window. On a phone, press and hold the link and a preview pops up. Read it from the left: the part immediately before the first single slash is the real site. So login.microsoftonline.com/something is Microsoft, but microsoftonline.com.secure-verify.io/login is not, because the real site there is secure-verify.io.
- Ask what it wants you to do, and how quickly. Nearly every phishing email creates a reason to hurry: your mailbox will be deleted, your payment failed, the document expires today, the director needs this before a meeting. Urgency exists to stop you thinking. When you notice it, that is the moment to slow down rather than speed up.
The patterns we see most
- A fake sign-in page. You get a notice about a shared document, a voicemail, a fax, or a quarantined message. Clicking it opens a Microsoft 365 sign-in page that is pixel-perfect, because it is a copy of the real one. The address bar is the only tell.
- A reply inside a real conversation. The attacker is already in someone else's mailbox and replies to a genuine thread, quoting real history. Nothing looks odd because most of it is real. Only the new attachment or link is theirs.
- The quiet request from the boss. Short, plain text, no logo, often from a lookalike address or a mobile number. "Are you at your desk? I need you to handle something." It builds to a payment, a gift card purchase, or a change of bank details.
- The signature or invoice attachment. A DocuSign, Adobe or invoice-shaped attachment that is really an HTML file. Opening it loads a sign-in page from your own computer, which slips past some filters.
- The unexpected multi-factor prompt. Multi-factor authentication is the code or approval you confirm on your phone. If one arrives when you were not signing in, someone else has your password. Decline it and tell us.
If you are not sure
Being unsure is normal, and it is not a failure. Two rules cover it.
Never verify something using the contact details inside the suspicious message. If an email says your supplier changed their bank account, ring the supplier on the number you already had. If it says Microsoft needs you to sign in, open your browser and go to office.com yourself.
Then send it to us. Forward it to support@yougrowit.com.au and we will tell you either way. We would far rather look at fifty safe emails than miss one. There is no such thing as wasting our time with this.
How to stop it happening again
Filtering catches a large share of this before you see it, but no filter catches everything, so the aim is to make the remainder survivable. Multi-factor authentication on every account is the single biggest help, because a stolen password on its own then does nothing. Keeping payment changes on a phone-call rule protects the money. And telling your team plainly that reporting a click is welcome, not punishable, is what makes the reporting happen fast enough to matter.
Still stuck?
Log a ticket at portal.yougrowit.com.au or email support@yougrowit.com.au. If it is stopping you working right now, call 03 9028 4358.
Support hours are Monday to Friday, 8:30am to 5:30pm Melbourne time, excluding Victorian public holidays.
Related Articles
You think you have been phished: what to do in the first ten minutes
You clicked a link, typed your password into a page that looked right, and something feels off. Maybe the page reloaded and asked again. Maybe a colleague replied to an email you never sent. This one catches everyone, including people who are good ...
Why we send you security alerts, and which ones matter
If we look after your systems, you will get emails from us about security. Some ask you to do something, most do not, and after a while it is easy to stop reading them. That is the outcome we most want to avoid, so here is exactly what we send and ...
Fake support calls and virus warning pop-ups
Two versions of the same scam. In one, a page takes over your screen with sirens or a beeping alarm, a Windows or Apple logo, and a warning that your computer is infected and you must ring a support number now. In the other, the phone rings and a ...
Invoice fraud and payment redirection: the scam that costs the most
Of everything that goes wrong with email, this is the one that takes real money out of a small business, and often tens of thousands of dollars at once. It is not a virus and it is not clever software. It is an ordinary email that asks you to pay the ...
Using your own phone or laptop for work, safely
Most small businesses run on personal devices to some extent. Someone checks email on their own phone, a director works from a home laptop, a part-timer uses their own machine two days a week. That is normal and it can be done safely. The risk is not ...