I.T. & Security
Spot the scam: 6 phishing red flags to train your team on
The most expensive security breach in a small business rarely involves a hacker in a hoodie - it's someone on the team clicking a link they shouldn't have. Scammers don't break in; they get invited, through an email or text that looks close enough to real. The fix isn't fancy software, it's a team that can spot the signs. This guide lays out six red flags that give a phishing attempt away, with real examples of the messages doing the rounds in Australian inboxes right now - the fake invoice, the "your account is locked" panic, the boss who suddenly needs gift cards. You'll get a short, plain briefing you can share with staff, a two-minute test to see who's switched on, and a simple rule for what to do when something feels off. It's written for a busy team, not a security desk - no jargon, just the tells that matter.
Why the breach starts with a click
Modern scammers don't crack passwords with brute force - they ask for them nicely. Phishing is the art of getting a real person to hand over a login, open a booby-trapped attachment, or pay a fake invoice, all while believing they're just doing their job. One wrong click can hand over an email account, and from there a criminal can read your mail, reset other passwords, and pose as you to your customers and suppliers.
That's why the strongest defence isn't a product, it's a switched-on team. Software filters catch a lot, but the clever ones get through - and the only thing standing between them and your bank details is a staff member who pauses and thinks. The six red flags below are the tells that pause is built on.
1. The address that's almost right
The display name says your bank, or Microsoft, or a supplier you know. The actual email address tells a different story: [email protected], [email protected] (look twice at the spelling), or a familiar name sitting on top of a random free webmail address. Scammers rely on you reading the friendly name and never checking what's behind it.
The tell: hover over or tap the sender to reveal the real address, and read the part after the @ carefully. A single swapped letter, an extra word, or a domain that isn't the company's real one is a red flag on its own.
2. Urgency and threats
"Your account will be suspended in 24 hours." "Unusual sign-in detected - verify now or lose access." "Final notice." Panic is the whole point. If you're frightened or rushed, you click before you think, which is exactly what the sender is counting on.
The tell: genuine organisations don't threaten to lock you out of everything within the hour by email. Real deadlines give you time and a way to check through the official app or website. Manufactured urgency is designed to stop you checking at all.
3. The unexpected invoice
An invoice, receipt or "your order has shipped" for something you never bought. Sometimes it's a PDF attachment, sometimes a "view invoice" button. The goal is to make you either open the attachment - which carries the malware - or ring the "billing" number in a panic to dispute a charge, and hand your card details straight to the scammer.
The tell: if you didn't order it, don't open it. Verify any real charge by logging into the account directly or ringing the company on a number you already have, never the one in the email.
4. The boss who needs gift cards
An urgent message from the "owner" or "CEO", often from a slightly wrong address or a new mobile number: "Are you at your desk? I need you to grab some gift cards for a client, I'm in a meeting and can't talk." Or the finance version: "Please update our supplier's bank details before the next payment run." This one preys on wanting to help the boss quickly.
The tell: any request for gift cards, urgent transfers or a change of bank details is a red flag no matter who it appears to come from. Verify in person or on a number you already have - a real boss will thank you for checking.
5. Links that don't go where they say
The text says your bank's web address, but the link points somewhere else entirely - a lookalike domain, a shortened link, or a login page that's a pixel-perfect copy of the real one sitting on the wrong address. You type your password, and you've just typed it straight into the scammer's form.
The tell: hover over a link to see where it truly goes before you click, and never sign in through a link in an email. If you need to log in, open the app or type the address in yourself.
6. A request that breaks the normal process
The most damaging scams don't look dramatic - they look like a small, reasonable exception. A supplier emails to say their bank account has changed. A colleague asks you to approve a payment out of the usual order. A password reset lands that nobody started. Each one asks you to step outside your normal process "just this once".
The tell: anything that touches money or access should follow the same checked process every time, with no exceptions for urgency. If a request would change where money goes or who can get in, slow down and verify it independently.
The one rule: stop and verify by phone
You don't need to memorise every trick. You need one habit: when something feels off, stop, don't click, and verify by phone using a number you already have - not one from the message. Ring the supplier, walk over to the boss, call the bank on the number printed on your card. Thirty seconds of checking beats a week of cleaning up.
Just as important: make it safe to check. The businesses that get burned are usually the ones where staff felt they'd look silly for questioning an email from the boss. Tell your team plainly that nobody will ever be in trouble for pausing to verify - and that they'll be thanked for it.
Try the two-minute test
Reading about red flags is one thing - spotting them under pressure is another. We built a quick, no-sign-up quiz that shows real-looking messages and asks you to call each one safe or scam. It's the fastest way to see who on your team has a sharp eye and who could use a refresher.
Take the two-minute phishing test and share it around the office. If you'd like a plain-English email-security review for the whole team, that's a conversation worth having before a scammer starts it for you.