How to Spot Phishing Scams Before You Pay
Cyber Security Action Month 2026
Your four missions this October
One practical topic a week to help your team stay a step ahead of cyber criminals. Take a second. Stay secure.
- Mission 015 OctThe Spy Who Emailed MePhishing scams and fake invoices
- Mission 0319 OctWhat Would a Criminal Pay for Your Client List?Passwords and protecting data
- Mission 0426 OctClicked Something Dodgy? Here's What to Do NextReporting cyber incidents
At a glance
On this page
- 01 Quick answer – Phishing scams
- 02 What to know first
- 03 Your mission this week
- 04 Types of phishing scams
- 05 Why it matters
- 06 Five red flags
- 07 Interactive check
- 08 The one habit that stops most scams
- 09 How to protect your business
- 10 What to do if you’ve clicked or paid
- 11 How Intellect IT can help
- 12 Phishing readiness check
- 13 Frequently asked questions
QUICK ANSWER
The Practical Starting Point: What Are Phishing Scams?
Phishing scams are fake messages that pretend to come from someone you trust, such as a supplier, your bank, Microsoft or your boss, to steal money, passwords or personal information. They arrive by email, text message, phone call and QR code.
For Australian businesses, one of the most costly versions is the fake invoice. It’s Friday afternoon and an email lands from a supplier you’ve used for years. Same logo, same signature, same friendly tone. There’s just one small change: “We’ve recently switched banks, please update our details before paying.” You pay it. Three weeks later, the real supplier calls asking why you haven’t. The money is gone.
No one hacked your network. Someone simply asked nicely. That’s why the one habit that stops most phishing scams is simple: before paying or changing bank details, call the person on a number you already have.
At Intellect IT, we see phishing as a people problem as much as a technology one. Filters catch a lot, but the strongest protection is a team that knows when to pause and check.
Key takeaways
Phishing scams target people
Instead of breaking through your firewall, criminals borrow trust: a familiar name, an urgent deadline or a request that looks routine. They want you to act before you think.
Fake invoices cost the most
Business email compromise, where criminals pose as a supplier or colleague to redirect payments, is one of the most reported and costly cybercrimes for Australian businesses.
Changed bank details are the big red flag
Treat every request to change payment details as suspicious until confirmed, even from a supplier you know well. Urgency and "please don't call" requests are warning signs too.
Call a number you already have
Before paying a new account or changing bank details, phone the person on a number from your records, not the one in the email. This one habit stops most invoice scams.
Never share passwords or codes
No legitimate organisation will ask for your password or multi-factor authentication (MFA) code. Turn on MFA for every email account so a stolen password alone isn't enough.
Report quickly, without blame
If someone clicks or pays, speed matters. Call your bank, tell your IT provider and report it to ReportCyber or Scamwatch. Staff who speak up early should never be in trouble for it.
Mission briefing · Week 1 of 4
Your mission: spot the spy who talks their way in
This October, Intellect IT is following KnowBe4’s “Secret Agents” campaign for Cybersecurity Awareness Month. Each week is a new mission, and each one helps turn your team into a frontline defence against cybercrime.
Mission 1 is phishing and social engineering. The most skilled criminals rarely need to break into your systems. They persuade someone to let them in, with requests so ordinary that email filters have nothing technical to catch. That makes your people the last line of defence, and this mission is about the subtle red flags only a person can spot.
Mission objectives
- Recognise the approach: Learn the red flags of phishing scams that technical filters miss.
- Verify before you act: Confirm every bank detail change by phone, using a number you already have.
- Signal for backup: Report anything suspicious straight away, without fear of blame.
Want to run this mission with your team? KnowBe4’s free Cybersecurity Awareness Month kit includes short training modules, posters and ready-made tabletop exercises. As a KnowBe4 partner, we can help you put it to work. Ask us how →
Types of phishing scams
Phishing scams rely on social engineering, which means they target people rather than technology. They come in several forms, and knowing the main types helps your team recognise them whatever channel they arrive on.- Email phishing: Mass emails pretending to be a bank, Microsoft, Australia Post, myGov or a utility company, usually linking to a fake login page.
- Business email compromise (BEC): Criminals pose as a supplier, colleague or executive, using a fake or hijacked email account, to redirect payments or request sensitive information.
- Spear phishing and whaling: Researched, personalised messages aimed at a specific person. Whaling targets executives and finance staff who can approve payments.
- Smishing (SMS phishing): Text messages about unpaid tolls, parcel deliveries or locked accounts, with a link to a fake payment or login page.
- Vishing (voice phishing): Phone calls from people claiming to be your bank, the ATO or tech support. Criminals now use AI to clone familiar voices too.
- Quishing (QR code phishing): QR codes in emails, on flyers or on parking meters that lead to fake login or payment pages, bypassing many email link filters.
For most businesses, business email compromise causes the biggest losses, so that’s where the rest of this article focuses. Next week, we look at how AI voice cloning is turning vishing into deepfake scams.
Why phishing scams matter for Australian businesses
Phishing scams are one of the most common ways cybercrime reaches Australian businesses. According to the ASD Annual Cyber Threat Report 2024–25:- Email is the front door: The two most reported cybercrimes for businesses were both email based: email compromise with no financial loss (19%) and business email compromise fraud with a financial loss (15%).
- One in three starts in the inbox: Together, those categories make up roughly one in three business cybercrime reports.
- The cost is rising: The average self-reported cost of cybercrime for a small business rose 14% to about $56,600 per report.
Why it matters
“Most phishing scams don’t beat technology, they beat a busy person on a Friday afternoon. The businesses that avoid losses aren’t the ones with perfect staff. They’re the ones with a simple rule everyone follows: if money or bank details are involved, pick up the phone and check.”
Stephen Allan Intellect IT Director, Cybersecurity Expert
Five red flags of phishing scams
Phishing scams are designed to look routine, but most share the same warning signs. Train your team to pause when they see any of these:-
Flag 01Changed bank details
-
Flag 02Urgency and pressure
-
Flag 03A sender or link that’s almost right
-
Flag 04Requests for passwords or codes
-
Flag 05Requests to skip normal checks
- Changed bank details: Any message saying a supplier, employee or client has “changed banks” is suspicious until you’ve confirmed it by phone, even from someone you know well.
- Urgency and pressure: “Pay by 3pm or your account goes on hold.” Deadlines are there to stop you checking, which is exactly the point.
- A sender or link that’s almost right: Look for swapped letters (supp1ies instead of supplies), extra words or a different ending such as .com instead of .com.au. Hover over links to see where they really go.
- Requests for passwords or codes: A “view invoice” link that asks you to sign in to Microsoft 365 is a common way to steal accounts. No legitimate organisation will ask for your password or multi-factor authentication (MFA) code.
- Requests to skip normal checks: “Please reply by email, our phones are down” or “keep this between us” are designed to cut you off from the real person.
Other warning signs include a generic greeting such as “Dear customer”, unexpected attachments and messages out of the blue from someone you rarely hear from.
Interactive check
What would you check before paying?
This invoice email looks convincing. Tap or click every part you’d check before paying it. There are six warning signs hidden in it.
Your result
Tap a part of the email to check it.
This is a quick awareness exercise, not a full phishing or email security assessment.
How a fake invoice scam works
Where phishing scams can be stopped
Invoice-based phishing scams follow a predictable path. The criminal controls the email thread, so the safest place to stop them is outside it, with a call to a number you already have.
Invoice email arrives
Lookalike or hijacked sender
Changed bank details
Pressure to pay now
Call-back check stops it
The one habit that stops most phishing scams
You don't need to become a forensic expert. You need one rule that everyone in the business follows, every time: Before you pay a new account or change any bank details, call the person on a phone number you already have. Not the number in the email. Not the number in the email signature. Use the one in your accounting system, on a previous verified invoice, in a signed contract or on the supplier's official website. Just as importantly, don't use the suspicious email to check itself. Don't reply to it, and don't click its links to "confirm" anything. If the supplier says they didn't request the change, stop the payment and tell your IT provider straight away, because their mailbox, or yours, may have been compromised. An independent phone call stops most invoice-based phishing scams because it takes the check outside the email thread a criminal controls. Put the rule in writing, tell your accounts team they'll never be in trouble for slowing a payment down to check, and make sure leaders follow it too.How to protect your business from phishing scams
Alongside the call-back rule, these steps protect against every type of phishing scam:- Go direct: Don't click links or scan QR codes in unexpected messages. Type the website address yourself or use a saved bookmark.
- Never share codes: Don't give anyone your password or MFA code, even if they say they're from IT, your bank or Microsoft.
- Turn on multi-factor authentication: Enable MFA for every email account, so a stolen password alone isn't enough.
- Filter and flag: Ask your IT provider to tag emails from outside your organisation, block lookalike domains and set up email authentication. Our guide to DKIM and DMARC email security explains how this stops criminals sending email from your genuine domain.
- Train regularly: Run phishing awareness training and simulated phishing tests so spotting scams becomes second nature.
What to do if you've clicked a link or paid a fake invoice
Speed matters. Acting quickly gives you the best chance of limiting the damage, though recovering money isn't guaranteed.-
Step 01Call your bank if money was sent
-
Step 02Change passwords and turn on MFA
-
Step 03Tell your IT provider
-
Step 04Keep the evidence
-
Step 05Report it
- Call your bank: If money was sent, call your bank straight away and ask whether the payment can be recalled or frozen.
- Change passwords: If you entered a password, change it immediately and make sure MFA is turned on.
- Tell your IT provider: They can check the account and protect other staff. If your own mailbox was used, they should look for hidden forwarding rules and lock it down.
- Keep the evidence: Don't delete the email, invoice or any replies, as they help your bank and investigators trace what happened.
- Report it: Use ReportCyber or call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371), and report it to Scamwatch to help warn other businesses.
We'll cover incident reporting in more detail in week 4 of this series.
How Intellect IT helps protect your team from phishing scams
Phase 1 – Understand your current risk
- Run a baseline phishing test: We send a realistic, safe simulated phishing email through KnowBe4 to see how your team responds before any training begins.
- Review how payments are approved: We look at how invoices are received, who can change supplier bank details and whether any verification step is in place.
- Identify high-risk roles: We pinpoint the people criminals are most likely to target, such as accounts, payroll, executives and anyone who can approve payments.
Phase 2 – Train your team to spot phishing scams
- Deliver security awareness training: We roll out short, practical KnowBe4 training that covers phishing, business email compromise, smishing, vishing and QR code scams.
- Focus on real-world red flags: Training uses examples your team will recognise, like changed bank details, urgent deadlines and fake Microsoft 365 sign-in pages.
- Build a no-blame reporting culture: We help make it easy and safe for staff to report suspicious messages, or a mistake, as soon as it happens.
Phase 3 – Strengthen your Microsoft 365 email security
- Enforce multi-factor authentication: We make sure MFA is turned on for every email account, so a stolen password alone isn’t enough.
- Tighten email filtering: We review Microsoft Defender for Office 365 settings, tag external emails and help block lookalike domains.
- Protect your own domain: We configure SPF, DKIM and DMARC so criminals find it much harder to send fake emails using your genuine business domain.
Phase 4 – Put a payment verification process in place
- Set a call-back rule: We help you document a simple rule that any new payee or bank detail change is confirmed by phone, using a number already on file.
- Add a second approval: We recommend two-person sign-off for new payees and large or unusual payments, so no one has to make a high-risk decision alone.
- Prepare an incident plan: Your team will know exactly who to call, and in what order, if someone clicks a link or pays a fake invoice.
Phase 5 – Keep testing as scams evolve
- Run regular phishing simulations: Ongoing KnowBe4 tests keep awareness high and show where extra training is needed.
- Report on progress: We track how your team’s results improve over time, so you can see the risk reducing.
- Stay ahead of new tactics: As criminals adopt AI voice cloning, deepfakes and new QR code tricks, we update training and controls to match.
The goal isn’t to create staff who never make mistakes. It’s to build a team that knows when to pause, a process that catches what people miss and the confidence to speak up quickly when something doesn’t look right.
Interactive check
How Protected Is Your Business From Phishing Scams?
Answer four quick questions to see whether your business has sensible protection against phishing scams and fake invoices, or whether your payment process, accounts or team training may need attention.
Before paying a new account or changing supplier bank details, does your team call the supplier on a phone number already on file?
Is multi-factor authentication (MFA) turned on for every email account in your business, including shared and admin accounts?
Has your team completed phishing awareness training or a simulated phishing test in the last 12 months?
If someone clicks a suspicious link or pays a fake invoice, do they know who to call and feel safe reporting it straight away?
Your phishing protection position
Answer all four questions to see your directional result.
This is a quick directional check, not a detailed phishing, Microsoft 365 or security awareness assessment.
Decision support
What does your current phishing protection look like?
Select the description closest to your current position.
Fast answers
Quick answers about phishing scams
Tap a question for a short, practical answer.
Is it enough if the supplier confirms the new bank details by email?
Can email filtering stop all phishing scams?
Will a phishing test embarrass or catch out our staff?
Are small businesses really targeted by phishing scams?
This article provides general cyber security information and isn't legal, financial or incident-response advice. If you suspect fraud or a cyber incident, contact your bank and IT provider immediately. Our October series follows KnowBe4’s "Secret Agents" Cybersecurity Awareness Month campaign.
Ready to protect your team from phishing scams?
At Intellect IT, we help Melbourne businesses reduce the risk of phishing scams with KnowBe4 security awareness training, simulated phishing tests and stronger Microsoft 365 email security.
If you’re unsure how your team would respond to a convincing fake invoice, whether MFA is turned on for every account or how supplier bank detail changes are checked, we can help you put simple, practical protection in place. This Cyber Security Action Month, take a second to find out where you stand.
QUESTIONS, ANSWERED
Frequently asked questions
FAQs – Phishing Scams
What is a phishing scam?
A phishing scam is a fake message that pretends to come from someone you trust, such as your bank, Microsoft, a supplier or your boss, to trick you into sending money, sharing passwords or revealing personal information. Phishing scams arrive by email, text message, phone call and QR code, and they target people rather than technology.
What are the main types of phishing scams?
What is the most common phishing scam targeting Australian businesses?
Business email compromise is the most damaging phishing scam for Australian businesses. Criminals pose as a supplier or staff member and ask for payment to a new bank account. Email compromise and business email compromise fraud were the two most reported business cybercrimes in the ASD’s Annual Cyber Threat Report 2024–25.
What is the difference between phishing and business email compromise?
How can I tell if an email is a phishing scam?
Common signs of a phishing email include urgent deadlines, a sender address that’s slightly wrong, a generic greeting, unexpected attachments, links that ask you to sign in and requests for passwords or codes. If something feels off, don’t click. Contact the sender using details you already have.
How can I tell if an invoice email is a scam?
The biggest warning sign of a fake invoice is a request to change bank details. Also look for pressure to pay quickly, a sender address that doesn’t quite match, and requests to reply by email rather than call. Always confirm payment changes by phoning the supplier on a number already on file.
Can AI make phishing scams harder to spot?
Yes. Criminals now use AI to write polished, error-free phishing emails and to clone familiar voices for phone scams. Spelling mistakes are no longer a reliable warning sign. A verification process, such as calling back on a known number, works even when the message looks and sounds genuine.
Ready when you are
Ready to experience
IT that just works?
Talk to an IntellectIT specialist. No obligation, no sales pitch, just honest advice for your business.
