Tech

How to Spot a Phishing Email or Text Before You Tap

Published

on

Why scams work

You know the moment. A text pings in saying your parcel is waiting and you need to pay a redelivery fee, or an email lands warning that your account has been locked. There is a button or a link, and a quiet voice says to hurry before you lose something. That moment, the pause between the message and the tap, is exactly where scams win.

They win because they are built on three things. Urgency, so you act before you think. Impersonation, so the message looks like it is from a name you trust. And a fake link or attachment, which is where the damage actually happens. Understand those three pillars and you can spot most phishing attempts before your thumb reaches the screen.

This guide walks you through what phishing is, the red flags to look for in emails and texts, why some scams now look worryingly polished, and what to do if you have already tapped or clicked. It is general consumer safety information, not legal or security advice. The official channels, Scamwatch, the Australian Cyber Security Centre, eSafety and your bank, are the places to confirm anything and to report a scam when you see one.

The good news is that you do not need to be technical to defend yourself. Scammers are not hacking into your accounts, they are persuading you to open the door, and persuasion is something you can learn to resist. The people who fall for these messages are not stupid. They are usually tired, busy or worried, which is exactly the state a scammer is trying to create. So the defence is not intelligence, it is a handful of habits you can practise until they are automatic.

What phishing actually is

Phishing is a fake message that pretends to be from a trusted organisation. The organisation might be your bank, Australia Post, the tax office, a retailer you shop with, or even a colleague. The goal is to get you to do one of three things: click a link, open an attachment, or hand over a login code, password or personal detail.

The name is a play on fishing. The scammer casts a message out to thousands of people, and waits for someone to bite. They do not need everyone to fall for it. They need a small number of people to act quickly, and the numbers game means even a tiny success rate pays for them. That is why these messages are so widespread, and why they will keep coming no matter how many people learn to spot them.

Here is the key thing to hold onto. A phishing message is not a technical hack. It is a confidence trick delivered through your inbox. The scammer is not breaking into your accounts, they are persuading you to open the door yourself. That is why learning to recognise the pattern is such an effective defence, because the message has to convince you before it can hurt you.

Phishing also targets businesses, not just individuals. One clicked link in a work inbox can hand a scammer access to supplier records, client lists or payroll. If your job involves handling money or personal data, the red flags in this guide apply double, because a work inbox is a far more valuable target than a personal one.

The anatomy of a phishing message

Before you look at any single detail, look at the message as a whole. Most phishing attempts share the same skeleton, and once you know the bones, they become much easier to spot.

Check the sender address first, not just the display name. Anyone can set their display name to your bank’s name. The actual email address behind it is harder to fake, so look at what comes after the @ symbol. A message from “support@yourbank.com” is very different from “support@yourbank-security.com” or “yourbank@gmail.com”.

Look at the greeting. Legitimate organisations that hold your details usually use your name. A generic “Dear customer” or “Dear user” is a warning sign, because it suggests the sender does not actually know who you are.

Feel the pressure. Phishing leans on deadlines: “within 24 hours”, “your account will be closed”, “final notice”. Real organisations rarely threaten you into acting within the hour. Urgency is the tell that the sender wants to skip your judgement.

Check the link before you commit to it. Hover over a link on a computer and the real address appears at the bottom of the window. On a phone, press and hold the link to see where it actually goes. If the address looks wrong, do not tap.

Beware the unexpected attachment. Invoices, receipts and documents you were not expecting are a common way to deliver malware. If you were not expecting a file, do not open it. And treat any request for a code or password as an instant red flag, because no legitimate organisation needs your password sent to them in a message.

A useful habit is to assume the worst of any unexpected message and then work backwards. Not paranoia, just a default pause. A real message from your bank does not mind if you take an hour to check it, because your bank is not racing anyone. A scam message does mind, because the scammer knows the longer you look, the more likely you are to notice the cracks.

Email red flags, specifically

Email is where phishing started, and it is still where the craftiest attempts live. The red flags are specific enough to name.

Look-alike domains are the classic. The scammer registers a domain that looks right at a glance, your bank’s name with an extra letter, a missing letter, or a swapped character. Yourbank.com and yourbannk.com look identical in a rushed glance. Read the domain slowly, character by character, when the message matters.

Check the reply-to address. A sender address can be made to look legitimate while the reply-to field points somewhere else entirely. If you reply, where does it actually go? If the reply-to does not match the sender, treat the message as hostile.

Spoofed display names deserve a mention because they fool so many people. The message may show the name of your bank or a person you know, but the email address behind it is a string of random letters. On a phone, where you often see only the display name, this is especially easy to miss.

Then look at the subject line. The urgent ones are the reliable ones to distrust: “account locked”, “invoice overdue”, “payment failed”, “suspicious sign-in”. Any subject that tells you something is wrong and you must act now is doing the work of a scammer.

Finally, learn the check that saves the most people. When you are not sure about a link, do not click it at all. Open your browser and type the organisation’s address yourself, or use the app you already have. If the message claims your bank account is locked, log in the normal way and look. The truth will be there, and the fake link never gets your tap.

One more layer worth knowing: some phishing emails appear to come from people you actually know. When an account is hacked, the scammer can send messages from a genuine address, which makes them almost impossible to spot by sender alone. If a colleague or family member emails you out of the blue asking for gift cards, an urgent transfer or a click on a strange link, treat it the way you would an unknown sender and confirm with them over the phone or face to face before you do anything.

Text and call red flags, specifically

Text messages and phone calls are where phishing has shifted in recent years, because people trust texts more than they trust email. The red flags are slightly different.

Shortened links are an instant caution. If a text about a delivery or a toll uses a shortened address, you cannot see where it leads without tapping, which is exactly the problem. Treat any shortened link in an unsolicited message as suspicious.

Delivery and fine messages top the scam charts in Australia. A parcel waiting, an unpaid toll, a fine you do not remember. The detail that gives them away is usually the request for payment or personal details to “release” or “cancel” something. If you were genuinely expecting a parcel, you can check the tracking through the official website or app, never through the link in the text.

The “you have won” message still does the rounds, and so do callback numbers. A message that tells you to call a number to claim a prize or sort out a problem is often pointing you at a scam call centre. Compare the number against the official one on the organisation’s website. If it does not match, it is not them.

Calls can be spoofed too. Scammers can make a call display a legitimate-looking Australian number, including your bank’s actual number, so the old “I checked the caller ID” test no longer holds up. If a caller asks you to confirm your password, read back a code or transfer money to a “safe account”, end the call and ring the organisation back on a number you find yourself. A real bank will never be offended by you hanging up to check.

One sentence does a lot of the work here. Government agencies and banks do not text you a link to log in. If a message claims to be from the tax office, Australia Post or your bank and asks you to log in through a link, it is not from them. When a suspicious text does arrive, you can report it to Scamwatch and then delete it, and most phones let you block the sender so it cannot come back.

Why some scams now look more believable

The uncomfortable truth is this. The old advice was that spelling mistakes and awkward grammar gave scams away. That advice is no longer reliable, because generative AI has quietly removed the errors.

Scammers now use AI to fix the spelling, smooth the grammar and mimic a brand’s tone of voice. A phishing email can read as professionally as the real thing, because it was polished by the same kind of tool that writes everyday content. “It looked professional” is no longer a safe test, and neither is “the logo looked right” or “the writing sounded like them”, because all of those can now be faked cheaply and at scale.

If you want to understand the technology behind this, you do not need to be a computer scientist. There is a plain-English explainer on generative AI on this site, and the short version is this: it is software that produces human-like text, and when it is pointed at a scam, it makes the scam more convincing.

So what is the reliable test now? The channel. When a message asks you to act, do not judge it by how polished it looks. Judge it by whether you can verify it through an independent route. Contact the organisation through its official app, its official website or a phone number you looked up yourself. Never use the link or the number in the message. A scam can imitate your bank’s email perfectly, but it cannot imitate the fact that you logged in through the real app and found nothing wrong.

What to do if you already tapped or clicked

First, do not panic. Falling for a phishing message happens to careful people every day, and what you do next matters far more than the tap itself.

Stop. Do not enter anything further, and do not click anything else in the message. Close the page or the conversation.

If you entered a password, change it now for that account, and change it from a clean device, not from the device where you clicked. Use a strong, unique password. If you reused that password anywhere else, change it there too, because scammers will try it against other accounts.

Turn on two-factor authentication on the account if you have not already. Even if a scammer has your password, a second code they cannot get will usually stop them.

Contact the real organisation. If the message pretended to be your bank, call your bank using the number on the back of your card or their official website. If it pretended to be a government agency, contact that agency through its official channel. Tell them what happened and ask what they recommend.

If you sent money or handed over banking details, act quickly. Contact your bank immediately about a transfer, and report the scam to Scamwatch so the reports help warn other people. The sooner you act, the more options you have.

After a scam, watch for a second wave. Scammers sometimes follow up pretending to be a recovery service that can get your money back for a fee, or a fake investigator who needs your details to help. Genuine recovery help is free, from your bank, Scamwatch or IDCARE, and anyone who asks for money to recover your money is just another scammer trying to profit twice from the same misfortune.

Slow down. Verify. Then act.

Protecting yourself from phishing is mostly a set of small habits, and none of them require technical skill. Slow down when a message demands speed, because urgency is the scammer’s favourite tool. Verify through the official channel, the app, the website or a number you looked up yourself, not the one in the message. Then, and only then, act.

Switch on two-factor authentication wherever it is offered. It is one of the single most effective things you can do, because it turns a stolen password into a dead end. Keep your phone and computer updated, because those updates close the security holes scammers use. Consider a password manager, which creates strong unique passwords for every account and means one leak does not become a breach of everything. And when you spot a scam, report it to Scamwatch, because every report makes the picture clearer for the people whose job it is to shut these operations down.

The message that nearly gets you will probably come again, in a slightly different disguise. Next time, let it wait. Check the sender, feel the pressure, and verify before you tap. That small pause is the difference between a scam that works and one that bounces off.

Sources:

  • ACCC Scamwatch, How to recognise a scam and report it
  • Australian Signals Directorate (ACSC), Phishing
  • eSafety Commissioner, Scams and staying safe online

Trending

Exit mobile version