Phishing Awareness: How to Spot and Stop Attacks (Australian Business Guide)

Phishing remains the single most common way attackers get into Australian businesses, and it almost never starts with clever code. This guide pulls together current ACSC, Cyber Security NSW and CISA guidance.

Phishing Awareness: How to Spot and Stop Attacks (Australian Business Guide)

Phishing remains the single most common way attackers get into Australian businesses, and it almost never starts with clever code. It starts with a convincing message and a person in a hurry. This phishing awareness guide pulls together current guidance from the Australian Cyber Security Centre, Cyber Security NSW, CISA and leading banks and security vendors into one practical playbook your whole team can use.

By the end you will know what phishing is, how to spot the red flags across every channel, what to do if someone takes the bait, and how to protect your business for the long term.

What is phishing, and why does it work?

Phishing is a form of social engineering. A cybercriminal poses as a trustworthy colleague, supplier or organisation to lure someone into handing over sensitive information or access, rather than attacking your technology directly. It arrives as fake emails, text messages, phone calls or online content that look legitimate, usually asking you to click a link, open an attachment, download software or “confirm” personal and banking details.

Attackers impersonate the organisations you already deal with: banks, telcos and internet providers, energy companies, couriers, online retailers and government agencies. They will copy real branding and marketing collateral to look the part. It works because it targets people, not firewalls, and because urgency, authority or reward can override caution in the moment.

A single successful click can give an attacker an initial foothold in your network. From there the result can be a data breach, financial loss, identity fraud, malware or full-blown ransomware. For a small business, even a minor incident can be devastating.

Phishing terms worth knowing

Smishing is phishing delivered by SMS, often a shortened link to a fake site or malicious download. Vishing is phishing by phone call, pressuring you to share details or grant remote access. Pharming is malware that silently redirects you from a legitimate web address to a convincing fake. Business email compromise (BEC) is a targeted attack impersonating an executive or supplier to redirect payments. Ransomware is malware, frequently delivered by phishing, that encrypts your files and demands payment.

Phishing by the numbers

Independent assessments show how easily phishing slips past both technology and people, and how rarely it gets reported: 8 in 10 organisations had at least one person fall for a phishing attempt during testing; 84% of employees took the bait within the first 10 minutes of receiving a malicious email; only 13% of targeted employees actually reported the phishing attempt; 70% of malicious files or links were not blocked at the network border; and mobile users are roughly three times more likely to fall for a phishing link than on desktop, with 56% of users having tapped a phishing URL on their phone.

The lesson for leaders is simple: technology stops a lot, but not everything. The two highest-value moves are making it easy and blameless for staff to report suspicious messages, and putting layered controls behind the inevitable click.

The anatomy of a phishing attack

Most attacks follow the same three moves. Recognise the pattern and the individual messages become far easier to catch. First, the attacker selects the bait, crafting a lure with a subject line designed to make you open it, most effectively themed around financial security alerts, organisation-wide announcements, and user-specific notices such as training or account updates. Second, they set the hook, casting widely and waiting, since it only takes one person to click, open or reply for the attacker to gain a foothold. Third, they reel in the catch: once someone engages, the attacker harvests credentials or runs malware, then tries to move laterally and reach valuable data.

How to spot a phish: the red flags

No single sign proves a message is malicious, but the more of these you see, the more suspicious you should be: urgency or threats such as “act now” or account suspension notices; too-good-to-be-true offers like unexpected rewards or refunds; mismatched sender or links where display names look right but addresses don't, so hover over links before clicking; look-alike addresses with domains altered by a character; spelling, grammar and odd branding errors; requests for credentials or payment such as being asked to log in via a link or pay by gift card or cryptocurrency; unexpected attachments, especially .exe, .bat or .zip files, or Office files asking you to enable macros; and out-of-pattern requests such as changes to bank details or new ways of sharing files.

The golden rule of verification: if a message asks you to act, verify it independently. Contact the person or organisation using details you source yourself, from their official website or a number you already hold, never the contact details in the suspicious message.

Phishing across every channel

Phishing is no longer just an email problem. Attackers reach people wherever they are, and the same device often holds both work and personal accounts. Email remains the classic vector, with malicious links and attachments, spoofed senders and fake login pages. SMS (smishing) delivers a text with a shortened link to a malicious site or app download. Phone calls (vishing) see callers impersonate banks, telcos, government or your own executives, often pushing you to install remote-access tools like AnyDesk or TeamViewer. Messaging apps such as WhatsApp, Messenger and Instagram lure you into downloading spyware or clicking malicious links. Malicious ad networks in apps use compromised in-app URLs that quietly trigger malware downloads. Mobile generally sees small screens and on-the-go tapping make people far more likely to fall for a link than on desktop.

Practical habits help: don't engage with callers asking for personal information, treat any request to pay by gift card as a scam, scan attachments before opening, keep macros disabled by default, and keep your operating system and apps updated.

Business email compromise: the costly cousin

Business email compromise is among the most expensive threats facing Australian businesses. Criminals impersonate an executive or supplier, using a hacked mailbox or a look-alike domain, to redirect payments or extract information. Two real examples make the risk clear.

In one case, an employee received an email apparently from a company executive asking her to buy six $500 prepaid cards as confidential staff gift vouchers and photograph them as proof. The executive never sent it; every message came from a random address.

In another, a construction business received an email from a “supplier” advising new bank details. No one called to confirm. The business paid an invoice of over $70,000, a second employee paid it again, and more than $150,000 was lost. The supplier's mailbox had been hacked. No funds were recovered.

The fix costs almost nothing: be cautious of any urgent payment request or change of bank details, and introduce a formal process to call the sender to confirm using a number you already hold, never the details in the email.

What to do if you've taken the bait

Mistakes happen, and speed matters far more than blame. Work through these steps in order: stay calm and report it to your IT or security team straight away (for personal accounts, report to ReportCyber at cyber.gov.au/report); disconnect any device where you granted remote access, and have it checked before banking on it again; change your passwords from a clean device, starting with email and banking, then anywhere the password was reused; turn on multi-factor authentication so a stolen password alone is not enough; secure your money by contacting your bank immediately if card or banking details were shared; run a security scan across affected devices; protect your identity by contacting IDCARE (idcare.org / 1800 595 160) if personal information was exposed; and warn others so colleagues, family and friends can watch for the same scam.

How to protect your business from phishing

No single control stops phishing. A layered approach aligned to the ACSC Essential Eight blocks the bait, contains the click and limits the damage. The ACSC's recommended starting points are multi-factor authentication, software updates and backups.

Turn on multi-factor authentication everywhere, starting with email, banking and admin accounts. Keep operating systems, applications and security software updated automatically. Back up important information regularly, keep a copy offline or immutable, and test your restores. Use security software and email filtering to detect and quarantine malicious content. Use strong, unique passphrases with a password manager. Apply least-privilege access so one compromise affects only what that person needs. Limit and secure shared accounts. Configure SPF, DKIM and DMARC to make your domain harder to spoof. Educate staff regularly; awareness is not a once-off. Maintain an incident response plan with clear reporting steps and a printed copy.

Many of these systems are complex to configure safely. The ACSC recommends speaking to an IT professional and working towards Maturity Level One of the Essential Eight.

Reporting a phish in Australia

Reporting helps authorities disrupt campaigns and protects others from the same scam. If something looks strange, report it, even if you didn't click. At work, report to your internal IT or security team, and don't forward the email to colleagues. ReportCyber (ACSC) is at cyber.gov.au/report. Scamwatch (ACCC) is at scamwatch.gov.au/report-a-scam. IDCARE is at idcare.org or 1800 595 160. Contact your bank immediately if financial details were shared.

Frequently asked questions

What is phishing? Phishing is a social-engineering scam where a cybercriminal pretends to be a trusted person or organisation to trick you into revealing sensitive information or granting access, usually by email, SMS, phone call or online message.

How do I spot a phishing email? Look for urgency, too-good-to-be-true offers, mismatched sender addresses and links, look-alike domains, spelling errors, requests for passwords or payment, and unexpected attachments. Several signs together mean you should verify the request independently.

What should I do if I clicked a phishing link? Stay calm and report it to IT, change passwords from a clean device, enable multi-factor authentication, contact your bank if money is involved, run a security scan, and report to ReportCyber at cyber.gov.au/report.

How can my business protect itself from phishing? Use a layered, Essential Eight-aligned approach: MFA, software updates, backups, email filtering, strong passphrases, least-privilege access, SPF/DKIM/DMARC and regular, blameless security awareness training.

Turn awareness into a managed defence with Synex

Awareness is the first layer. Synex Technology turns it into an ongoing, managed defence, so your people, mailboxes, devices and data are protected by design, not by luck. As an Australian managed service provider based in Brisbane with offices in Sydney, Canberra and Adelaide, we help small and mid-market businesses build layered cyber resilience, from email security and MFA to staff training, monitoring and incident response.

This article is general information and not legal advice. For guidance specific to your business, speak with a qualified IT or cyber security professional. Content synthesised from publicly available phishing awareness materials from the ACSC/ASD, Cyber Security NSW, CISA and others, current as at 2026.

Read next

← Back to Insights