Phishing remains the starting point for the vast majority of cyber incidents we see at Perth businesses - not because spam filters have failed, but because the emails are getting harder to tell apart from the real thing. Here are the tactics that come up again and again, based on patterns we see across local businesses.
Why Phishing Still Works
Modern phishing emails rarely look like the obvious scam messages of a decade ago. They're often well-written, branded convincingly, and timed to arrive when someone is busy and likely to act quickly without scrutinising every detail. Attackers don't need to fool everyone - they only need one person to click, reply, or enter their details.
Common Tactics We See
Fake Invoice or Payment Requests
An email arrives that looks like it's from a supplier, with an attached "updated invoice" or a note that their bank details have changed. The branding and tone often closely match real correspondence - sometimes because the attacker has compromised a genuine supplier's mailbox and is replying within an existing email thread.
"Urgent" Requests From Management
A message appears to come from a director or manager, often sent outside business hours or while that person is "travelling and hard to reach by phone." It asks for something time-sensitive - a funds transfer, gift cards, or sensitive information - and leans on urgency and authority to discourage the recipient from double-checking through another channel.
Fake Microsoft 365 / Login Pages
An email warns that a password is about to expire, a document has been shared, or a mailbox is over quota - with a link to a login page that looks identical to the real Microsoft 365 sign-in screen. Credentials entered there go straight to the attacker, who can then use them to access email, send further phishing emails from a legitimate account, or set up mail forwarding rules to monitor communications.
Fake Delivery and Service Notifications
Messages mimicking couriers, telcos, or utility providers - "your package couldn't be delivered," "your bill is overdue" - designed to create a small sense of urgency that prompts a click without much thought.
Reply-Chain Hijacking
Rather than starting a new conversation, the attacker replies within a real, existing email thread (often because one party's mailbox has already been compromised). Because the thread history looks legitimate, recipients are far less likely to question a new attachment or link appearing partway through.
Red Flags to Look For
- Unexpected urgency - pressure to act immediately, especially around payments or sensitive information.
- A request to bypass normal process - "don't worry about the usual approval steps for this one."
- Slightly altered email addresses - a domain that looks right at a glance but has a subtle difference (an extra letter, a different top-level domain).
- Links that don't match where they claim to go - hovering over a link shows a different destination to the text or branding.
- A request for a change to banking details or payment method via email alone, with no other verification.
What to Do If You Spot One
The single most important thing is having a clear, simple process for reporting suspicious emails - and making sure staff know it's always better to report something that turns out to be harmless than to stay quiet about something that turns out to be real.
- Don't click links or open attachments - forward or report the email through your organisation's reporting process.
- If a request involves money or sensitive information, verify it through a separate, known channel - call the person directly using a number you already have, not one from the email.
- If you've already clicked a link or entered credentials, report it immediately so passwords can be reset and account activity reviewed.
Building Resilience Beyond Awareness
No amount of training will catch 100% of phishing attempts - some will always get through. That's why awareness training works best alongside technical controls: multi-factor authentication limits the damage if credentials are stolen, email filtering catches a large proportion of attempts before they reach an inbox, and regular phishing simulations help staff build the instinct to pause and verify before acting.
Frequently Asked Questions
What's 'reply-chain hijacking' and why is it so convincing?
It's when an attacker replies inside a real, existing email thread, usually because one party's mailbox has already been compromised, rather than starting a fresh suspicious-looking email. Because the thread history looks completely legitimate, people are far less likely to question a new attachment or link that shows up partway through.
How do I check if a link in an email is safe before clicking?
Hover over the link without clicking and look at where it actually points, if the destination doesn't match the text or the branding, treat it as suspicious. Combine that with checking the sender's actual email address rather than just the display name, since that's another common way these emails get past a quick glance.
What should I do if I've already clicked a phishing link or entered my details?
Report it immediately rather than staying quiet about it, the faster passwords are reset and account activity is reviewed, the less time an attacker has to do anything with what they got. It's always better to report something that turns out to be harmless than to sit on something that turns out to be real.
If someone asks me to change bank details or send an urgent payment by email, what should I do?
Verify it through a separate channel before acting, call the person or supplier directly using a phone number you already have on file, not one provided in the email itself. Legitimate requests to change payment details essentially never come through email alone with no other way to confirm them.
We run phishing simulations and ongoing security awareness training for Perth businesses - helping staff recognise these tactics before they cause harm.
Security Awareness Training →Not sure how your team would respond?
Call 0433 087 091 for a free, no-obligation conversation about phishing simulations and staff training for your business.
Book a Free ConsultationFor related reading, see our guides to Phishing & Staff Security Training for Perth Businesses and Business Email Compromise: How Perth SMBs Can Stop Invoice Fraud.