Module 2 of StartCloud's Cyber Hygiene for Staff learning pathway, in six short units with a knowledge check: why phishing works on busy people (urgency, authority, familiarity), the red flags in a suspicious email walked through on a mock example, scam texts, calls and QR codes, business email compromise and the verify-by-phone golden rule, and the two-second habits that beat most of it.
How to Spot a Phishing Email Before You Click
Why phishing still works
First, a reframe. Phishing does not work because people are gullible. It works because people are busy. It is a numbers game: send a convincing fake to enough inboxes and a handful of people, mid-meeting, mid-deadline, mid-school-pickup-panic, will click before they think. The scammer does not need you to be careless all day. They need two careless seconds.
That is also why phishing sits year after year among the most commonly reported cybercrimes for Australian businesses. Not because it is clever. Because it scales, and because it is aimed at the one thing every workplace has plenty of: people with too much to do.
Nearly every phishing message, on any channel, pulls on the same three levers. Learn to feel the tug and you are most of the way there.
Your account will be suspended in 24 hours. Your parcel will be returned today. The invoice is overdue and the matter is escalating. Deadlines switch off the careful part of your brain, which is exactly the point.
We are wired to respond quickly to people and institutions with power over us. A message that appears to come from your bank, the tax office, or your own managing director gets opened faster and questioned less.
Microsoft 365, Australia Post, myGov, your bank. The logos are copied, the layout is copied, and your eye has seen the real thing a thousand times, so it fills in the gaps and vouches for the fake.
Here is the trick the rest of this module builds on: the moment a message makes you feel rushed, leaned on, or flattered, that feeling is your cue to slow down, not speed up. Real organisations almost never need you to do anything in the next ten minutes. Scammers almost always do.
Time to meet one in the wild. Below is a fake we built for training, the classic Microsoft 365 password expiry phish that lands in Australian inboxes every single week. It has five red flags planted in it. See how many you can spot before reading the list underneath.
Dear user,5
Your Microsoft 365 password expires today. If you do not verify your account within 24 hours, your mailbox will be permanently suspended and your files will be deleted.
Hover reveals the real destination: http://m365-account-verify.dodgy-example.invalid/login
Anyone can type anything into the display name field. The actual sending address is the tell: here it is a random domain dressed up with the word "microsoft" and a sneaky zero. On a phone, tap the sender's name to reveal the real address before you trust it.
The link text says one thing, the real destination says another. On a computer, rest your mouse over the link without clicking and the true address appears in the corner of the window. If the two do not match, or the real one is a jumble of letters, walk away.
A 24-hour countdown, a suspended account, files about to be deleted. Real IT teams and real companies give notice, send reminders, and do not threaten. A deadline that arrives out of nowhere exists to stop you thinking.
Unexpected attachments are how a lot of nasty software arrives, especially compressed files and documents that ask you to "enable content". If you were not expecting it, do not open it, even if you know the sender. Their account may be the one that got phished.
"Dear user" from a company that knows your name. Phrasing that is almost right but not quite. The polish has improved a lot lately, so treat a perfect-looking email with the same suspicion as a clumsy one, but an odd tone is still a free clue when you get one.
Not every phish threatens you. Some flatter you instead: a refund you were not owed, a gift card for a survey, a prize from a competition you never entered. Unexpected bad news and unexpected good news deserve exactly the same squint. Nobody is giving away $500 for three multiple-choice questions.
One more Australian favourite while we are here: the fake Australia Post parcel notice. Same recipe, different costume. A delivery "could not be completed", a small "redelivery fee" is needed, and the link wants your card details. If you are genuinely expecting a parcel, go to the carrier's website or app yourself. Never through the link.
If phishing only lived in email, spam filters would have mostly won by now. So it moved. The same three levers from Unit 1, urgency, authority and familiarity, now arrive by text, phone call and QR code, where there is no spam filter and your guard is lower.
The scam text
Parcel could not be delivered, road toll unpaid, myGov account suspended, "Hi Mum, I lost my phone". Texts feel more personal than email and get read within minutes, which scammers know. Same levers: urgency, authority, familiarity, just 160 characters at a time.
- Real couriers and toll operators do not ask for card details by text
- myGov does not send links asking you to sign in
- A number you do not recognise plus a link equals do not tap
- When unsure, open the real app or website yourself
The scam call
Someone from "the bank's fraud team" says your account is being drained right now and needs you to move money to a safe account. Or "the ATO" says there is a warrant out. The pressure is the product: keep you on the line, keep you scared, keep you from calling anyone who would talk sense.
- Banks never ask you to move money to a safe account
- The ATO does not threaten arrest over the phone
- Caller ID can be faked, so the number proves nothing
- Hang up, then call back on the official number yourself
The dodgy QR code
A QR code is just a link you cannot read. Scammers stick fake ones over real ones on parking meters and posters, and drop them into fake invoices, because your phone will cheerfully open whatever is underneath. The cafe menu is probably fine. The sticker on a pole asking you to "verify your payment" is not.
- Treat a QR code exactly like a link from a stranger
- Check where it wants to take you before you sign in to anything
- Be extra wary of QR codes on invoices and unexpected letters
- A sticker on top of another sticker is a genuine red flag
Scamwatch, run by the National Anti-Scam Centre, is the place Australians report scam texts, calls and emails, whether or not any money was lost. Your two-minute report helps get scam numbers and websites shut down and warns the next person. Think of it as leaving a one-star review that actually does something.
Now for the version aimed squarely at businesses, the one the professionals call business email compromise. No dodgy links, no malware, often not a single spelling mistake. Just an email that convinces someone in your business to send real money to the wrong place. Of everything in this module, this is where Australian businesses lose the most, and the amounts per incident can be brutal.
An email arrives from a supplier you genuinely use: "Please note our bank details have changed, use the new account for the attached invoice." Often the scammer has quietly broken into the supplier's real mailbox, so the email is authentic, the invoice is real, and only the BSB and account number are fake. The money leaves, and nobody notices until the supplier chases the unpaid bill weeks later.
"Are you at your desk? I need a favour and I'm about to go into a meeting." It looks like it comes from the owner or a director, it targets someone helpful, and the favour is always the same: buy gift cards, scratch the codes, send photos. Absurd in the retelling, effective in the moment, because saying no to the boss feels harder than it should.
The wider family of both tricks. A scammer sits inside or alongside a real email conversation about a real payment, then nudges the money somewhere else: a changed invoice, a new remittance address, an "updated" payroll bank account for a staff member. Everything about the transaction is legitimate except the destination.
Any change of bank details. Any unusual or urgent payment request. Any "keep this between us" favour from the boss. Pick up the phone and check with the real person, using a number from your own records or their official website, never a number from the email itself, because that number belongs to whoever wrote the email. One thirty-second call beats every filter, every policy and every gut feeling. Honestly, if your team takes a single habit from this whole pathway, make it this one.
And a word for whoever pays the bills in your business: none of this is a reason to feel silly for nearly falling for one. These scams are built by people who study how offices work. The fix is not being smarter than them at 4:55pm on invoice day. It is a boring, reliable habit that runs even when you are tired.
Everything in this module boils down to four small habits, each costing about two seconds, which together shut down the vast majority of what you just read. Here they are, one last time.
Two seconds with the mouse over a link, or a long press on the phone, shows you where it really goes. Make it automatic, like checking the mirror before changing lanes.
Bank, myGov, Microsoft, the courier. If a message says there is a problem with your account, close the message and sign in the way you always do. If the problem is real, it will be waiting for you there.
New bank details, urgent payments, strange favours: confirm by phone on a number you already had. Out of band just means using a different channel than the one the request arrived on.
Use the report button in Outlook, tell whoever looks after your IT, and pass scams to Scamwatch. Deleting protects you for one afternoon. Reporting protects the next person, and in a small team, the next person sits three metres away.
No shame, no cover-ups, just speed. Tell your IT person or manager straight away, change the password if you typed one in, and let them take it from there. Module 6 of this pathway walks through the first five minutes in detail. The people who report fast are the heroes of these stories. The people who stay quiet for a week are the case studies.
- ACSC (cyber.gov.au): Phishing
- ACSC (cyber.gov.au): Business email compromise
- Scamwatch (National Anti-Scam Centre): scam types and alerts
- Scamwatch: Report a scam
Scam techniques change season to season, so the ACSC and Scamwatch pages above are worth a look whenever something new starts doing the rounds. Details were current at the time of writing (July 2026).
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. Phishing messages lean on three levers to make you click. Which set is it?
2. An email's display name says "Microsoft 365 Support" but the actual address is security-alert@m1crosoft-verify.invalid. What does that tell you?
3. What does hovering your mouse over a link (without clicking) actually do for you?
4. A regular supplier emails to say their bank details have changed, with an invoice attached and due this week. What do you do?
5. You have spotted a phishing email in your work inbox. What is the best move?