Phishing email examples: what Australian scam emails look like
Phishing emails change their costumes constantly, but underneath they reuse the same five patterns. Learn the pattern once and you'll recognise it in whatever disguise it wears next. Every example below is a reconstruction of a common scam: the wording varies, the tells don't.
Got one in your inbox right now? Don't study. Check it: the message check (personal) or business email check walks you through the tells in about two minutes, without pasting the email anywhere.
The five patterns
1. The myGov / ATO refund
From: myGov <[email protected]>
Subject: You have a new refund of $740.60 waiting
Dear customer, our records show you are eligible for a tax refund. To receive your payment, confirm your identity within 48 hours: [Claim my refund]
The tells:
- The real address behind "myGov" isn't a gov.au domain. Expand the sender to see it.
- A refund you weren't expecting, with a deadline. The ATO pays refunds into your bank account after you lodge; it never emails "claim" links.
- The link's real destination (long-press or hover to preview it) isn't my.gov.au.
2. The missed delivery (Australia Post, toll notices, "your parcel")
From: AusPost Delivery <[email protected]>
Subject: Your parcel could not be delivered - action required
Your package AU-30291 is on hold due to an unpaid shipping fee of $2.99. Pay now to schedule redelivery: [Resolve now]
The tells:
- A tiny "fee": the scam isn't the $2.99, it's the card details you type to pay it.
- No real tracking number that works on the carrier's own site: check there directly, never via the email's link.
- Australia Post says it will never ask for payment by email or text to release a parcel.
3. The bank "security alert"
From: CommBank Security <[email protected]>
Subject: Unusual sign-in detected - your access has been limited
We detected a sign-in from an unrecognised device. Your account access has been limited for your protection. Verify your identity to restore access: [Verify now]
The tells:
- Fear plus a login link: the fake page captures your NetBank credentials and often the SMS code too.
- Banks tell you to log in via their app or by typing their address yourself; they don't embed "verify" links.
- Generic greeting ("Dear customer") from a bank that knows your name.
4. The Microsoft 365 / password expiry (aimed at businesses)
From: IT Support <[email protected]>
Subject: Your password expires today - keep current password
Your Office 365 password expires in 4 hours. To keep your current password and avoid losing access to email, verify here: [Keep my password]
The tells:
- Harvests your work login, the entry point for invoice fraud and mailbox compromise.
- Real password expiry happens when you sign in, not via emailed "keep my password" links.
- The sender isn't your actual IT provider's domain; when unsure, ask them directly.
5. The invoice with new bank details (business email compromise)
From: Accounts - Harrison Supply Co <[email protected]>
Subject: RE: Invoice 4471 - updated banking details
Hi, please note we have recently changed banks. Kindly update your records and process the attached invoice to the new account: BSB 000-000, Acc 0000 0000. Regards, Accounts.
The tells:
- The single most expensive email a business can receive. The invoice looks identical to the real supplier's; only the account number changed.
- The sender domain is one letter off the real supplier's, or the reply-to silently differs.
- The defence is a rule, not an eye: every bank-detail change is confirmed by phone on a number you already have, before it's actioned.
The pattern behind all five
Trusted name + manufactured urgency + one requested action. The design can be pixel-perfect and the spelling flawless; polish proves nothing. What gives every phishing email away is infrastructure it can't fake: the sender's real address, and the link's real destination. Check those two things and you've beaten most of them.
Official help and reporting
These are the official Australian services. They are free and they are the ones to trust:
Common questions
- What does a phishing email look like?
- Most phishing emails combine a trusted name (myGov, Australia Post, your bank), a reason to act quickly (suspended account, missed delivery, tax refund), and one requested action: click a link, open an attachment, or reply with details. The design can be pixel-perfect; the giveaways are the sender's real address, the link's real destination, and the pressure to act now.
- How can I check if an email I received is a phishing scam?
- Check three things: expand the sender's display name to see the real address, long-press or hover the link to see its real destination without opening it, and ask whether the email pressures you to act quickly. Scamwarden's free message check and business email check walk you through the full pattern list in about two minutes, without you pasting the email anywhere.
- What should I do with a phishing email after I've spotted it?
- Don't click anything or reply. Report it to Scamwatch at scamwatch.gov.au, and keep the email until you've reported it: the original headers are evidence. If it targets your business, also tell your IT provider and report to ReportCyber at cyber.gov.au. If you clicked and entered details, contact your bank straight away and change the password on any account that shares it.