5 real phishing email examples (and what to spot in each)

5 real phishing email examples from current Australian scam alerts: ATO/myGov impersonation, invoice payment redirection, fake logins, callback scams and fake shared documents — with the tells and the right response for each.

The best way to teach staff to spot phishing is to show them the emails actually circulating — not cartoon diagrams of a fish hook. Below are five phishing email patterns taken from real Australian scam alerts and threat reports current in 2026. For each one: what the email looks like, the tell-tale signs, and the right response. Use them as the basis for a team briefing, a quiz, or the scenarios your next phishing simulation should cover.

Key takeaways

Example 1: The ATO / myGov impersonation

What it looks like: An email claiming to be from the Australian Taxation Office: "You have a new payment update in your ATO profile" or "Review your income statement" — with a button that goes to a fake myGov sign-in page. The ATO and Scamwatch have both re-issued warnings for exactly this pattern around tax time.

The tells:

The response: Do not sign in through any emailed link. Type my.gov.au into the browser yourself. Suspicious contact claiming to be from the ATO can be reported to ReportScams@ato.gov.au.

Example 2: The invoice with changed bank details (payment redirection)

What it looks like: An invoice or a short reply on an existing thread — often from a supplier you genuinely deal with — advising updated payment details, sometimes with a polite apology about a "new banking provider". Scamwatch's alert on fake business invoice scams describes scammers posing as a real business you have recently dealt with, sending invoices with changed payment details so your money lands with them.

The tells:

The response: Call the supplier on the number already in your records — never the number in the email — before any payment. This single callback habit stops more business losses than any software filter.

Example 3: The Microsoft 365 / email "keep your password" login page

What it looks like: "Your mailbox is full" or "Your password expires today" — click through and you land on a page that is a near-perfect clone of the Microsoft sign-in, which quietly captures whatever you type and forwards you to the real site. This credential-capture pattern is the most common outcome of a clicked link.

The tells:

The response: Close the tab. If you already typed your password, treat it as stolen — reset it from another device, revoke sessions, and check for inbox rules you did not create (the full sequence is in what to do when an employee clicks a real phishing link).

Example 4: The fake purchase callback scam

What it looks like: A message saying you bought something you did not buy, and that you must call a phone number to stop or reverse the payment. Scamwatch issued a dedicated alert on this pattern. The number connects to the scammer, who talks you into "refunding" or handing over remote access.

The tells:

The response: Never call the number in the message. Check your own bank or card statement independently, and if you need to contact your bank, use the number on your card.

Example 5: The fake shared document

What it looks like: "Sarah shared 'Q4 Payroll.xlsx' with you" — a SharePoint or OneDrive notification, sometimes arriving over Teams or in the same thread as a real conversation, linking to a page that asks you to sign in to view the file. Because remote teams live in shared documents, the prompt feels completely normal.

The tells:

The response: Check with the sender through a channel you already trust — chat them directly, do not reply on the same thread. If you signed in, treat the credentials as compromised.

The pattern behind all five

Notice what every example has in common: none of them asks the reader to be careless. They each hijack a routine — tax time, supplier payments, password expiry, a delivery, a colleague sharing a file. That is why once-a-year awareness training does not hold up: recognising hijacked routines is a reflex, and reflexes only come from rehearsal.

A monthly simulation programme built on these exact scenarios, with automatic coaching after every click, is how that reflex gets built across a team. Cyber Aware's phishing simulations draw on 100+ templates spanning easy-to-spot through hard-to-detect, and pair with security awareness training on the same enrolment. Human Risk Reporting then shows per person which examples are still landing, and the comparison page is the place to start if you are weighing platforms.

FAQ

What are the most common phishing emails right now? In Australia, the most reported patterns are ATO and myGov impersonations around tax time, fake business invoices with changed payment details, and fake purchase callback scams — all three carry current Scamwatch or ATO alerts.

How do I check if an email is really from the ATO? Do not reply or click. Call the ATO on 1800 008 540 or check by signing in at my.gov.au directly. Any suspicious contact claiming to be from the ATO can be forwarded to ReportScams@ato.gov.au.

What should staff do when they spot one of these? Report it with the mail client's built-in Report button — see how to report a phishing email in Outlook — and delete it after reporting. Never reply or forward it to a colleague to ask if it is real.

Can we use these examples in our own training? Yes — they make ideal simulation scenarios precisely because they are the attacks actually being reported. The Australian Signals Directorate specifically warns staff to treat unexpected requests for personal or financial information, and changes to banking details, as red flags.

Related guides

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.