The best way to teach staff to spot phishing is to show them the emails actually circulating — not cartoon diagrams of a fish hook. Below are five phishing email patterns taken from real Australian scam alerts and threat reports current in 2026. For each one: what the email looks like, the tell-tale signs, and the right response. Use them as the basis for a team briefing, a quiz, or the scenarios your next phishing simulation should cover.
Key takeaways
- The five patterns cover most real attacks: government (ATO/myGov) impersonation, invoice payment redirection, fake login pages, purchase callback scams and fake shared-document prompts.
- Every one of them exploits trust in a familiar sender or process — none relies on the recipient being careless.
- The Australian Taxation Office will never send a link asking you to sign in to myGov; Scamwatch keeps live alerts for the current campaigns.
- The correct response to every example is the same: do not click, do not reply, report — via the mail client's Report button, and externally via Scamwatch.
- Rehearsing these exact scenarios in monthly simulations is what converts recognition into reflex: Cyber Aware's published benchmark for monthly programmes is an average 80% reduction in clicked links within eight months.
Example 1: The ATO / myGov impersonation
What it looks like: An email claiming to be from the Australian Taxation Office: "You have a new payment update in your ATO profile" or "Review your income statement" — with a button that goes to a fake myGov sign-in page. The ATO and Scamwatch have both re-issued warnings for exactly this pattern around tax time.
The tells:
- The sender domain does not end in .gov.au
- A link asking you to sign in to myGov — the ATO states it will never send this
- Urgency around a payment or deadline
The response: Do not sign in through any emailed link. Type my.gov.au into the browser yourself. Suspicious contact claiming to be from the ATO can be reported to ReportScams@ato.gov.au.
Example 2: The invoice with changed bank details (payment redirection)
What it looks like: An invoice or a short reply on an existing thread — often from a supplier you genuinely deal with — advising updated payment details, sometimes with a polite apology about a "new banking provider". Scamwatch's alert on fake business invoice scams describes scammers posing as a real business you have recently dealt with, sending invoices with changed payment details so your money lands with them.
The tells:
- A change to bank details, however routine it sounds
- Pressure to process before a "due date"
- A reply-to address that differs subtly from the real one
The response: Call the supplier on the number already in your records — never the number in the email — before any payment. This single callback habit stops more business losses than any software filter.
Example 3: The Microsoft 365 / email "keep your password" login page
What it looks like: "Your mailbox is full" or "Your password expires today" — click through and you land on a page that is a near-perfect clone of the Microsoft sign-in, which quietly captures whatever you type and forwards you to the real site. This credential-capture pattern is the most common outcome of a clicked link.
The tells:
- The URL is not a genuine Microsoft domain
- Generic IT language nobody in your organisation would actually use
- The page asks again for the second authentication factor (a sign it is harvesting, not verifying)
The response: Close the tab. If you already typed your password, treat it as stolen — reset it from another device, revoke sessions, and check for inbox rules you did not create (the full sequence is in what to do when an employee clicks a real phishing link).
Example 4: The fake purchase callback scam
What it looks like: A message saying you bought something you did not buy, and that you must call a phone number to stop or reverse the payment. Scamwatch issued a dedicated alert on this pattern. The number connects to the scammer, who talks you into "refunding" or handing over remote access.
The tells:
- A purchase you cannot find in your own accounts
- A phone number supplied in the message itself
- Well-meaning urgency: "call within 24 hours or the charge stands"
The response: Never call the number in the message. Check your own bank or card statement independently, and if you need to contact your bank, use the number on your card.
Example 5: The fake shared document
What it looks like: "Sarah shared 'Q4 Payroll.xlsx' with you" — a SharePoint or OneDrive notification, sometimes arriving over Teams or in the same thread as a real conversation, linking to a page that asks you to sign in to view the file. Because remote teams live in shared documents, the prompt feels completely normal.
The tells:
- A document you were not expecting, from someone who has never shared files with you
- A sign-in prompt where there should just be a download
- The preview disappears when you hover over the real link destination
The response: Check with the sender through a channel you already trust — chat them directly, do not reply on the same thread. If you signed in, treat the credentials as compromised.
The pattern behind all five
Notice what every example has in common: none of them asks the reader to be careless. They each hijack a routine — tax time, supplier payments, password expiry, a delivery, a colleague sharing a file. That is why once-a-year awareness training does not hold up: recognising hijacked routines is a reflex, and reflexes only come from rehearsal.
A monthly simulation programme built on these exact scenarios, with automatic coaching after every click, is how that reflex gets built across a team. Cyber Aware's phishing simulations draw on 100+ templates spanning easy-to-spot through hard-to-detect, and pair with security awareness training on the same enrolment. Human Risk Reporting then shows per person which examples are still landing, and the comparison page is the place to start if you are weighing platforms.
FAQ
What are the most common phishing emails right now? In Australia, the most reported patterns are ATO and myGov impersonations around tax time, fake business invoices with changed payment details, and fake purchase callback scams — all three carry current Scamwatch or ATO alerts.
How do I check if an email is really from the ATO? Do not reply or click. Call the ATO on 1800 008 540 or check by signing in at my.gov.au directly. Any suspicious contact claiming to be from the ATO can be forwarded to ReportScams@ato.gov.au.
What should staff do when they spot one of these? Report it with the mail client's built-in Report button — see how to report a phishing email in Outlook — and delete it after reporting. Never reply or forward it to a colleague to ask if it is real.
Can we use these examples in our own training? Yes — they make ideal simulation scenarios precisely because they are the attacks actually being reported. The Australian Signals Directorate specifically warns staff to treat unexpected requests for personal or financial information, and changes to banking details, as red flags.
Related guides
- How to report a phishing email in Outlook
- What to do when an employee clicks a real phishing link
- Phishing simulations
- Security awareness training
Sources
- Scamwatch: Australian Taxation Office (ATO) and myGov impersonation scams, accessed 29 September 2026.
- Scamwatch: Scam alert — Fake business invoice scams, accessed 29 September 2026.
- Scamwatch: Scam alert — Fake purchase callback scams, accessed 29 September 2026.
- Australian Taxation Office: Scam alerts, accessed 29 September 2026.
- Australian Signals Directorate: Guidelines for personnel security, accessed 29 September 2026.