Quick answer
Be suspicious of any email that creates urgency, asks you to log in, pay an invoice or change bank details, or comes from an address that doesn't quite match the sender's name. Don't click — report it using Outlook's Report button and tell your IT team. If someone already clicked or typed a password, change the password and tell IT immediately.
THE WARNING SIGNS
What a phishing email looks like.
Modern scams can look very polished — AI has ended the era of obvious typos — so focus on what the email is asking you to do, not just how it reads.
- ▸Urgency or a threat. "Your account will be closed", "payment overdue", "action required in 24 hours." Pressure is designed to make you act before you think.
- ▸An unexpected login or payment request. A link to "verify your account", an invoice you weren't expecting, or a request to release a payment.
- ▸A request to change bank details. The single most costly scam for businesses. Treat any change to payment or account details as suspicious until verified by phone.
- ▸The sender doesn't match. The display name says a supplier or a colleague, but the actual email address is a lookalike or a stranger's domain.
- ▸Links that don't go where they say. Hover over a link (don't click) and check the real destination in the bottom corner. Mismatched or odd URLs are a red flag.
- ▸Unexpected attachments. Invoices, "voicemails" or "scanned documents" you weren't expecting — especially in odd file formats.
IF IT LOOKS SUSPICIOUS
What to do.
- Don't click, reply or open attachmentsDon't engage with the email at all — replying just confirms your address is live.
- Verify through a channel you trustIf it claims to be from a colleague, supplier or your bank, contact them on a number you already have — never the phone number or link in the email itself.
- Report itUse the Report → Report phishing button in Outlook, and tell your IT or security team so they can protect everyone else. In Australia you can also report scams to Scamwatch and cybercrime to ReportCyber.
- Delete itOnce reported, delete the email so no one opens it later by mistake.
If someone already clicked or entered a password: act fast. 1) Change that account's password immediately (and anywhere the same password was reused). 2) Tell your IT/security team now — speed limits the damage. 3) Confirm MFA is on, and ask IT to check your mailbox for sneaky forwarding rules attackers add to hide their tracks. 4) If bank details or money were involved, phone your bank straight away and report it to ReportCyber. There's no shame in reporting quickly — a fast report is what stops a click becoming a breach.