It's Your Idea
Security

Ring your supplier before you pay the invoice

We put out a media release this morning, because a run of scam emails impersonating local web agencies has started landing in client inboxes across regional Victoria and New South Wales. The short version is below. The part that matters is one phone call.

What the emails look like

They come from a free Gmail account set up to look like a real business, using the owner's name, photo and logo. They tell the customer their website needs urgent compliance work before a deadline, warn that something will be shut down or restricted if it is not done, then offer packages priced between $600 and $1,200. The deadlines fall within days of the email being sent.

There is no such thing as WordPress compliance. Nobody can restrict your website because you did not buy a package. The deadline is invented. It is there to stop you picking up the phone, because the moment you ring your developer the whole thing falls over.

Your portfolio is also a customer list

Web and design agencies are being hit first because their customer lists are the easiest to collect. The same method works on any business that shows its past work online.

A builder has twenty finished homes on a page. A joiner has a gallery. A landscaper has before and after shots with the street under them. Photographers, cabinetmakers, sign writers, printers, mechanics — everyone does it, because it wins work. That gallery is also a list of people who have paid that business money. Add the Google reviews with names on them and the tagged photos on Facebook and the picture is fairly complete.

Nobody was hacked in any case we have seen. The lists were assembled from public pages, including the “site by” credits in website footers. We publish a portfolio ourselves, and it carries exactly the same exposure — that is rather the point. The answer is not to take your work offline. It is to make the phone call before money moves.

AI took the effort out of it

These used to be easy to pick. The English was wrong, the formatting was wrong, they quoted the wrong currency. That is gone. Someone can point a language model at a business website, have it read every page and the whole portfolio, write in the owner's tone of voice and produce a hundred different emails before lunch.

The models that run on a local machine are the problem: no account, no billing, nobody watching what they are used for, and the framework can be adjusted so it does not refuse. Effort was the thing that kept this kind of fraud rare. There is no effort left in it.

The same template has turned up in more than one part of the country. An agency in Newcastle reported the same emails reaching its own clients last week, with a different deadline and slightly different pricing, which points to one operation working through regional centres rather than something local.

One rule, and it costs nothing

No invoice gets paid and no bank details get changed without a phone call to a number you already had. Not a number in the email. The one in your phone, or on the invoice from last year.

It does not matter whether it is a website bill, a plumber, a feed order or your accountant. If money is about to move and an email is the only thing telling you where it goes, check it. Ten seconds on the phone beats a thousand dollars out the door and an awkward conversation with your bank.

What to look for

  • A Gmail, Outlook or Hotmail address instead of the business's own domain, usually with the business name worked into it so it reads right at a glance.
  • A deadline with nothing behind it. Restrictions, disruption, loss of status, and no authority named as imposing any of it.
  • Official sounding words that describe no actual work: compliance verification, CMS health, system verification, platform requirements.
  • A generic greeting, or an email sent to info@ or admin@ rather than to a person.
  • Three packages at three prices, set out to look like a real quote, all small enough to approve without thinking too hard.
  • Proof that turns out to be a normal setting on your own website, presented as a fault.
  • A request to pay before anyone has described the work in plain terms.

If one arrives

Do not reply and do not click anything. Ring the business it claims to be from, on a number you already hold. Report it to Scamwatch and to ReportCyber.

If you have already paid, call your bank straight away and ask for a scam recall. Treat any password or login sent to that address as gone.

Tell your own customers before it happens

The cheapest protection is a sentence your customers read while nothing is going wrong: this is the email address we use, and we will never demand urgent payment to a deadline. Send it now and it is sitting in their inbox when a convincing fake turns up.

If you are not sure whether something you have received is real, ring us on 0423 561 268. We would far rather check an email for you than help you chase a payment afterwards.

Not sure what's running on your site, or when it was last updated?

Get in touch →
← Back to all articles