All Guides
Email Security

How to Spot a Scam Email

A practical, step-by-step walkthrough using a real ASIC business name renewal scam. Learn how to verify senders, inspect links without clicking, recognise redirect traps, and know exactly what to do if you or a staff member clicks.

Last reviewed September 202612 min read

The ASIC Business Name Renewal Scam

A business owner registers a business name through ASIC. Weeks later, an email arrives that looks identical to a genuine ASIC renewal notice. Same blue header, same ASIC logo, same layout, same wording. The subject line references a business name renewal. Everything about it looks legitimate at a glance.

The owner has two registered business names, so the timing feels right. The natural instinct is to click and pay. This is exactly the scenario scammers exploit: they align their fake email with a real administrative event the target is expecting.

The key lesson

Scammers do not need to hack your email. They just need to send something you are already expecting. The more routine and administrative the email appears, the more dangerous it is.

This particular scam is well documented on the ASIC website. The attackers register lookalike domains, copy the ASIC email template, and send to business owners around renewal time. The goal is not always immediate payment. Often the payment link redirects to the real ASIC site to build trust, while a separate link downloads malware disguised as a renewal notice.

Step 1: Verify the Sender Address

Before clicking any link or opening any attachment, look at who the email is actually from. Not the display name, the actual email address. In most email clients you can click or tap the sender name to reveal the full address.

Legitimate

no.reply@asic.gov.au

Domain matches the organisation exactly

Scam

asic.transaction.no-reply@asicsaustralia.biz

Lookalike domain, not the real asic.gov.au

In this scam, the sender address attempted to look official: asic.transaction.no-reply@asicsaustralia.biz. To an untrained eye, that reads like ASIC. But the domain is asicsaustralia.biz, not asic.gov.au. Anyone can register a lookalike domain for a few dollars.

Display name can be anything. The domain after the @ symbol is what matters.
Lookalike domains use tricks like adding an extra letter (asics instead of asic), a different TLD (.biz, .net, .com instead of .gov.au), or a hyphen.
Government agencies in Australia use .gov.au domains. Any government email from .biz, .com, or .net is a scam.
Check the reply-to address too. Some scams send from one address but set a different reply-to.

Step 2: Hover Before You Click

Links in emails can display one address but send you somewhere completely different. Never click a link blindly. Preview it first.

On a Mac (Mail app)

Hover to the right of any link and click the down arrow to use Quick Look. This previews the web page without managing to it. You can also hover over the link to see the destination URL in a tooltip.

On iPhone or iPad

Long-press (hold your finger) on the link. A preview sheet appears showing the destination URL at the top. This does not navigate to the page.

On Windows (Outlook)

Hover over the link. The destination URL appears in a small tooltip near your cursor. Right-click and select Copy Hyperlink to paste it into a browser address bar for inspection without managing.

In this scam

The Pay Now button previewed as an authentic-looking ASIC page. But the URL shown at the top of the preview was not asic.gov.au. It was a scam domain. The preview looked real because the attackers copied the ASIC website design. The visual quality is irrelevant. The domain in the address bar is the only thing that matters.

Step 3: Watch for the Redirect Trap

A common and sophisticated trick: the primary link (like a Pay Now button) actually redirects to the real organisation's website. This builds trust. It makes you think the email is legitimate because clicking the button took you to the real ASIC page.

The scammer does this deliberately. They know that once you trust the email, you are far more likely to click the second link, the one that matters. In this ASIC scam, the Pay Now link redirected through eoaclk.com before landing on the real ASIC website. But the renewal notice link further down would have downloaded a ZIP file containing malware or ransomware.

How the redirect trap works

  1. Suspicious link (Pay Now) redirects to the real ASIC site
  2. You see the real ASIC page and think the email is genuine
  3. You click the second link (Renewal Notice / Download)
  4. Malware, ransomware, or credential-harvesting page loads

Treat every link in a suspicious email as independent. The fact that one link goes somewhere safe does not mean the others do. Verify each one.

What Would Have Happened If You Clicked

In this scam, the renewal notice link would have downloaded a ZIP file. Opening that file on an unprotected computer could have installed any of the following:

Ransomware

Encrypts your files and demands payment. Can take down an entire business network in hours. Australian businesses lose millions to ransomware each year.

Info-stealing malware

Silently harvests saved passwords, browser cookies, and session tokens from the device. Sent back to the attacker for account takeover.

Remote access trojan (RAT)

Gives the attacker persistent control of the device. They can install more malware, access files, and use the machine to attack others on your network.

Credential harvester

Displays a fake login page to capture your ASIC, bank, or email credentials, then forwards them to the attacker.

On a properly managed business device with EDR (endpoint detection and response), most of these would be blocked or quarantined automatically. On an unmanaged personal device, the outcome depends entirely on whether the antivirus happens to recognise the specific malware.

Common Australian Impersonation Scams

Scammers impersonate trusted Australian organisations because recognition drives clicks. Here are the most common impersonations targeting Australian businesses and individuals:

ASIC

Business name renewal scams. Sends fake renewal notices with lookalike domains. Often pairs a real redirect with a malicious download link.

ATO (Australian Tax Office)

Fake tax refunds, outstanding debt threats, or GST refund claims. Urgent language and links to credential-harvesting login pages.

Australia Post

Parcel delivery scams. Asks for a small redelivery fee to capture card details. Extremely common during shopping seasons.

MyGov / Services Australia

Fake Medicare or Centrelink messages. Claims your account is suspended or a payment is waiting. Links to fake MyGov login pages.

NBN Co

Fake NBN disconnection or upgrade notices. Often paired with phone calls claiming to be from NBN technical support.

Health funds (Bupa, Medibank)

Fake refund or membership renewal emails. Exploits the trust in health fund branding and timing around policy reviews.

The pattern is always the same

  • Impersonates a trusted, recognisable Australian organisation
  • Creates urgency or references an expected administrative event
  • Uses a lookalike domain or spoofed display name
  • Asks you to click a link, open an attachment, or enter credentials
  • The real organisation will never ask you to do these things via an email link

Red Flag Checklist

Work through this checklist on any email that asks you to click, pay, or log in. If you tick even one box, treat the email as suspicious until verified.

Sender domain does not match the organisation (asic.gov.au vs asicsaustralia.biz)
Generic greeting (Dear Customer, Hello) instead of your name or business name
Creates urgency or fear (account suspended, overdue, act now)
No mention of your specific details that a real sender would know
Links display one URL but hover preview shows a different domain
Unexpected attachment, especially ZIP, HTML, ISO, or macro-enabled Office files
Reply-to address is different from the sender address
First-time sender from an external domain
Request to change bank details or make a payment
Spelling or grammar errors that a professional organisation would not make
Email arrives at a time that aligns with a real administrative event
The email references an account or service you have, but the details are vague

If You Already Clicked

If you or a staff member has already clicked a link or opened an attachment from a suspicious email, act fast. The first hour matters most.

1

Disconnect from the internet

Turn off Wi-Fi or unplug the network cable immediately. This stops any active malware communicating with the attacker and prevents lateral movement across your network.

2

Do not turn off the device

Leave it powered on. Shutting down can destroy evidence in memory and trigger anti-forensic behaviour in some malware. Disconnect the network instead.

3

Run a full security scan

If you have EDR or antivirus, run a full scan immediately. If the device is a business machine, contact your IT team or MSP right away. They can isolate and investigate the device remotely.

4

Change passwords from a different device

Use a separate, known-clean device to change passwords for any accounts accessed from the affected machine. Start with email, banking, and any admin accounts.

5

Enable MFA if not already on

Turn on multi-factor authentication for every account that supports it. If MFA was already on and you entered a code, the attacker may have captured it. Contact your IT team.

6

Contact your bank if you entered payment details

If you entered card or bank details on a fake page, call your bank immediately. They can freeze the card and monitor for fraudulent transactions.

7

Report the scam

Report to Scamwatch (scamwatch.gov.au). For business email compromises, report to your IT team and consider reporting to ReportCyber (cyber.gov.au).

Defences for Your Business

Individual vigilance matters, but you cannot rely on every staff member catching every scam. Technical controls are the foundation. Training is the second layer.

Email authentication (DMARC, SPF, DKIM)

Stops attackers spoofing your domain. Also flags incoming emails from unauthenticated domains. The single most effective email security control.

Related guide

Advanced anti-phishing

Microsoft Defender for Office 365 or a dedicated gateway (Proofpoint) catches lookalike domains, impersonation, and malicious links before they reach the inbox.

EDR on every device

Endpoint detection and response (Huntress, CrowdStrike, Defender) blocks malware execution and provides rollback if ransomware is detected.

Safe Links / URL rewriting

Checks every clicked link in real time against threat intelligence. Blocks pages that were weaponised after the email was delivered.

External sender banners

A clear banner on every email from outside the organisation. Reduces the effectiveness of impersonation by making external origin visible.

Verification processes

Phone-verify any bank detail change. Dual approval for payments above a threshold. Never action payment changes from email alone.

The reporting culture principle

The single best indicator of security maturity is how fast staff report suspicious emails. Reward reports. Never punish clicks. If people are afraid of consequences, they hide incidents and the attacker stays inside your network undetected.

Frequently Asked Questions

How can I tell if an email from ASIC is real?

Legitimate ASIC correspondence comes from an asic.gov.au domain. Scam versions use lookalike domains like asicsaustralia.biz or asic-transaction.com. Always hover over links to check the destination, and never enter payment details without confirming through your ASIC Connect account directly.

What should I do if I clicked a link in a scam email?

Disconnect the device from the internet immediately. Run a full antivirus and EDR scan. Change passwords for any accounts accessed from that device. If you entered payment details, contact your bank straight away. Report the scam to Scamwatch and, for business emails, to your IT team.

Will antivirus catch malware from a phishing link?

It depends on the malware. Signature-based antivirus catches known threats, but zero-day and fileless malware can slip through. Business-grade EDR with behavioural detection (Huntress, CrowdStrike, Defender) provides far better protection than consumer antivirus.

Is it safe to preview a link without clicking?

On a Mac, the Mail Quick Look feature previews the page without executing scripts in most cases. On iPhone or iPad, long-pressing a link shows the URL without managing. Neither is completely risk-free on an unpatched device, but they are far safer than clicking through directly.

Why do scam emails look so authentic?

Attackers copy real email templates, logos, colours, and layouts from legitimate organisations. Some use stolen brand assets and professional design tools. The visual quality is no longer a reliable indicator of authenticity. The sender address and link destinations are what matter.

Protect Your Team From Phishing

We deploy email authentication (DMARC, SPF, DKIM), managed EDR, phishing-resistant MFA, and run simulated phishing campaigns that build real awareness, not tick-box compliance.