How to Spot a Phishing Email Disguised as Your Bank

Phishing emails impersonating Australian banks rank among the most common scams reported to the ACCC's Scamwatch service, with thousands of incidents logged each month across Sydney, Melbourne, Brisbane and smaller regional centres. The messages arrive looking remarkably like genuine correspondence from institutions such as Commonwealth Bank, Westpac, ANZ, NAB, Macquarie or Bendigo Bank, complete with logos, official-sounding language and familiar reference numbers. For many people juggling work, family and a side hustle, a quick glance at an inbox is all it takes for a fraudulent message to slip through.

These scams work because they exploit everyday trust. Australians receive legitimate bank communications constantly: statements, fraud alerts, verification prompts and marketing offers. Fraudsters mimic the tone, layout and small details that usually signal authenticity. When a message demands immediate action or threatens to lock an account, rational thinking gets bypassed and the recipient clicks before considering the consequences.

Learning to recognise the patterns that separate a real bank email from a fake one protects savings, credit scores and personal identity. The rest of this guide walks through the signals worth checking, the questions worth asking, and the habits that keep your information out of criminal hands.

The sender's address is the first thing to check

Every email header contains a sender address, and this is where most phishing attempts reveal themselves. A genuine message from a major Australian bank will come from a domain matching its official website, such as @commbank.com.au, @westpac.com.au or @anz.com.au. Anything else deserves suspicion. Common tricks include substituting letters, adding extra words or switching to a free email provider. A message claiming to be from NAB but sent from a @gmail.com address is an immediate red flag, no matter how professional the content looks.

Sometimes the deception is subtler. Fraudsters register domains that look almost identical to the real thing, swapping a lowercase "l" for the number "1" or inserting a hyphen. An address like @nab-bank.com looks plausible at a glance, especially on a phone screen. Always tap or click the sender name to reveal the full underlying address rather than trusting the display label. On mobile devices, the header is often hidden by default; iPhone and Android mail apps show only the friendly sender name. Long-pressing to view the full details catches most impersonation attempts before they can do harm.

Manufactured urgency is a classic pressure tactic

Australian banks rarely demand instant action over email. When a message insists an account will be suspended within hours, that a transaction is pending approval right now, or that verification must be completed before midnight, the alarm bells should ring loudly. Scammers rely on urgency because it short-circuits careful thinking. A person who would normally pause will instead click the link and enter their details before realising what has happened.

Genuine fraud detection systems from Australian banks typically block suspicious transactions automatically and contact customers through verified channels, such as the official mobile app or a phone call to the number on file. An email asking the recipient to log in via a link to verify or cancel a transaction is following a script written by criminals. Banks do not need customers to "confirm" details through an embedded button; their systems handle verification directly. Any email that pushes for a click instead is almost certainly a forgery, regardless of how polished the wording appears.

Inspecting links before clicking is non-negotiable

Every hyperlink in a phishing email is a potential trap. On desktop, hovering the mouse cursor over a link reveals the destination URL in the bottom corner of the browser or email client. On mobile, pressing and holding the link does the same thing. The destination should match the bank's real domain. A link claiming to lead to Westpac's login page but pointing to a random string of characters, an unfamiliar country code, or a misspelled web address is the clearest possible sign of fraud.

Shortened URLs, which condense long addresses into short strings, are a particular favourite of scammers because they hide the destination until after the click. Banks do not normally send shortened links in their official communications. Even where the visible text of a link reads as "www.yourbank.com.au", the underlying URL can point somewhere entirely different. Always trust the preview over the text. Typing the bank's web address directly into the browser, rather than following a link in an email, remains the most reliable way to reach the genuine login page and avoid handing credentials to criminals.

Branding flaws and visual inconsistencies give the game away

Professional phishing kits have improved, but small errors still slip through. Spelling mistakes, awkward grammar, mismatched fonts, low-resolution logos and odd spacing are all signs an email is not the polished production it pretends to be. Australian banks invest heavily in their brand presentation, and any deviation from their usual style stands out once you know what to look for. Comparing a suspicious message against an old statement or a genuine past alert is often enough to reveal the difference.

Pay attention to the greeting. Real bank communications typically address customers by their full name or the name on the account, not by generic terms like "Dear Customer" or "Dear Valued User". Mass phishing campaigns cannot personalise each message because they do not actually hold the recipient's details. A vague greeting suggests the sender is casting a wide net rather than responding to a specific account issue. The footer is another area where fraudsters cut corners: legitimate bank messages include detailed legal disclosures, an Australian Business Number (ABN), a physical address, links to privacy policies, and unsubscribe options that comply with the Spam Act 2003.

Requests banks never make over email

No Australian bank will ever ask a customer to send their full password, their CVV number from the back of a card, their internet banking PIN, or a one-time code received via SMS. These details are the keys to the kingdom, and no legitimate employee needs them. If an email asks for any of this information, it is fraudulent by definition, regardless of how convincing the rest appears.

Some phishing emails direct recipients to call a phone number that looks Australian but routes to an overseas call centre. Before dialling, cross-reference the number with the one printed on the back of a debit card or listed on the bank's official website. Even then, it is safer to hang up and call the bank directly using the number on a recent statement. Other scams involve attachments disguised as account statements or verification forms, which often contain malware designed to harvest credentials. Banks increasingly deliver statements through secure in-app portals rather than email attachments, so opening an unexpected file is a risk rarely worth taking.

Steps to take when something feels off

When an email triggers doubt, the safest response is to avoid interacting with it entirely. Do not click links, download attachments or reply. Instead, open a new browser window, type the bank's web address directly, and log in to check whether any action is genuinely required. Most banks have dedicated email addresses for reporting phishing, such as hoax@nab.com.au or spoof@westpac.com.au, which forward suspicious messages to their security teams for analysis.

Reporting the email helps protect other Australians, because banks and agencies like the Australian Cyber Security Centre use these reports to identify patterns and disrupt scam networks. The ACSC's ReportCyber portal accepts online reports of cybercrime, while Scamwatch at the ACCC collects data on scams of all kinds. If information has already been entered on a phishing site, the response must be immediate: change the internet banking password from a clean device, call the bank's official fraud line to freeze or monitor the account, and review recent transactions. Under the Notifiable Data Breaches scheme in the Privacy Act 1988, Australian organisations must notify affected individuals when personal information is likely to be accessed without authorisation, but acting quickly limits the practical damage regardless.

Building habits that keep your money safe

Phishing awareness is most effective when it becomes routine rather than reactive. Checking sender domains before opening attachments, hovering over links before clicking, and verifying unusual requests through a separate channel are all second nature once practised. Over time, these habits take only a few seconds and prevent the kind of mistakes that lead to lengthy recovery processes and stressful calls to fraud departments.

Multifactor authentication adds another layer of protection. Even if a phishing email captures a password, a one-time code sent to a phone or generated by an authenticator app keeps the account locked. Major Australian banks now offer app-based approvals, push notifications and biometric verification that make traditional password theft far less effective. Pairing these features with up-to-date software across phones, tablets and computers closes many of the vulnerabilities phishing emails try to exploit. Operating system updates, browser patches and current antivirus software reduce the impact of malicious attachments and compromised websites.

Everyday habits that reduce your risk

Banking safely in Australia today means treating every unexpected email as a question rather than an instruction. The discipline of pausing, checking and verifying takes only seconds, yet it stops almost every phishing attempt in its tracks. For readers who want to broaden their understanding of how to choose a secure banking setup that fits their personal circumstances, the resources collected through this site offer practical guidance drawn from real consumer experience. Start by applying the checks above to your own inbox today, and pass them on to family members who might be less confident with email; one shared tip can prevent a great deal of financial harm.