A familiar name can lower your guard
A recent incident reported to our team is a useful reminder that phishing does not always look obviously suspicious.
In this case, a targeted email used a domain name that closely resembled a familiar business name. The subject line was formal and security-related, which could make a recipient feel that a quick response was expected.
This is a common spear-phishing tactic. Instead of sending a generic scam to thousands of people, the attacker makes the message feel connected to a real company, service provider, or customer relationship.
The legitimate business does not need to have its website or email system compromised for this to happen. An attacker can register a separate domain that looks convincing at a glance, then use it to send messages that borrow the trust associated with the real business.
Why lookalike domains work
The domain is the part of an email address after the @ symbol. Attackers may add or remove a character, change a spelling, include an extra word, or use a different domain ending. Those differences can be easy to miss when the display name and the rest of the message look familiar.
The email may be professionally written. It may refer to a genuine service, use a plausible employee name, or arrive at a time when the recipient is expecting an invoice, a project update, or an account notice.
That is what makes this type of attack effective. It relies on normal business habits: responding to suppliers, approving changes, and dealing with important requests promptly.
What the attacker may be trying to achieve
The details vary, but a spear-phishing message often tries to persuade someone to take an action before they have time to verify the request.
- Click a link and sign in to an account
- Open an attachment that appears to be a document or invoice
- Approve access to a Microsoft 365 application or account
- Change banking or payment information
- Redirect a payment to a fraudulent account
The message does not need to contain poor spelling or obvious warning signs to be fraudulent. A legitimate-looking sender name is not enough. The full email address and the request itself both need to make sense.
Check the full sender address
Before responding to an unexpected or important email, look beyond the name shown in your inbox. Open the sender details and read the full address, including the domain.
If the domain is unfamiliar, misspelled, or only slightly different from the one you expect, treat the message with caution. Do the same when an email creates urgency around a payment, banking change, account access, security approval, password, or sign-in link.
A message can be genuine and still deserve a check. The cost of pausing for a few minutes is small compared with the impact of a compromised account or misdirected payment.
Verify outside the email
Use a communication method you already trust. Call your usual contact using a number you have on file, or start a new email to an address you know is correct.
Do not use the phone number, link, or reply address provided in the suspicious message. Those details may lead back to the attacker. Do not click links or open attachments while you are trying to determine whether the message is legitimate.
For any banking or payment change, make independent verbal confirmation part of your process before money is sent. This is especially important for businesses that regularly deal with suppliers, subcontractors, and client payments by email.
Make verification a normal business habit
Phishing protection is not only a technical issue. It is also a business process issue. Staff need a clear, practical way to pause and verify requests that could affect accounts, access, or money.
Keep known contact details available. Make sure people understand that they will not be penalized for checking a request before acting on it. Review payment and account-change procedures regularly, particularly when responsibilities change or new staff join the team.
If you receive a suspicious message, preserve it, do not reply, and report it to your IT provider or the organisation being impersonated through a known contact channel.
If you are concerned about a suspicious message using your business name, contact ALPHA+V3 to discuss a practical next step.