Skip to content

Typology · 1 alert

Phishing & Impersonation fraud

Cloned bank, courier, and government portals, plus callers claiming to be your own fraud department.

Published alerts
1
Reported exposure
$38,600
Reporting parties
22

The mechanics

How phishing and impersonation operations are run

The message arrives with a deadline: a parcel held for a small customs fee, a subscription auto-renewing tonight, a suspicious login that needs confirming. The link resolves to a near-identical copy of a real login page on a lookalike domain, and the page harvests credentials and the one-time code in real time while a person waits on the other side to use them. Where a call is involved, the caller already knows enough about you to sound legitimate and will ask you to move money to a 'safe account' they control.

Checks that break it

  1. 01Never follow a link in the message; open the organisation's app or type the address you already know.
  2. 02No bank, tax office, or courier will ever ask for a one-time code, and no real fraud team moves your money for you.
  3. 03Read the domain from right to left before the slash; lookalike prefixes are the whole trick.

Loading alerts…