News

Spot The Scam Quiz


Cybersecurity awareness

Spot the Scam: can your team pick the fakes?

Five emails. Four are real attack patterns landing in Australian inboxes. One is completely legitimate. Read each one, decide, then check the answer.

Comstel ICT · Cybersecurity · August 2026

The average business email compromise attempt doesn’t look like a scam. It looks like your CEO asking a favour, or a supplier chasing an invoice — and it arrives on a Tuesday afternoon when everyone is busy.

Here are five. Work through them with your team and see how they go.

1. Accounts — Bunnings Trade

“Our records show invoice INV-88214 remains unpaid. Please remit within 48 hours to avoid suspension of your trade account.”

Scam. The domain is a hyphenated lookalike, not the real one. Genuine suppliers also don’t threaten suspension over a single invoice you’ve never seen. Never pay from a link — open your own accounting system and check.

2. Microsoft 365 Message Center

“Service advisory: Exchange Online will undergo scheduled maintenance. No action is required.”

Legitimate. Correct domain, no urgency, no link to click, and it asks you to do nothing at all. Notice how boring it is — that’s usually a good sign.

3. Sarah Mitchell (CEO)

“I’m stuck in back-to-back meetings and can’t take calls. I need you to arrange a payment for a supplier — can you handle it discreetly? Send me your mobile.”

Scam. Textbook business email compromise: a personal address for a work request, manufactured urgency, an excuse for why they can’t be phoned, and a request for secrecy. Any one is a red flag; all four together is an attack.

4. Australia Post

“We attempted delivery but no one was available. Confirm your address and pay the $2.95 redelivery fee within 24 hours or your parcel will be returned.”

Scam. The tiny fee is the trick — it feels too trivial to verify, and the real prize is your card details. Australia Post doesn’t charge redelivery fees by email. Deadlines measured in hours are almost always an attack.

5. IT Support

“Your network password expires in 4 hours. Click here to keep your current password and avoid being locked out.”

Scam — and the hardest one. The domain looks right because sender addresses can be forged. The giveaway is the offer to keep your existing password, which no password system has ever needed you to do. Real expiry notices come from your device, not your inbox.

The pattern worth teaching

Urgency, secrecy, and a payment or password request. Almost every attack uses at least two of the three.

If number five caught you out, you’re in very good company. Sender addresses are trivial to forge, and that’s precisely why training alone can’t be the whole defence.

Awareness is the first layer, not the only one

People will click. They’re busy, the fakes are good, and attackers only need to be lucky once. The businesses that don’t lose money have something underneath the training: filtering that stops most of it arriving, endpoint protection that catches what does, and monitoring that spots a compromised account before it’s used.

That’s what Comstel deploys and manages with Bitdefender GravityZone — prevention, detection and response, watched by a team rather than left to a dashboard nobody opens.

Find out what’s actually getting through

A Comstel security assessment reviews your email filtering, endpoint protection and exposure, then tells you plainly where the gaps are.

Book a free consultation

Get in touch

Tell us what you need and we’ll get back to you — usually the same business day.

By submitting, you agree to Comstel’s Privacy Policy.

Enquiry received

A real Australian-based specialist will be in touch the same business day.