A SMALL PAUSE. A BETTER CHECK.
Familiar email.
Unfamiliar request.
Look past the logo. These examples show where a message’s story and its evidence stop matching.
The supplier and the manager
share the same strange address.
A supplier chases an invoice. An apparent manager approves it. Look across the conversation: the address receiving the supplier reply also appears behind the manager’s name.
The habit: expand the sender and recipient addresses. Compare each person’s role across the whole thread.
An anonymised reconstruction of a reviewed submission. Names, addresses, amounts and references are fictional. The original message and attachments are not published.
Hello Alex, please send the invoice.
A · accounts-review [at] mail.example
Invoice approved. Please prioritise payment.
See the attachment clues
Riverstone Services Pty Ltd
Invoice 6421 · Total $12,480
Payee: B · Taylor Reed
Remittance: C · payments [at] other-company.example
B The payee differs from the issuer. A trustee or trading-name explanation needs independent confirmation; it does not prove account ownership.
C Compare the sender, supplier website and remittance address. Different identities matter more when combined with a questionable approval trail.
A valid ABN or correctly calculated total can be copied onto a false invoice. Neither authenticates the payment request.
What else should I notice?
Fictional teaching examples. Expand any message to reveal the clue.
01A link wearing a familiar nameCredential phishing+
Destination: document-access[.]example
The visible label claims SharePoint; the destination tells a different story. Preview the link without opening it. On touch devices, use the link preview or ask IT.
Open the service from your usual app or bookmark.
02A new bank account, same invoicePayment diversion+
A genuine supplier’s mailbox can be compromised. Correct names, past invoices and a familiar domain do not verify new payment instructions.
Call the supplier on a number already in your records.
03A QR code that changes the taskQR phishing+
The concern is the unexpected credential request and destination, not the presence of a QR code. A QR code can hide the same kind of link as an email button.
Check the decoded destination before continuing; verify an unexpected sign-in.
04Your manager asks for secrecyExecutive impersonation+
The unfamiliar address, unusual purchase and attempt to prevent verification reinforce each other. The display name alone identifies nobody.
Contact the manager through your normal company channel.
05A trusted host leads somewhere elseDocument and link chains+
A genuine document-sharing platform can host a misleading file. Recheck the destination when the document asks you to move to another site.
A trusted first page does not authenticate the next page.
06A reply chain that asks you to trust itFabricated conversation+
Quoted messages can be edited. Compare addresses, participants, chronology and the actual approval record. “Re:” and missing signatures alone do not prove forgery.
Find the original approval in your own records or verify it separately.