Scam Alert: Scammers impersonating ASIC in email spear phishing scam

Key points

  • ASIC is warning financial service businesses to be alert to email spear phishing scams impersonating ASIC.
  • Scammers may try to build trust by impersonating an ASIC employee and starting a general conversation.
  • The email address the scammers use may look like genuine ASIC email addresses.
  • Businesses should take care to verify that contact from ASIC is legitimate. ASIC will always send communication from an email address ending in @asic.gov.au.

ASIC is warning the financial services industry to be alert to email spear phishing scams after receiving multiple reports of scammers targeting personnel of market operators and financial businesses by impersonating ASIC staff.

Scammers are using email addresses that look like genuine ASIC email addresses. They may do this by changing their sender display name or using technology to make it appear as though the email has been sent from a legitimate ASIC address – a technique known as spoofing.

ASIC will always send communication from an email address ending in @asic.gov.au.

Anyone who receives an email claiming to be from ASIC should check that the email address itself ends in @asic.gov.au, not just the display name, and make sure that you see the entire ‘from’ field. 

What are phishing and spear phishing scams?

Phishing scams attempt to deceive people into sharing personal information such as login details or sensitive business information. Scammers may send emails that direct you to provide your information or may send links to fake websites or attachments that install malware onto your computer.

Spear phishing is a targeted phishing scam that uses personalised communications to deceive recipients. Scammers may target employees to gain confidential business information or access to business systems.

Scammers may impersonate work colleagues, government employees or other agencies and start a general conversation to build trust. The email addresses may look similar to a legitimate business email address.

Because spear phishing emails are personalised, they can be highly convincing. AI and other technologies are making it easier for scammers to personalise scams at scale.

Scammers have been impersonating ASIC through fake emails, calls, text messages, websites and documents. Go to our webpage with recent alerts and further information to help you protect yourself from these scams.

What to look out for

Look out for emails that:

  • Use ASIC’s branding but originate from an unfamiliar email address or domain.
  • Contain generic subject lines, such as ‘violation notice’.
  • Contain questions or requests with limited context, such as an email starting with ‘Would you mind letting me know if you received my previous email?’
  • Create a sense of urgency or encourage a quick response by using phrases such as ‘Action Required’ and ‘Code Violation Notice’.
  • Contain links to websites asking you to log in using company credentials or upload sensitive documents.
  • Ask you to click on links, including links to ‘secure document folders.’ These links may contain malware.
  • Appear to forward or respond to previous emails that you don’t recall and cannot independently verify – any email content can be edited by the sender to make a phishing email look more legitimate.

Tips to protect yourself

Stop:

If an email doesn’t feel right – stop. Do not click on, engage with the email or click on any links or attachments unless you confirm that it’s legitimate.

Check:

Verify that the contact from ASIC is legitimate. ASIC will always send communication from an email address ending in @asic.gov.au. Take care that the email address itself ends in @asic.gov.au – not just the display name. You can call ASIC on 1300 935 075 or send us an online inquiry and ask for the communication to be verified. Financial services licensees can also reach out to their usual ASIC contacts to verify the correspondence.

Protect:

Help others by reporting scams to Scamwatch. For scams impersonating ASIC, also report these to ASIC directly. If you received the email at your business email address, follow your employer’s guidance for reporting phishing emails or contact your employer’s IT as others in your organisation may have also been targeted.

 

ASIC is Australia’s corporate, markets and financial services regulator.