MailGuard is detecting and blocking a phishing campaign designed to pressure recipients into “renewing” a domain or hosting service, then harvesting credit card details, and attempting to capture additional verification codes and a card PIN. The email presents as an urgent service notice from “Domain Services”, warning that web hosting has expired and claiming the recipient must act immediately to avoid downtime, data loss, or reputational damage. The call to action directs users to a fraudulent payment journey that imitates a legitimate billing experience, but is hosted on an unrelated domain.
In the example intercepted by MailGuard’s filter network, the message:
This campaign is straightforward, and effective, because it borrows a familiar business fear, service interruption, and turns it into a payment trap.
Step1, the lure:
The email claims a hosting or domain service has expired and frames the consequence as urgent and costly, downtime, data loss, brand impact. The aim is to rush a decision before the recipient verifies the sender or checks their actual domain registrar.
Step2, credit card capture:
Clicking through takes the victim to a page titled “Complete Your Purchase”, requesting credit card details. The page includes an order summary and a “Submit Purchase” action, which can create a false sense of legitimacy.
Step3, code capture:
After card details are entered, the next screen requests a code received via SMS or prompts the user to confirm a transaction in their banking app. This mirrors real card verification flows, and may be used to authorise an attempted charge.
Step 4, PIN capture attempt:
In the observed sequence, the flow then attempts to capture a card PIN. This isa major red flag, reputable online merchants do not ask for your card PIN via a web form. MailGuard’s team did not proceed past this step.
Even when a phishing email looks polished, the underlying signals often give it away:
If a staff member has interacted with this scam, move quickly, and treat it as a potential financial fraud incident:
This campaign is a reminder that phishing does not need to be technically complex to succeed. A credible business scenario, a realistic-looking payment page, and a well-timed sense of urgency can bypass even experienced users, especially when the request feels operational rather than suspicious.
MailGuard continues to monitor threats like this across its filter network and will publish updates as the campaign evolves.
Share these practical indicators with teams:
MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.
Avoid emails that:
Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.
All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.
For a few dollars per staff member per month, you can protect your business with MailGuard's specialist AI-powered, zero-day email security. Special Ops for when speed matters! Our real-time zero-day, email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.
Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.