MailGuard has intercepted a new wave of an Energy Australia refund scam, and this variant is more convincing than the ones we've flagged before. The scammers have added a domain-spoofing trick to the sender address and extended the phishing flow to harvest a fuller set of personal and financial details, including a one-time SMS code.
How the Scam Works
The subject line is consistent across the campaign: "Refund Due to Overcharge on Yearly Consumption." The promised refund amount is also identical in every email we've seen: $AU278.00. Consistency like this tells us the campaign is being run at scale, with the sender address customised per target while the lure itself stays the same.

Example phishing content shown using Energy Australia branding. Not affiliated with Energy Australia.
A spoofed sender address built from the recipient's own domain
This is the detail that makes this variant worth paying close attention to. Rather than using a generic lookalike sender, the scammers construct the display name and sending address using the target organisation's own domain name, appended with "security.account."
In the example intercepted by MailGuard, sent to a staff member at Mind Medicine Australia, the addresses appeared as:
-
Display address: "Energy Australia mindmedicineaustralia(dot)orgsecurity.account"(at)inbox(dot)net
-
Sending address: mindmedicineaustralia(dot)orgsecurity.account(at)inbox(dot)net
At a glance, seeing your own organisation's domain sitting inside the sender name can lend the email a false sense of legitimacy, especially to a recipient scanning quickly on a mobile device. It's a simple technique, but an effective one, and a reminder that the presence of a familiar domain string in a sender address is not proof of authenticity.
Inside the phishing flow
Clicking through from the email leads to a fake Energy Australia site hosted at goldtunes[.]de, a domain with no connection to Energy Australia, that closely mirrors the real brand's colours and layout. Unlike simpler scams that ask for one or two details, this flow is built to extract a complete identity and payment profile across several pages.
Step 1: Email and full name capture. The landing page claims the recipient is "ineligible for a refund" unless it is redeemed through the site, prompting them to enter their email address and full name to proceed.
Example phishing content shown using Energy Australia branding. Not affiliated with Energy Australia.
Step 2: Billing information. The next page requests the name on the card, address, city, state, zip code, mobile number and date of birth, under the banner "Billing Information."
Example phishing content shown using Energy Australia branding. Not affiliated with Energy Australia.
Step 3: Payment card details. The "Payout method" page then asks for a full card number, expiry date and CVV, reassuring the visitor that "all information provided will be kept confidential."
Example phishing content shown using Energy Australia branding. Not affiliated with Energy Australia.
Step 4: One-time SMS code. Finally, the site asks for a one-time security code sent to the victim's phone. This is the step designed to defeat card verification and authorise a fraudulent transaction using the details already captured.
Example phishing content shown using Energy Australia branding. Not affiliated with Energy Australia.
Notably, when MailGuard's analysts tested this step with fake data, the page returned an "invalid code" error and prompted a second attempt.
On the second attempt, the page redirected away from goldtunes[.]de and through to the legitimate Energy Australia website. This is a deliberate piece of misdirection. A victim who reaches the real Energy Australia site after "completing" the process is far less likely to suspect anything was wrong, even though their card details and personal information have already been harvested in the steps before it.
Why this campaign is convincing
This campaign combines two techniques that raise the risk for organisations specifically, rather than individual consumers:
- Domain-personalised sender addresses make the email feel more relevant and trustworthy to a workplace inbox than a generic phishing blast.
- A multi-stage data harvest captures enough information (identity, address, card details and a live OTP) to enable direct financial fraud, not just credential theft.
- A "soft landing" redirect to the genuine Energy Australia site reduces the chance the victim reports the incident, giving the scammers a longer window to act on the stolen data.
Energy providers remain a favoured lure because almost every household and business has a relationship with one, and refund or billing-related emails don't tend to raise the same suspicion as, say, an unexpected invoice.
Stay Safe, Know the Signs
MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.
Avoid emails that:
- Aren’t addressed to you personally.
- Are unexpected and urge immediate action.
- Contain poor grammar or miss crucial identifying details.
- Direct you to a suspicious URL that isn’t associated with the genuine company.
Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.
One Email Is All That It Takes
All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.
For a few dollars per staff member per month, you can protect your business with MailGuard's specialist AI-powered, zero-day email security. Special Ops for when speed matters! Our real-time zero-day, email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.
Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.




