MailGuard Blog — Breaking alerts, news and updates on cybersecurity topics

Fake American Express “non‑compliance” phishing scam targets Australians

Written by MailGuard | 28 September 2026, 23:52:42 Z

 

A new phishing campaign is impersonating American Express, using a fabricated “non‑compliance lockout” notification to lure recipients into a multi‑step web flow designed to harvest Amex login credentials, card verification data, and personal information.

What the Scam Looks Like

The email itself is simple. Rather than a dramatic subject line, it arrives with the generic heading “Your Amex Card has been locked due to non‑compliance issues”, styled to look like a routine American Express service alert.

The body tells the recipient their card has been “temporarily locked due to unusual spending activity” and that “all card transactions and merchant payments are currently suspended pending identity and card‑usage verification.” A blue “Confirm your Identity” button invites them to resolve the issue.

The email includes American Express branding, familiar layout elements, and language about secure verification details that make it feel like a standard card‑security notice rather than a threat.

Example phishing content shown using American Express branding. Not affiliated with American Express. 

A rotating sender built to blend in

Behind the branding, the sender details tell a different story:

  • Display name: American Express | Non-Compliance Issues

  • Display address: DoNotReplyUS(at)online.net

  • Sending address: donotreplyus(at)online.net

None of these align with legitimate American Express infrastructure, but the email is styled convincingly enough that a busy staff member or cardholder could easily miss the mismatch.

Inside the phishing flow

Clicking “Confirm your Identity” leads to a phishing site that closely mimics the look and feel of the official American Express portal, including Amex logos, familiar colour schemes, and footer acknowledgements.

From there, the fake site walks visitors through a staged, escalating sequence of pages.

Step 1: Browser verification prompt

The next page is a “Confirm access” screen prompting the user to verify their browser session:

  • “Confirm access”
  • “Tap below to verify this browser session and continue”
  • A large “I’m ready” button

Example phishing content shown using American Express branding. . Not affiliated with American Express.

Step 2: Username and password 

The first page is a fake American Express login screen requesting:

  • User ID
  • Password

It closely mirrors the genuine Amex sign‑in experience, including navigation elements, footer links, and a “Remember Me” checkbox.

 

Example phishing content shown using American Express branding. . Not affiliated with American Express.

Step 3:  3‑digit CID 

 After “signing in,” the site moves to a “3‑Digit CID” page, instructing the user to enter the three numbers printed on the back of their card. A text box labelled “3‑Digit CID” and a “Verify” button are presented, along with an illustration showing where the CID is located. 

Example phishing content shown using American Express branding. Not affiliated with American Express.

Step 4:  Fake error page 

The flow ends on an error screen if fake details are entered, but by this point, attackers have already captured:

  • Amex login credentials
  • Card verification data (CID)
  • Browser/session metadata

MailGuard’s analysts observed that a genuine visitor may then be redirected to the legitimate American Express site, a deliberate piece of misdirection designed to leave the victim believing the process worked normally rather than realising their details have already been captured.

Example phishing content shown using American Express branding. Not affiliated with American Express.

Why this scam is worth flagging to your team

A few details make this campaign more dangerous than a typical credential‑phishing attempt:

  • It asks for everything in one visit. The flow captures Amex login credentials, card verification data, and browser/session confirmation. Together, that gives an attacker enough to attempt account takeover, card‑not‑present fraud, and further identity abuse in the same session.

  • The “non‑compliance lockout” pretext is mundane, not alarming. A temporary card lock due to “unusual spending activity” is a plausible, low‑drama scenario that doesn’t immediately trigger the same suspicion a “your account will be suspended” threat might.

  • The staged verification steps feel authentic. Multiple pages, CID prompts, and browser verification mimic the layered security experience users associate with financial institutions, making the process feel legitimate.

  • The redirect back to the real Amex site at the end is deliberate misdirection. Ending on a familiar confirmation message and then redirecting to the genuine portal is designed to leave the victim with a sense of normalcy, reducing the likelihood they will realise their details have been stolen and report the incident quickly.

  • For organisations whose staff use corporate cards for travel, procurement, or business expenses, this kind of scam has implications beyond individual loss. Compromised cardholder identities can be leveraged to access other systems, initiate fraudulent transactions, or bypass controls that rely on financial verification.

Stay Safe, Know the Signs

MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.

Avoid emails that:

  • Aren’t addressed to you personally.
  • Are unexpected and urge immediate action.
  • Contain poor grammar or miss crucial identifying details.
  • Direct you to a suspicious URL that isn’t associated with the genuine company.

Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.

One Email Is All That It Takes   

All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.     

For a few dollars per staff member per month, you can protect your business with MailGuard's specialist AI-powered, zero-day email security. Special Ops for when speed matters!  Our real-time zero-day, email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.  

Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.