MailGuard has intercepted a multi-stage phishing campaign impersonating Origin Energy and offering a fake $150 overpayment refund. The lure is simple, the flow is polished, and the goal is to harvest identity data, card details, and one-time SMS codes that enable account takeover and fraudulent payments. Our filters are blocking these emails for protected customers, and we're publishing indicators and screenshots here so security teams can brief staff and tune controls quickly.
Here's what it looks like:
Step 1: Spoofed email
A branded HTML email mimicking an authentic Origin Energy electricity bill advises the recipient of a refund and urges them to 'Verify Account' within 24 hours.
Step 2: Refund bait
The link opens a page carrying Origin Energy branding and a large 'Verify' button, hosted on a domain unrelated to Origin Energy.
Step 3: Personal data capture
A “Billing Address” form requests full name, date of birth, address, email and phone.
Step 4: Card data capture
Following that, a “Card Verification” form requests the victim's credit card number, expiry and CVV.
Step 5: One-time code harvest
A “Phone Verification” page then captures an SMS code, enabling attackers to bypass 2FA protections and process fraudulent payments.
Step 6: False reassurance
Finally, a “Completed” page appears offering false reassurance to the victim is redirected to the legitimate Origin Energy website to reduce suspicion.
Here's an end-to-end view of the flow, in the process diagram below.
MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.
Avoid emails that:
Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.
All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.
For a few dollars per staff member per month, you can protect your business with MailGuard's specialist, 'zero zero-day' email security. Special Ops for when speed matters! Our real-time 'zero zero-day', email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.
Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.