Can scams come in from real, known businesses?

It’s not just unknown addresses. Companies you know and use in your day to day can be just as responsible for sending you threats you can fall for.

It’s not just unknown addresses. Companies you know and use in your day to day can be just as responsible for sending you threats you can fall for.

It happened rather out of the blue for a reader. In one moment, a company and service they had trusted turned out to be a sender of a scam and a purveyor of malware. And the service had no idea.

A stray email arrived offering a document to click on. A health services company, it could have been something useful, such as a new term or a change to the way payments were to be made.

It looked legitimate, complete with a company letterhead. There would be no reason for a scammer to fake this.

And yet the email read like a scam, and included malware that could have done harm.

What happened, and is this sort of thing normal?

malware-service-email-2026-01.jpg
This came in from a company, but it wasn’t quite legit. Something might throw you off.

Emails from the unknown and those you know

By now, you’re probably all too familiar with the idea that scams won’t stop for the one simple fact that they work.

Criminals make a fortune from just how much they do to trick us into clicking to fake websites, to downloading files that lock our data down, that steal passwords and finances, and in general look to make a mess of our lives.

Scams are a multi-billion dollar industry, and while there are definite ways to defend yourself — not the least of which includes security software, education, and simply thinking about what you’ve been sent rather than acting out of urgency — it can be all too easy to fall down the wrong email or link simply out of trust.

Trust can be a definite issue, in that we’ll trust businesses to not send scam messages our way, but clearly not what’s in the dreaded spam folder of our inboxes.

And yet that trust can backfire significantly, with businesses and services also under attack from scammers and criminals who want to use their services as a distribution system.

“One of the biggest misconceptions is that scams only come from unknown senders,” said Tyler McGee, Head of Asia Pacific and Japan at McAfee.

“In reality, some of the most successful phishing attacks leverage trusted business relationships and familiar brands to lower a recipient’s guard. Cybercriminals can hack business email accounts, impersonate organisations, or use lookalike domains and fake document-sharing notifications that closely resemble trusted services,” he said.

“For consumers, this means that an email appearing to come from a healthcare provider, retailer, bank, or other legitimate organisation should not automatically be trusted.”

It means that the emails you get from trusted organisations and services you normally liaise with and automatically read with certainty can’t always be trusted in quite that same way, and you may need to keep your wits about you as if the email was from the unknown and dreaded spam folder.

malware-service-email-2026-03.jpg
The link tells us everything: this document supposedly at Microsoft wasn’t going to Microsoft at all. It’s a trick.

It’s just business

At the business end, services need to be aware of the risk scams and malware pose to them, and at least attempt to ensure their computers are less at risk.

While that will usually mean ensuring security software exists and is kept updated — an issue not every business wants to know about due to the expected cost this brings — it also means making sure workers in the business are trained and educated to deal with some of these threats.

However, the business knowledge goes deeper than merely being on guard. They also need to alert people about the issues, as well.

“Businesses should be taking appropriate steps to protect their systems and their customers, but security is only part of the responsibility. When an organisation knows its brand or communications are being used to deceive people, it’s also important to be transparent and alert customers so they know what to look out for,” McGee told Pickr.

“This is also a reminder that the days of simply trusting your intuition online are gone. Scammers can make messages look like they’re coming from organisations you already know and trust, so a familiar name or sender is no longer enough to tell you something is legitimate.”

“Consumers should pause, verify unexpected requests through a trusted channel, and use technology that can help identify threats that may otherwise look completely convincing,” he said.

Using a phone

How to stay on alert for scams, even if they’re official looking

It can be exhausting to always be on guard, and yet that is what many of us are doing. The internet is always changing, as is the nature of how criminals attempt to fleece us, and that’s because it works.

Scams work. Malware works. Criminals wouldn’t be doing any of this if it didn’t, but the simple reality is that people are falling victim to it all the time, with hundreds of millions lost to scams in Australia each year, a number which may not include the money lost to malware and other online security issues.

Frustratingly, we are all targets for criminals, and that can make simply checking your email a bit of a burden at times.

However, there are some tips you should always keep in mind, such as being cautious with urgency. Scammers and criminals love the idea of creating urgency, largely because it pushes our common sense to the side and forces us to take action without thinking.

Always verify the sender of an email at the sender address, and remember that scammers can’t simply use the address of a real company or website. They can use the logo or images, but the sender address isn’t something they can simply latch onto.

But businesses can also be accidentally caught up in a scam by falling for a security exploit on their end, which is why it’s important to wait for a second and think about what you’ve been sent.

Even in the case of an email from a business, suggesting a document needs to be seen immediately can raise red flags. If an email like this comes in, consider calling the company or service for verification, simply because clicking could land you in trouble, especially if they’re none the wiser.

Security software can also help in some situations, but may not be as relevant if you’re checking email or messages on your phone. If you’re truly in doubt, simply call the company you’ve received the email from, and not using the number on the email. That could have been manipulated.

Instead, simply do a search answer find the real company and website using your favourite search engine of choice. Scammers and criminals are unlikely to override the real company on search, and you’ll likely end up being able to talk to a real person who can tell you what’s going on.