Report a Phishing or Suspicious Email

Phishing emails try to get you to hand over your passphrase, approve a sign-in prompt, open a harmful file, or pay someone who is not who they say they are.

Reporting one takes a few seconds and protects everyone. You will never be criticised for reporting something that turns out to be legitimate. We would far rather look at a hundred harmless emails than miss one real attack.

What to look for

  • Unexpected urgency: Your account will be closed today. Action required immediately. Payment overdue.
  • A request for your passphrase, or a multifactor prompt you did not trigger.
  • A familiar name but an unfamiliar address: Check the full email address, not just the display name.
  • A request to change bank details or redirect a payment: Even if it appears to come from a supplier or a colleague.
  • Unexpected attachments or links: Hover over a link and check the address matches the text.
  • A tone that is slightly off: Odd greeting, unusual phrasing, a colleague who suddenly writes differently.
  • Pressure to keep it quiet, or to act outside the normal process.

Attacks aimed at councils often reference real things — a development application, a rates notice, a supplier invoice. Looking plausible is the point.

How to report it

  1. Forward the email to Help@kingborough.tas.gov.au with SUSPECTED PHISHING in the subject line.
  2. Once reported, delete it from your inbox. You do not need to warn colleagues yourself — we will do that if it is warranted, and a forwarded warning containing the original links creates its own risk.

If you think you have already clicked

Act now. Speed matters far more than being certain.

  1. Change your passphrase immediately, from a different device if you can.
  2. Call us on (03) 6211 8100. Phone, do not email — if your mailbox is compromised, email may not reach us, and we need to move quickly.
  3. Tell us exactly what happened. Whether you entered your passphrase, whether you approved a multifactor prompt, whether you opened an attachment. The multifactor detail matters most and changes what we do next.
  4. Do not delete the email. We need it to trace the attack and find who else was targeted.

You will not be in trouble. Phishing is built to catch competent people having a busy day, and the people who report fastest are the reason these attacks fail. Telling us in the first ten minutes is worth more than anything else you can do.

If you are not sure

Report it anyway by messaging us. That is the correct answer every time.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.