Phishing aimed at store owners doesn't look like a suspicious stranger — it looks like your hosting company, your payment processor, and your domain registrar, arriving on a busy afternoon with a deadline attached. These seven patterns account for most of what lands in a store owner's inbox.
1. The hosting suspension notice
Your account will be suspended in 24 hours — click to verify billing. The logo is right, the urgency is manufactured, and the link leads to a login page that isn't your host's. Tell: real hosts reference your actual account details and domain; verify by typing your host's address yourself, never through the email.
2. The payment processor limitation
A fake Stripe or PayPal alert claims your account is limited and settlements are on hold until you confirm your identity. Because held payouts are terrifying, people click fast. Tell: check the sender's actual domain and log in directly — real limitations always appear inside your dashboard.
3. The domain renewal invoice
An official-looking renewal notice for your own domain — from a registrar you've never used. Pay it and you've either lost money or begun transferring the domain away. Tell: you only ever owe renewal fees to the registrar where the domain actually lives.
4. The chargeback notification
A dispute has been filed — see attached report. The attachment carries malware or the link harvests your processor login. Tell: legitimate dispute notices appear in your processor dashboard, and real ones never arrive as .zip or .html attachments.
5. The supplier invoice with new bank details
A vendor you genuinely work with emails that their banking information has changed — except the email is from a spoofed or compromised account, and the new account belongs to the fraudster. Tell: confirm any banking change by phone, using a number you already had on file.
6. The trademark or copyright complaint
A law firm claims an image on your site infringes copyright; the evidence is in the attachment. Fear of legal trouble does the clicking. Tell: real legal notices identify the specific work and arrive through channels you can verify independently.
7. The unusual login alert
A cloned security warning for your own store admin — someone signed in from a new device, secure your account now. The panic-click delivers your real credentials to the attacker. Tell: go to your admin login directly and check the activity log yourself.
Phishing is how attackers get the keys; what they do next happens on your website. Trust Guard's daily scanning and monitoring catch the malware and unauthorized changes that follow a stolen password, so one bad click doesn't get to become a quiet takeover.
Comments
No comments yet. Be the first to share your thoughts!