Phishing is a fake email, text, or lookalike website built to steal a password, a card number, or a two-factor code. Attackers copy logos and write as if they are us, a bank, or a payment company. They want you to panic and click.
We will never ask you to send a password, a two-factor code, or a full card number by email. If you cannot sign in, start a portal password reset or open a support ticket. Do not reply to the message.
How we actually contact you
Real mail about your account:
- Uses the display name LochStudios
- Addresses you by name when we have it
- Points you at the portal, Billing, or a ticket you already opened
- For tickets, tells you to open the ticket in the portal. We do not read replies to those notifications.
We send invoices, payment receipts, password resets you asked for, new-device notices, service-ready mail, and ticket updates. A hosting-ready email does not include passwords or FTP logins. See Getting started after you order hosting.
People-facing addresses we publish are on @lochstudios.com (for example support@lochstudios.com). The public website is lochstudios.com.au. That .com.au site is not the mailbox we ask you to write to. Help is a ticket, not a reply.
If you are unsure a message is from us:
- Do not click the links in it.
- Sign in at the portal by typing that path yourself, or by using a bookmark you made.
- Check Billing for a real invoice, or open a support ticket.
Open cPanel and WebMail from the portal. On a hosting service click Log in to cPanel. On a LochStudios Mail service click Log in to WebMail. Do not use a hostname from an email.
Common phishing tactics
Attackers often use:
- Urgency. "Your account will be locked" or "Confirm this payment now."
- A generic greeting. "Dear Customer" or "Dear User" instead of your name.
- A lookalike link. The text says one site. The real destination is another.
- A request for secrets. Passwords, card numbers, PINs, or two-factor codes.
- A threat or a prize. "Act now or lose the service" or "Click to claim a refund."
- A mismatched sender. The display name says LochStudios. The address is something else.
Poor spelling is a clue. So is a polished message. Do not trust logos or colours alone.
We do send invoice reminders, including when a service is close to suspension. Those invoices are always in Billing. If the portal has no matching invoice, the email is not a bill from us.
How to check a message
Hover over links (do not click).
In most mail apps, rest the cursor on the link and read the address that appears. On a phone, touch and hold the link until the destination shows, then cancel.
Suspicious:
- The text says our site, but the destination is a different domain or an extra word (
lochstudios-secure.example,packages-lochstudios.net). - The destination is an IP address, a URL shortener, or a file download.
- The path looks like a login form you did not open yourself.
Read the sender's address, not only the name.
Anyone can set the display name to LochStudios. Look at the part after @. Extra words, a domain that only resembles ours, or an address that asks you to "verify" by return mail is a warning.
Ask what the message wants.
- Does it ask you to confirm a password, a card, a PIN, or a two-factor code?
- Does it create panic ("immediate action") for something you cannot see in the portal?
- Does it tell you to reply with account details?
- Does it tell you to open cPanel or WebMail at a hostname you have never used?
If any of those are true, treat it as phishing.
What to do if you receive a phishing email
- Do not click links or open attachments.
- Do not reply.
- Mark it as junk or phishing in the mail app so later copies are filed away.
- Delete it after you have marked it.
- Check the real account yourself. Type the site or open the portal. Do not use contact details from the email.
If the message pretends to be us, open a support ticket. Include the From address, the subject, and the time. Do not forward the original as a reply to a notification email. Paste the text into the ticket or attach a screenshot.
On shared hosting, mark junk in Roundcube (the Junk folder). On LochStudios Mail, use the Spam folder in WebMail. See Manage spam and the quarantine. Unsure which product you have? Open a support ticket.
If the message pretends to be a bank or another company, open their site by typing the address you already know, or use a bookmark you made. Do not call a number printed in the email.
If you already clicked
Do not panic. A click is not the same as a stolen account.
- You only opened a page and typed nothing. Close the tab. That is usually enough.
- You typed the portal password. Change it under Account → password from a device you trust. Confirm two-factor authentication is on. Save the recovery codes in your password manager.
- You typed a mailbox password. On shared hosting, sign in at the portal, click Log in to cPanel, open Email Accounts, and set a new password. On LochStudios Mail, change it in WebMail. Then update every phone and desktop app. See Create strong passwords and use a password manager.
- You typed a WordPress, FTP, or database password. Change that secret in cPanel and in the app that uses it. See Secure your WordPress site and Create an FTP account and connect.
- You typed a card number. Call the number on the back of the card. Do not call a number from the email.
- You think a site was changed. Read What to do if your website is hacked.
Then open a support ticket. Tell us what you clicked and what you typed (not the password itself). We will check the account with you.
A "new device" or "password changed" email you did not expect
That can be a real notice from us. Do not click the email. Sign in at the portal yourself, change the password, and check two-factor. Then open a support ticket.
Habits that help
- Turn on portal two-factor authentication. Use an authenticator app, not SMS. Open Account → Two-factor authentication.
- Use a password manager. It fills the real site. A fake login page will not match the saved URL.
- Keep each password unique. The portal, each mailbox, FTP, MariaDB, and WordPress are different secrets.
- Open the portal from a bookmark you created, or by typing
/portal. Do not search for a login page and click the first ad. - Treat unexpected "reset your password" mail as a warning. If you did not ask for a reset, ignore the link and open a support ticket. If you did ask, use Forgot password only from a page you opened yourself.