LochStudios  /  Help Centre  /  Security  /  Recognise and avoid phishing emails

Recognise and avoid phishing emails

Spot fake mail that pretends to be LochStudios or another company, and what to do if you clicked a link or typed a password.

Updated

Phishing is a fake email, text, or lookalike website built to steal a password, a card number, or a two-factor code. Attackers copy logos and write as if they are us, a bank, or a payment company. They want you to panic and click.

We will never ask you to send a password, a two-factor code, or a full card number by email. If you cannot sign in, start a portal password reset or open a support ticket. Do not reply to the message.

How we actually contact you

Real mail about your account:

  • Uses the display name LochStudios
  • Addresses you by name when we have it
  • Points you at the portal, Billing, or a ticket you already opened
  • For tickets, tells you to open the ticket in the portal. We do not read replies to those notifications.

We send invoices, payment receipts, password resets you asked for, new-device notices, service-ready mail, and ticket updates. A hosting-ready email does not include passwords or FTP logins. See Getting started after you order hosting.

People-facing addresses we publish are on @lochstudios.com (for example support@lochstudios.com). The public website is lochstudios.com.au. That .com.au site is not the mailbox we ask you to write to. Help is a ticket, not a reply.

If you are unsure a message is from us:

  1. Do not click the links in it.
  2. Sign in at the portal by typing that path yourself, or by using a bookmark you made.
  3. Check Billing for a real invoice, or open a support ticket.

Open cPanel and WebMail from the portal. On a hosting service click Log in to cPanel. On a LochStudios Mail service click Log in to WebMail. Do not use a hostname from an email.

Common phishing tactics

Attackers often use:

  • Urgency. "Your account will be locked" or "Confirm this payment now."
  • A generic greeting. "Dear Customer" or "Dear User" instead of your name.
  • A lookalike link. The text says one site. The real destination is another.
  • A request for secrets. Passwords, card numbers, PINs, or two-factor codes.
  • A threat or a prize. "Act now or lose the service" or "Click to claim a refund."
  • A mismatched sender. The display name says LochStudios. The address is something else.

Poor spelling is a clue. So is a polished message. Do not trust logos or colours alone.

We do send invoice reminders, including when a service is close to suspension. Those invoices are always in Billing. If the portal has no matching invoice, the email is not a bill from us.

How to check a message

Hover over links (do not click).

In most mail apps, rest the cursor on the link and read the address that appears. On a phone, touch and hold the link until the destination shows, then cancel.

Suspicious:

  • The text says our site, but the destination is a different domain or an extra word (lochstudios-secure.example, packages-lochstudios.net).
  • The destination is an IP address, a URL shortener, or a file download.
  • The path looks like a login form you did not open yourself.

Read the sender's address, not only the name.

Anyone can set the display name to LochStudios. Look at the part after @. Extra words, a domain that only resembles ours, or an address that asks you to "verify" by return mail is a warning.

Ask what the message wants.

  • Does it ask you to confirm a password, a card, a PIN, or a two-factor code?
  • Does it create panic ("immediate action") for something you cannot see in the portal?
  • Does it tell you to reply with account details?
  • Does it tell you to open cPanel or WebMail at a hostname you have never used?

If any of those are true, treat it as phishing.

What to do if you receive a phishing email

  1. Do not click links or open attachments.
  2. Do not reply.
  3. Mark it as junk or phishing in the mail app so later copies are filed away.
  4. Delete it after you have marked it.
  5. Check the real account yourself. Type the site or open the portal. Do not use contact details from the email.

If the message pretends to be us, open a support ticket. Include the From address, the subject, and the time. Do not forward the original as a reply to a notification email. Paste the text into the ticket or attach a screenshot.

On shared hosting, mark junk in Roundcube (the Junk folder). On LochStudios Mail, use the Spam folder in WebMail. See Manage spam and the quarantine. Unsure which product you have? Open a support ticket.

If the message pretends to be a bank or another company, open their site by typing the address you already know, or use a bookmark you made. Do not call a number printed in the email.

If you already clicked

Do not panic. A click is not the same as a stolen account.

Then open a support ticket. Tell us what you clicked and what you typed (not the password itself). We will check the account with you.

A "new device" or "password changed" email you did not expect

That can be a real notice from us. Do not click the email. Sign in at the portal yourself, change the password, and check two-factor. Then open a support ticket.

Habits that help

  • Turn on portal two-factor authentication. Use an authenticator app, not SMS. Open Account → Two-factor authentication.
  • Use a password manager. It fills the real site. A fake login page will not match the saved URL.
  • Keep each password unique. The portal, each mailbox, FTP, MariaDB, and WordPress are different secrets.
  • Open the portal from a bookmark you created, or by typing /portal. Do not search for a login page and click the first ad.
  • Treat unexpected "reset your password" mail as a warning. If you did not ask for a reset, ignore the link and open a support ticket. If you did ask, use Forgot password only from a page you opened yourself.

Related


Was this article helpful?

← Back to Security