Seasonal Threats

Holiday cyber scams: how Australian businesses can stay safe

A hooded figure at a computer displaying Christmas-themed scam pop-ups including fake gift cards, invoices, and delivery updates, in a festive office setting

Before Christmas leave starts, write down who can approve payments and who staff should call about a suspicious message. Without that cover, an unusual request can be waved through because the usual person is away.

The rules can stay short.

Watch for changed payment details

A fake supplier invoice may copy a real business name, format or past conversation. The important change is often the bank account.

Confirm new or changed payment details by calling a known contact number. Do not use the number in the message requesting the change. Apply the rule to every supplier, even when the request appears urgent.

Give accounts staff the JCPIT invoice fraud checklist before the leave period starts.

Treat gift card requests as suspicious

A message may claim that the owner needs gift cards for customers or staff and cannot take a call. It may ask for photos of the card numbers after purchase.

Do not buy gift cards in response to an unexpected message. Confirm the request directly with the person using a known phone number or a separate conversation.

Check delivery messages carefully

Busy businesses receive many parcel notifications. Scam messages may link to a fake sign-in page or ask for a small redelivery payment.

Open the courier's official website or app yourself and enter the tracking number there. Do not sign in through an unexpected email or text message.

Be careful with invitations and charity requests

Fake event invitations and donation requests can be used to collect passwords or payment details. Check the organiser through an official website or known contact before opening attachments, signing in or paying.

A familiar logo is not proof that a message is genuine.

Brief all staff, including temporary workers

Give staff a short briefing before the busy period. Explain how to report a suspicious message and who can approve payments when managers are away.

Temporary workers should not receive more system access than their role needs. Give each person an individual account, turn on multi-factor authentication and set an end date for access.

Prepare for leave and outages

Keep computers and business apps updated before key staff go on leave. Confirm that backups are running and test a restore of important data.

Write down who will respond to a suspicious sign-in, fraudulent payment or unavailable system. Keep bank, insurer and IT support contact details somewhere accessible if normal email is unavailable.

The JCPIT cyber incident first-hour checklist gives the person on duty a calm sequence to follow if something happens.

Slow down unusual requests

Scams often rely on secrecy, urgency or a change to the normal process. Staff should be allowed to pause and verify without being blamed for a delay.

If leave dates are already set but the cover plan is not, book a holiday security planning consultation with JCPIT Support. We will review temporary access, payment approvals and the incident contacts staff will need while managers are away.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
SPF, DKIM and DMARC explained in plain English
Next Article →
Cyber insurance requirements in Australia: what small businesses need to know