How to recognise and avoid a fake 'Your account will be suspended' or 'security alert' email scam
Summary
This guide helps you troubleshoot and resolve: How to recognise and avoid a fake 'Your account will be suspended' or 'security alert' email scam. Follow the steps below to fix the issue.
Common Causes
Phishing emails that claim your account will be suspended or that a security alert has been triggered are common across Australia. These emails often look convincing, using 220 Internet Services branding, logos, and even a similar sender name. The goal is to trick you into clicking a link that leads to a fake login page where your credentials are stolen. This article explains how to spot these scams and what to do if you receive one.
Quick Fix Steps
- Do not click any links or open attachments in the suspicious email.
- Check the sender’s actual email address — not just the display name.
- Hover over any buttons or links to preview the destination URL.
- Log in to the 220 support portal directly by typing
https://app.220.com.au/into your browser. - If you entered your password on a suspicious page, change it immediately.
- Report the email to 220 Internet Services and delete it.
Detailed Instructions
Step 1: Pause before you act
Scam emails rely on urgency. Phrases like “Your account will be suspended within 24 hours” or “Immediate security alert — action required” are designed to make you panic and click without thinking. Take a breath. A legitimate provider will not suspend your account without prior written notice and multiple reminders.
Step 2: Examine the sender’s email address
The display name may say “220 Internet Services” or “220 Support”, but the actual email address tells the real story. Click the sender’s name in your email client to expand the full address.
- Legitimate 220 emails come from an address ending in
@220.com.au. - Scammers often use addresses like
[email protected],[email protected], or a free email provider such as Gmail or Outlook. - Watch for subtle misspellings, extra hyphens, or swapped letters.
Step 3: Hover over links to preview the destination
On a computer, move your mouse pointer over any button or link in the email without clicking. A small tooltip or the bottom-left corner of your browser will show the actual URL.
- Legitimate 220 links will point to
https://app.220.com.au/orhttps://www.220.com.au/. - Scam links often use lookalike domains such as
220-com-au.com,220internet.xyz, or a URL shortener likebit.ly.
On a mobile device, press and hold the link to preview the URL before releasing.
https://app.220.com.au/ manually. Log in there to check for any genuine account notices.Step 4: Look for poor grammar, spelling, and generic greetings
While some scam emails are well written, many contain telltale signs:
- Generic greetings such as “Dear Customer” or “Dear User” instead of your name.
- Awkward phrasing, unusual capitalisation, or spelling mistakes.
- Requests for information 220 would never ask for via email, such as your password, credit card number, or date of birth.
Step 5: Check for pressure tactics and threats
Scammers want you to act before you think. Common red flags include:
- Threats of immediate account suspension or data loss.
- Claims that “unusual sign-in activity” has been detected and you must verify your identity now.
- Countdown timers or deadlines of only a few hours.
- Offers that seem too good to be true, such as a refund or prize for clicking a link.
Step 6: Verify directly with 220 Internet Services
If you are unsure whether an email is genuine, do not reply to it. Instead:
- Open a new browser tab.
- Type
https://app.220.com.au/into the address bar. - Log in with your normal credentials.
- Check the Notifications or Account Status section for any legitimate alerts.
If there is no alert in the portal, the email was almost certainly a scam.
Step 7: Report and delete the email
Once you have confirmed the email is fraudulent:
- Do not click any links or download any attachments.
- Forward the email as an attachment to
[email protected]if your email client supports this. Alternatively, take a screenshot and attach it to a support ticket. - Open a ticket at Open a Ticket and include the sender address and a brief description.
- Delete the email from your inbox and your deleted items folder.
- If you use Microsoft Outlook, you can also right-click the email and select Junk → Block Sender.
What to do if you clicked a link or entered your password
If you suspect you have fallen for a phishing email, act quickly:
- Change your password immediately. Log in to
https://app.220.com.au/and update your password. If you use the same password on other websites, change it there too. - Enable two-factor authentication (2FA) on your 220 account if you have not already done so. This adds an extra layer of security even if your password is compromised.
- Check for unauthorised activity. Review your account for any changes to contact details, forwarding rules, or unfamiliar login sessions.
- Run a malware scan. If you clicked a link or downloaded an attachment, run a full scan with your antivirus software.
- Report the incident to 220 Internet Services via Open a Ticket so our security team can investigate.
Troubleshooting
I’m not sure if an email is real or fake
When in doubt, treat it as fake. Do not click anything. Log in to the 220 portal directly and check for notices there. If you are still unsure, Open a Ticket and our team will confirm whether the email is legitimate.
The email looks exactly like a real 220 email
Scammers can copy logos, formatting, and even the footer text from genuine emails. The sender address and link destination are the most reliable indicators. Check those first. If the sender address does not end in @220.com.au, it is fraudulent.
I received a text message or phone call instead of an email
Scammers also use SMS (“smishing”) and phone calls (“vishing”) with the same urgency tactics. The same rules apply: do not click links in unexpected text messages, do not provide personal information over the phone, and verify directly with 220 through the portal.
I keep receiving these emails
If you receive repeated phishing emails, mark them as junk or spam in your email client. Most email providers learn from this and will filter similar messages in the future. You can also create a rule to automatically delete emails from the offending sender.
I’ve already deleted the email — can I still report it?
Yes. If you remember the sender address or took a screenshot, you can still report it by opening a ticket at Open a Ticket and including the details you have. Even without the full email, reporting the sender address helps our security team block future attempts.
Still Having Issues?
đź’» Open a Ticket