Home › Knowledgebase › KB-629

How to recognise and avoid a fake 'Your account will be suspended' or 'security alert' email scam

Summary

This guide helps you troubleshoot and resolve: How to recognise and avoid a fake 'Your account will be suspended' or 'security alert' email scam. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? đź’» Open a Ticket

Common Causes

Important: 220 Internet Services will never ask you to confirm your password, credit card details, or personal information via email. If an email asks you to click a link and enter login details, treat it as suspicious.

Phishing emails that claim your account will be suspended or that a security alert has been triggered are common across Australia. These emails often look convincing, using 220 Internet Services branding, logos, and even a similar sender name. The goal is to trick you into clicking a link that leads to a fake login page where your credentials are stolen. This article explains how to spot these scams and what to do if you receive one.

Quick Fix Steps

  1. Do not click any links or open attachments in the suspicious email.
  2. Check the sender’s actual email address — not just the display name.
  3. Hover over any buttons or links to preview the destination URL.
  4. Log in to the 220 support portal directly by typing https://app.220.com.au/ into your browser.
  5. If you entered your password on a suspicious page, change it immediately.
  6. Report the email to 220 Internet Services and delete it.

Detailed Instructions

Step 1: Pause before you act

Scam emails rely on urgency. Phrases like “Your account will be suspended within 24 hours” or “Immediate security alert — action required” are designed to make you panic and click without thinking. Take a breath. A legitimate provider will not suspend your account without prior written notice and multiple reminders.

Step 2: Examine the sender’s email address

The display name may say “220 Internet Services” or “220 Support”, but the actual email address tells the real story. Click the sender’s name in your email client to expand the full address.

Step 3: Hover over links to preview the destination

On a computer, move your mouse pointer over any button or link in the email without clicking. A small tooltip or the bottom-left corner of your browser will show the actual URL.

On a mobile device, press and hold the link to preview the URL before releasing.

Tip: If you are unsure about a link, do not click it. Instead, open a new browser tab and type https://app.220.com.au/ manually. Log in there to check for any genuine account notices.

Step 4: Look for poor grammar, spelling, and generic greetings

While some scam emails are well written, many contain telltale signs:

Step 5: Check for pressure tactics and threats

Scammers want you to act before you think. Common red flags include:

Step 6: Verify directly with 220 Internet Services

If you are unsure whether an email is genuine, do not reply to it. Instead:

  1. Open a new browser tab.
  2. Type https://app.220.com.au/ into the address bar.
  3. Log in with your normal credentials.
  4. Check the Notifications or Account Status section for any legitimate alerts.

If there is no alert in the portal, the email was almost certainly a scam.

Step 7: Report and delete the email

Once you have confirmed the email is fraudulent:

  1. Do not click any links or download any attachments.
  2. Forward the email as an attachment to [email protected] if your email client supports this. Alternatively, take a screenshot and attach it to a support ticket.
  3. Open a ticket at Open a Ticket and include the sender address and a brief description.
  4. Delete the email from your inbox and your deleted items folder.
  5. If you use Microsoft Outlook, you can also right-click the email and select Junk → Block Sender.

What to do if you clicked a link or entered your password

If you suspect you have fallen for a phishing email, act quickly:

  1. Change your password immediately. Log in to https://app.220.com.au/ and update your password. If you use the same password on other websites, change it there too.
  2. Enable two-factor authentication (2FA) on your 220 account if you have not already done so. This adds an extra layer of security even if your password is compromised.
  3. Check for unauthorised activity. Review your account for any changes to contact details, forwarding rules, or unfamiliar login sessions.
  4. Run a malware scan. If you clicked a link or downloaded an attachment, run a full scan with your antivirus software.
  5. Report the incident to 220 Internet Services via Open a Ticket so our security team can investigate.
Warning: If you entered your password on a fake login page, that password is now in the hands of scammers. Do not reuse it anywhere. Change it on every account where you have used it.

Troubleshooting

I’m not sure if an email is real or fake

When in doubt, treat it as fake. Do not click anything. Log in to the 220 portal directly and check for notices there. If you are still unsure, Open a Ticket and our team will confirm whether the email is legitimate.

The email looks exactly like a real 220 email

Scammers can copy logos, formatting, and even the footer text from genuine emails. The sender address and link destination are the most reliable indicators. Check those first. If the sender address does not end in @220.com.au, it is fraudulent.

I received a text message or phone call instead of an email

Scammers also use SMS (“smishing”) and phone calls (“vishing”) with the same urgency tactics. The same rules apply: do not click links in unexpected text messages, do not provide personal information over the phone, and verify directly with 220 through the portal.

I keep receiving these emails

If you receive repeated phishing emails, mark them as junk or spam in your email client. Most email providers learn from this and will filter similar messages in the future. You can also create a rule to automatically delete emails from the offending sender.

I’ve already deleted the email — can I still report it?

Yes. If you remember the sender address or took a screenshot, you can still report it by opening a ticket at Open a Ticket and including the details you have. Even without the full email, reporting the sender address helps our security team block future attempts.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

đź’» Open a Ticket