Email Threat Shieldby Bit PrecisionOpen the pilot ↗

A SMALL PAUSE. A BETTER CHECK.

Familiar email.
Unfamiliar request.

Look past the logo. These examples show where a message’s story and its evidence stop matching.

FROM A REAL REVIEW · DETAILS REPLACED

The supplier and the manager
share the same strange address.

A supplier chases an invoice. An apparent manager approves it. Look across the conversation: the address receiving the supplier reply also appears behind the manager’s name.

The habit: expand the sender and recipient addresses. Compare each person’s role across the whole thread.

An anonymised reconstruction of a reviewed submission. Names, addresses, amounts and references are fictional. The original message and attachments are not published.

A claimed conversation
ToA · accounts-review [at] mail.example

Hello Alex, please send the invoice.


FromJordan · Procurement Manager
A · accounts-review [at] mail.example

Invoice approved. Please prioritise payment.

AOne external address plays two different roles. Verify the approval with the real manager through a known channel.
See the attachment clues
INVOICE · FICTIONAL RECONSTRUCTION

Riverstone Services Pty Ltd
Invoice 6421 · Total $12,480

Payee: B · Taylor Reed
Remittance: C · payments [at] other-company.example

B The payee differs from the issuer. A trustee or trading-name explanation needs independent confirmation; it does not prove account ownership.

C Compare the sender, supplier website and remittance address. Different identities matter more when combined with a questionable approval trail.

A valid ABN or correctly calculated total can be copied onto a false invoice. Neither authenticates the payment request.

What else should I notice?

Fictional teaching examples. Expand any message to reveal the clue.

01A link wearing a familiar nameCredential phishing+

Your Microsoft 365 document is ready.
Open SharePoint document

Destination: document-access[.]example

The visible label claims SharePoint; the destination tells a different story. Preview the link without opening it. On touch devices, use the link preview or ask IT.

Open the service from your usual app or bookmark.

02A new bank account, same invoicePayment diversion+

Our bank details have changed.
Use the new account below for today’s payment.

A genuine supplier’s mailbox can be compromised. Correct names, past invoices and a familiar domain do not verify new payment instructions.

Call the supplier on a number already in your records.

03A QR code that changes the taskQR phishing+

Scan to view your invoice.
After scanning: Enter your work password to release payment.

The concern is the unexpected credential request and destination, not the presence of a QR code. A QR code can hide the same kind of link as an email button.

Check the decoded destination before continuing; verify an unexpected sign-in.

04Your manager asks for secrecyExecutive impersonation+

From: Managing Director
director-request [at] external-mail.example

I’m in a meeting. Buy the gift cards now.
Don’t call or discuss this with anyone.

The unfamiliar address, unusual purchase and attempt to prevent verification reinforce each other. The display name alone identifies nobody.

Contact the manager through your normal company channel.

05A trusted host leads somewhere elseDocument and link chains+

Shared document → “View secure invoice” →
an unrelated sign-in or payment website

A genuine document-sharing platform can host a misleading file. Recheck the destination when the document asks you to move to another site.

A trusted first page does not authenticate the next page.

06A reply chain that asks you to trust itFabricated conversation+

Re: Approved payment
“Finance already checked this. Please process.”

Quoted messages can be edited. Compare addresses, participants, chronology and the actual approval record. “Re:” and missing signatures alone do not prove forgery.

Find the original approval in your own records or verify it separately.