Phishing Email Warning to Customers: A Free Template

When your brand is impersonated in phishing emails that are currently circulating, it is important that you communicate with your customers properly.

Addressing that hackers are using your name to send phishing attempts helps to protect your customers, and at the same time signals that you take these incidents very serious.

This article is for you if you need to address your customers but don’t really know what a phishing warning email is supposed to contain. Either that, or you simply don’t have the time or don’t want to write the entire email yourself from scratch.

Disclaimer: These templates are editorial guidance, not legal advice. Before you send any communications based on these templates, confirm the wording you will use with your legal team. Also, legal requirements of breach notification vary significantly per country, industry, the nature of the incident.

Template: Active Brand Impersonation Warning

This is arguably the one you will use most often, when you catch wind that your brand is being used to dupe and trick your customer base.

Send this to your customers as soon as you know that phishing emails are being sent out. Every hour you delay this, is an hour your customers are exposed.

The template below makes sure you:

  • Protect customers from the ongoing scam
  • Communicate properly in the event of a crisis
  • Demonstrate that you care about the safety of your customers
  • Have proof that you warned customers early, which can help in possible future legal or support issues

Input Your Specific Details

Note: The [bold, bracketed text] are the parts where you are supposed to fill in the details relevant to your specific situation. The text in parentheses is guidance for writing the template and should be deleted before sending.

Subject: Important: Phishing scams impersonating [Company Name], please read


Dear Customer/[first name],

We are writing to let you know that scammers are currently impersonating [company name] in phishing messages targeting our customers.



What is happening
(Describe the impersonation message in 1-2 sentences. How are they reaching your customers? (email or text?) What are they asking recipients to do?)



How to recognize the fake message:
Through the following signs you can identify the scam:

(Warning sign 1, for example, the message contains a shortened link that does not lead to a website with your company’s official domain.)

(Warning sign 2, for example, manufactured urgency, the fake message pushes for immediate action, or action within 24 hours.)

(Warning sign 3, for example, a request for sensitive information: the scammer asks for passwords, credentials, or payment details.)



What to do if you already engaged with the message
If you clicked the link but didn’t enter any information, the risk is generally lower, but not zero. To be safe:

  • Change the password of your account, and other accounts you have that share the same password
  • Enable 2FA (leave this out if your website doesn’t support 2FA.)
  • Watch your accounts for any unusual activity in the upcoming weeks
  • If you notice anything suspicious, contact us immediately at (company phone number)


How to verify if communications are actually from us:
Check the sender’s email address carefully, not just the display name. (@ozarc.io vs. @ozarcsupport.io? Give the actual domains your company uses to communicate via email.)


You can always contact us directly, to make sure the communications are from us and not from scammers. You can call our phone number or contact us through email. You will find our contact information at the end of this email.



What we’re doing about this scam
We take these incidents and the safety of your identity, data, and finances very seriously. Our security team is actively working to terminate the associated websites and stream of fraudulent messages.



How you can contact us to give us a heads up or if you have concerns
You can contact us by sending an email to [company email] or calling us: [company phone number]


Sincerely, [your name] (include executive signature)

What Every Customer Warning Email Must Include

These are the most important things you should keep in mind when writing a phishing warning email to customers:

  • It describes the attack specifically, was it credential harvesting, letting the customer download a malicious file, or transfer a large sum of money?
  • How did the attack reach your customers?
  • How customers can contact your brand the next time in the event of a possible scam
  • What signs they need to watch out for going forward if they want to protect themselves from phishing

What to Do When Customers Receive Phishing Emails

A single report by a customer about an ongoing phishing campaign is often the signal of a wider campaign. How you handle it matters beyond that one conversation.

Get the evidence, but don’t click anything yourself. Ask the customer to forward the text message or email. Make sure your security team can review it.

It must become clear if this is a new message you’ve already seen, or if it’s the first sign for a new campaign. Furthermore, thank the customer for reporting it. A quick and human reply encourages people to flag suspicious messages instead of just deleting them.

Why You Should Report These Phishing Campaigns

A few reasons why you should report phishing campaigns or messages that use your company name:

  • It builds a documented response you may need later: If you would need to prove that you ”did something about it”, a documented response to share proves that you took the proper steps.
  • It helps more than just your own customers: Blocklisting and industry reporting (like APWG) protect anyone who might receive the same message.
  • It protects your brand’s reputation, not just the immediate victims: A scam running under your name erodes trust in the real thing, even if you didn’t cause it and weren’t hacked yourself.

How to Report

Giving specific instructions for every country isn’t realistic since reporting bodies and dedicated channels for reporting vary wildly from one place to the next, and what’s accurate today may have changed by the time this gets read.

The most reliable way: Search [your country’s name] report phishing on Google.

Either that, or your country’s national CERT/CSIRT on Google.

(CERT: Computer Emergency Response Team)

Comments

Leave a Reply

Discover more from OZARC

Subscribe now to keep reading and get access to the full archive.

Continue reading