American Express Impersonation Scam Targets Australians with Fake Non-Compliance Lockout
A new phishing campaign has been targeting Australians, impersonating American Express and using a fabricated 'non-compliance lockout' notification to harvest sensitive information.
The email arrives with a generic subject line, styled to look like a routine American Express service alert. The body tells the recipient their card has been temporarily locked due to unusual spending activity and that all transactions are suspended pending verification.
Clicking on the 'Confirm your Identity' button leads to a phishing site that closely mimics the official American Express portal, including Amex logos and colour schemes. The flow ends with an error screen if fake details are entered, but by this point, attackers have already captured login credentials, card verification data, and browser/session metadata.
The scam is particularly dangerous as it asks for everything in one visit and uses a mundane pretext that doesn't immediately trigger suspicion. MailGuard advises recipients to delete the email without clicking on any links and provides guidance on how to identify suspicious emails.