American Express Phishing Scam Targets Australians With Non-Compliance Lockout
A phishing campaign targeting Australians has been detected by MailGuard, with scammers impersonating American Express to steal sensitive user credentials and financial data.
The emails are designed to look like a routine American Express service alert, with recipients told that their card has been locked due to 'non-compliance issues' and that they need to confirm their identity to resolve the issue.
However, behind the branding, the sender details reveal a different story. The display name is American Express | Non-Compliance Issues, but the actual sending address is donotreplyus(at)online.net, which does not align with legitimate American Express infrastructure.
Once clicked, the email leads to a phishing site that closely mimics the look and feel of the official American Express portal. The flow captures Amex login credentials, card verification data, and browser/session confirmation in multiple staged steps.