Thriday customers hit with phishing scam from official email address
# Thriday customers hit with phishing scam from official email address Australian fintech Thriday warned customers Tuesday that a phishing email was sent from its official [email protected] address, requesting banking details via a fraudulent link. The timing matters: the scam hit during tax season, when Thriday's SME customers are finalising 2025-26 financial year affairs. The company told customers to delete the email immediately and avoid clicking any links. Customers who clicked the link were told to contact their bank and call Tyro (Thriday's ASX-listed parent company) on 1300 008 976. ## Why this matters for sales teams Thriday sits in the crowded small business finance platform segment alongside Xero, MYOB, Airwallex, and traditional banking tools. The company combines business banking, accounting, tax, and cashflow management in one platform. When your product handles sensitive banking and business data, security incidents directly affect: - Customer acquisition: prospects evaluate trust and security during evaluation - Onboarding conversion: new customers hesitate when security questions surface - Account retention: existing customers reassess platform risk - Sales cycle length: enterprise deals require extra security review For sales teams in fintech or any platform handling financial data, a phishing attack from an official company email raises questions prospects will ask: - How did attackers access the official sending address? - What customer data might be exposed? - What security improvements are being implemented? Thriday was founded in 2020 by CEO Michael Nuciforo and targets Australian SMEs and sole traders. The company has not disclosed customer numbers or revenue figures. ## What sales teams should know If you are selling in the SMB fintech space: - Expect security questions to increase in discovery calls - Prepare specific answers about email authentication protocols - Know your company's incident response timeline - Have documentation ready on data handling and breach notification Competitors will use this. Be ready to differentiate on security without being opportunistic. Thriday said it will provide further updates via email. The company has not disclosed how many customers received the phishing email or whether any customer data was compromised.