Thriday phishing email hits SMB customers, asks for bank details

Australian fintech Thriday warned customers Tuesday that a phishing email sent from its official address contains a fraudulent link requesting banking credentials. The timing matters: it hit during tax season, when small business owners are most vulnerable to credential harvesting attempts.

Thriday phishing email hits SMB customers, asks for bank details

What Happened

Thriday, the SMB banking and accounting platform owned by ASX-listed Tyro, sent an urgent alert Tuesday after a phishing email went out from [email protected] asking customers to click a link and provide personal and banking details.

The company told customers to delete the email immediately. Anyone who clicked the link was advised to contact their bank and call Tyro on 1300 008 976.

Why This Matters for Sales Teams

Phishing campaigns that compromise legitimate email addresses are harder to spot than generic scams. The attacker used Thriday's actual sending address, which means either the email infrastructure was compromised or the domain was spoofed convincingly enough to pass basic checks.

For sales teams selling into SMBs or managing fintech partnerships, this is a reminder that security hygiene is part of the value prop. When your product touches customer money or data, a phishing incident becomes a trust issue fast.

Industry data shows phishing click rates average 3 to 5% across sectors, with finance and professional services slightly higher. Ransomware attribution studies consistently show 70 to 90% of attacks start with a phishing email. Spear phishing, which targets specific roles or companies, converts even better because the message feels contextual.

The SMB Angle

Thriday competes in the crowded ANZ SME fintech space against business banking and spend-management tools. The company's pitch depends on trust: small businesses link their accounts and hand over financial visibility. A credential-harvesting attempt aimed directly at that relationship is commercially relevant even when no funds are reported lost.

The timing during tax season is not accidental. Small business owners are already stressed, clicking links in financial emails without the usual scrutiny. That is when conversion rates spike.

What Sales Teams Can Do

If you are selling software, payments, or financial services, assume your team will be targeted. Spear phishing emails aimed at sales reps often impersonate customers, partners, or internal finance teams requesting urgent wire transfers or credential resets.

Security awareness training works when it is specific. Generic phishing simulations do not cut it. Show your team real examples: fake login pages, spoofed executive emails, urgent requests that skip normal process. Teach them to verify URLs, enable MFA everywhere, and confirm unusual requests through a second channel.

Thriday has not disclosed whether the email system itself was breached or if this was a spoofing attack. Either way, the lesson is the same: when an email from a trusted sender asks for credentials, verify before clicking.