Recognising phishing attempts targeting hosting customers
Quick answer
Hosting customers get targeted with fake invoices, fake suspension warnings, and fake login pages. Check the sender's actual domain, never click a link in an unexpected billing or account email, and log in by typing portal.worldstream.com yourself instead.
Anyone running servers is a useful target: a compromised hosting account can be used to host malware, send spam, or hold real infrastructure to ransom. Phishing against hosting customers tends to follow a small number of patterns, once you know them, most attempts are easy to spot.
Fake invoice and billing emails
A common pattern: an email that looks like an invoice or payment failure notice, with a link to "view invoice" or "update payment details". The link goes to a lookalike page designed to capture login details or card information.
- Check the sender's email domain carefully, not just the display name. A display name can say anything; the domain after the @ is harder to fake convincingly.
- Look for small misspellings or extra words in the domain, such as an extra hyphen or a different top-level domain than the real one.
- Don't click the link. Open a new browser tab and go directly to your billing area in Portal instead.
- Genuine invoices and billing history are always available inside Portal itself, you don't need to rely on a link in an email to find them.
Fake "your server will be suspended" urgency emails
These rely on urgency to get you to act before you think it through: a claim that a server, domain, or account will be suspended within hours unless you click a link and "verify" something immediately.
- Urgency and a short deadline are themselves a warning sign. Legitimate account or billing issues don't usually require action within minutes of the email arriving.
- Check your actual account status directly in Portal rather than trusting the email's claim.
- If you're genuinely unsure whether a notice is real, contact support through a channel you already know and trust, not a phone number or reply address given in the suspicious email.
Fake login pages
A link in a phishing email often leads to a page that looks like a normal login screen, sometimes a close copy of a real one, built purely to capture whatever you type into it.
- Check the address bar before entering anything. A fake page will have a different domain, even if the page itself looks right.
- Type portal.worldstream.com into your browser yourself rather than following a link from an email, a chat message, or a search result ad.
- Save the real portal address as a bookmark and use that bookmark to log in, so you're never relying on typing it correctly, or clicking a link, under pressure.
- If you use two-factor authentication and a login page doesn't ask for your second factor the way it normally does, stop and check the address bar again.
A few things that hold true everywhere
- Worldstream will never ask for your password by email, and neither will any reputable provider. Treat any email that asks you to "confirm" or "verify" your password as fake.
- Hovering over a link (without clicking) usually shows the real destination URL, check it matches where you expect to land.
- Attachments you weren't expecting, especially ones claiming to be invoices, are a common malware delivery method. Don't open them from an email you're not certain about.
- If you've already clicked a link and entered credentials on a page you now suspect was fake, change that password immediately and, if you reused it anywhere else, change it there too.