Recently our WordPress development agency was targeted by what appears to be a sophisticated phishing scam posing as a legitimate project inquiry.
The approach was convincing enough that it could easily fool agencies or freelancers who regularly receive new client enquiries through their website. Because scams like this are becoming more common, I wanted to share what happened so other developers and agencies know what to look out for.
How the Scam Started
The first contact came through our website contact form, which is normally how legitimate clients reach us about WordPress development projects. The message appeared professional and detailed. The sender claimed to represent a company that needed help with a WordPress-related project and suggested they were ready to move forward quickly.
At first glance everything seemed normal:
- The message was written clearly and professionally
- The person referenced a real company
- They even had a website that appeared legitimate
However, a few things began to feel slightly unusual as the conversation continued.
Warning Signs That Something Was Off
As the discussion progressed, the sender started providing instructions that raised some red flags. They sent messages such as:
“We are ready to provide you with full access to our website and all data for a more thorough analysis of the proposed work.”
“After completing Google authorization, you’ll receive a Username*****. Please send it to me, and we’ll grant you full access.”
“We have also prepared all of our company’s payment details and are ready for the final audit and drafting of the service agreement.”
“I am sending you a document with technical specifications.”
“Unfortunately, it is not within my authority to schedule and conduct audio or video conferences. I will pass this information on to my CEO, and he will email you as soon as he is available so that you can schedule a date and time for the call.”
Digging Deeper
Several aspects immediately stood out as suspicious:
- The company website they referenced appeared real but may have been cloned or used as part of the scam.
- They avoided video or phone calls
- They wanted me to authenticate through Google and send them a username
- They were pushing access and documentation very early
- The process felt scripted and overly formal
- The person’s name did not exist online — no LinkedIn, no company profile, no references.
- Inspecting the email’s HTML code revealed a different email address embedded in the message.
- The phone number to call shown in the code was a generic placeholder: 0123456789.
- The email headers contained Russian characters embedded in the code.
The goal of the scam likely wasn’t to build a website at all — it was probably an attempt to trick developers into granting access to their Google accounts or downloading malicious documents.
How These Scams Usually Work
Phishing scams targeting developers often follow a similar pattern:
- Initial project enquiry through a contact form or email.
- Professional but generic communication to build trust.
- A request to open documents or authenticate through a platform.
- Attempt to capture login credentials or install malware.
Developers and agencies are attractive targets because we often have access to:
- hosting accounts
- client websites
- domain registrars
- cloud platforms
- Google Workspace accounts
One compromised login can potentially give attackers access to multiple systems.
What To Do If You Receive a Similar Enquiry
If something about a project enquiry feels unusual, take a moment to verify before proceeding. Some simple checks include:
- Look up the person on LinkedIn
- Check the company domain age
- Inspect email headers
- Ask for a quick video call
- Never log into accounts via links provided in documents
A legitimate client will almost always be happy to jump on a quick video call.
Scammers almost always avoid it.
Why I’m Sharing This
As WordPress developers we often focus on building secure websites for our clients — but we also need to protect our own businesses from social engineering attacks. This scam attempt was fairly convincing, and I can easily see how a busy freelancer or agency could follow the instructions without thinking twice. If sharing this experience helps even one other developer avoid the trap, it’s worth it.
Final Thoughts
The internet is full of legitimate opportunities, but unfortunately it also contains people trying to exploit them. When dealing with new project enquiries, especially from unknown contacts, it’s always worth doing a quick verification before engaging further.
Trust your instincts. If something feels slightly off, it probably is.