X
Xero
Targeting NZ administrative and accounting staff with highly effective "Fake Xero Invoice" lures to distribute malware or harvest banking details.
Official indicators
X
Xero<messaging-noreply@post.xero.com>
To: you@example.com
For your security, please Log in to Xero to complete this action.
Original URL: https://login.xero.com/. Click or tap if you trust this link.
What real Xero messages look like
- Official emails originate from @xero.com or @post.xero.com
- Xero will never ask for your login password or banking details in an email
- Official invoices are viewed securely within the Xero portal — never as an unverified link
- Legitimate billing notifications will lead you to log in at login.xero.com
Common spoof patterns
- "Invoice [Number] from [Local Business]" emails with a malicious link
- "Your Xero subscription payment failed" lures targeting credit card info
- Fake "Shared Document" notifications mimicking the Xero branding

