Phishing Awareness & Fraud Prevention
Thought Media™ takes online security, fraud prevention, and the protection of our clients, customers, partners, employees, applicants, vendors, and members of the public seriously. Phishing is a form of fraud in which someone attempts to impersonate a legitimate company, organization, employee, financial institution, government agency, or other trusted party.
The goal may be to convince someone to:
- Provide passwords or login credentials
- Disclose personal or financial information
- Send money or change payment instructions
- Provide banking or credit card information
- Reveal authentication or verification codes
- Open a malicious attachment
- Visit a fraudulent website
- Download malicious software
- Provide confidential business information
- Grant remote access to a computer or account
- Take another action that benefits the scammer
Phishing and impersonation attempts may occur through email, text message, phone call, social media, messaging applications, websites, online advertisements, or other digital channels.
If you receive a communication claiming to be from Thought Media™, verify that it originates from an official Thought Media™ source before responding, providing information, clicking links, downloading files, changing payment information, or making a payment.
Official Thought Media™ Communications
For our United States website and operations, the official Thought Media™ website is:
ThoughtMedia.com
Official Thought Media™ notices and business communications originate through company-authorized domains, email addresses, telephone numbers, and communication channels.
When receiving an email claiming to be from Thought Media™, carefully review the entire sender email address, not simply the sender name displayed by your email application.
A legitimate-looking display name such as:
- Thought Media
- Thought Media Inc.
- Thought Media Support
- Thought Media Billing
- Thought Media Recruitment
- Thought Media Accounts
- Thought Media Administration
- The name of an actual Thought Media™ employee does not prove that the email was sent by Thought Media™.
The actual email address and domain should always be reviewed.
Official Thought Media™ email communications use company-authorized email addresses associated with our official domains.
Thought Media™ does not send official company notices from personal Gmail, Yahoo, Hotmail, Proton Mail, or other unrelated free email accounts.
If you are uncertain whether a communication is legitimate, contact Thought Media™ independently through:
ThoughtMedia.com
or email:
[email protected]
[email protected]
Do not reply to a suspicious sender to ask whether their own communication is authentic.
Be Cautious of Free and Unrelated Email Addresses
Phishing scams frequently use free, personal, anonymous, compromised, or unrelated email accounts designed to appear as though they represent a legitimate company.
These may include addresses using:
- Gmail
- Yahoo
- Hotmail
- Outlook
- Proton Mail
- Other free email services
- Random or unrelated business domains
- Domains created specifically for fraudulent activity
A scammer may create an address containing the words “Thought Media,” the name of an employee, the name of a department, or the name of one of our services.
For example, an email address could contain a convincing name while still ending in an unrelated domain such as:
@gmail.com
@yahoo.com
@hotmail.com
@proton.me
The presence of Thought Media, an employee name, or another familiar term in an email address does not mean that the sender is associated with Thought Media™.
If someone contacts you through an unexpected personal, free, or unrelated email address while claiming to officially represent Thought Media™, treat the communication with caution and independently verify it.
Watch for Domains That Imitate ThoughtMedia.com
More sophisticated phishing attacks may use domain names designed to resemble a legitimate company’s domain.
A fraudulent domain may use:
- Misspelled company names
- Additional words before or after the company name
- Added letters or numbers
- Hyphens or other characters
- Different domain extensions
- Similar-looking characters
- Misleading subdomains
- Recently registered domains
- Completely unrelated domains
A fraudulent address may look convincing when viewed quickly while actually belonging to an unrelated party.
For our United States and international website, the official domain is:
ThoughtMedia.com
Always review the complete domain carefully.
Be cautious of any domain that attempts to imitate ThoughtMedia.com through spelling changes, character substitutions, added words, different extensions, or other variations.
When in doubt, manually type: ThoughtMedia.com into your browser instead of following a link contained in an unexpected email, text message, or other communication.
Staff & Employee Impersonation
Phishing attempts may impersonate individual Thought Media™ employees, executives, managers, recruiters, accounting personnel, technical support staff, project managers, or other members of our team.
Scammers may obtain employee names, job titles, photographs, professional information, and other details from company websites, LinkedIn, social media, business directories, public sources, data breaches, or other locations.
They may then use this information to make a fraudulent communication appear legitimate.
A message can therefore appear to come from a real Thought Media™ employee even though that employee did not send it and has no involvement with the communication.
Common staff impersonation attempts may claim that a Thought Media™ employee:
- Needs an urgent payment or wire transfer
- Has changed banking or payment instructions
- Needs gift cards or another unusual form of payment
- Wants you to purchase something on their behalf
- Is providing a new invoice
- Needs access to an account or system
- Requires a password or authentication code
- Wants you to open or sign a document
- Needs confidential company information
- Is contacting you from a new or temporary email address
- Is temporarily using a Gmail, Yahoo, Hotmail, Proton Mail, or other personal account
- Has changed their telephone number
- Is contacting you through WhatsApp, Telegram, Signal, social media, or another messaging application
- Needs immediate action
- Does not want you to contact anyone else about the request
The use of a real Thought Media™ employee’s name, title, photograph, email signature, department, or other identifying information does not prove that the communication came from that person.
Verify the Actual Sender, Not Just the Displayed Name
Many email applications display a sender’s name much more prominently than the actual email address.
An email could display something such as:
John Smith – Thought Media
while the underlying sender address belongs to a free email account, unrelated domain, or domain designed to imitate ThoughtMedia.com.
Always inspect the complete sender email address.
If an employee who normally communicates with you using an official Thought Media™ email address suddenly contacts you through another domain, personal email address, new telephone number, or unfamiliar messaging application, independently verify the communication before acting on it.
Executive and Management Impersonation
A particularly serious form of business phishing involves impersonating executives, managers, company owners, accounting personnel, or other people with authority.
These attacks are sometimes referred to as executive impersonation, CEO fraud, or business email compromise.
A scammer may attempt to create urgency or secrecy with messages such as:
- “I need this handled immediately.”
- “I’m in a meeting and can’t talk.”
- “Don’t contact anyone else about this.”
- “Use these new banking details.”
- “Can you process this payment for me?”
- “I need you to purchase gift cards.”
- “Send me the authentication code.”
- “This is confidential.”
- “Our banking information has changed.”
Unexpected financial requests and changes to payment instructions should always be independently verified using contact information you already know to be legitimate.
Recruitment Fraud & Hiring Impersonation
Scammers may also impersonate Thought Media™ recruiters, hiring managers, human resources personnel, executives, or other employees when conducting employment scams.
A fraudulent recruiter may:
- Offer employment without a legitimate interview process
- Contact applicants from a free or unrelated email address
- Conduct interviews exclusively through text or messaging applications
- Request banking information unusually early in the hiring process
- Send a fraudulent check
- Ask an applicant to purchase equipment or software
- Request payment for equipment
- Request cryptocurrency, gift cards, or money transfers
- Ask applicants to pay application, training, onboarding, or administrative fees
- Send fraudulent employment documents containing Thought Media™ branding
- Create a fake website resembling ThoughtMedia.com
- Impersonate a real Thought Media™ employee
- Ask applicants to communicate through WhatsApp, Telegram, Signal, or another messaging platform
- Request identity documents or sensitive information through suspicious channels
Job applicants should independently verify communications claiming to be from Thought Media™.
We maintain a dedicated public resource explaining employment and recruitment scams involving our company name.
For additional information, please review:
Thought Media™ Recruitment Fraud Awareness
If you believe someone is impersonating a Thought Media™ recruiter, employee, or hiring representative, please report the communication to:
[email protected]
or
[email protected]
Phishing Emails
Email remains one of the most common methods used to conduct phishing and impersonation scams.
A phishing email may claim that:
- An invoice or payment is overdue
- Your account has been suspended
- Your password needs to be reset
- A document is waiting for your signature
- A refund or payment is available
- Someone from management needs an urgent payment
- Your website has a problem
- Your domain is expiring
- Your hosting account has a problem
- Your email account needs to be verified
- You have been selected for employment
- You need to provide banking or payroll information
- You must download an attachment
- You need to log in through a link in the email
- An employee or executive has changed payment instructions
- Your account has experienced suspicious activity
- A service is about to expire
- You have received an unexpected invoice or purchase order
Scammers commonly attempt to create urgency so recipients act before carefully examining the communication.
Unexpected messages using language such as:
“Urgent”
“Immediate action required”
“Final notice”
“Your account will be closed”
“Payment required today”
“Confidential”
“Potential Problems Detected on Your Website”
“Maintenance Required on Your Website”
should receive additional scrutiny.
Phishing Text Messages
Phishing conducted through SMS or other text messaging services is commonly known as smishing.
Fraudulent text messages may claim to involve:
- Payments
- Account verification
- Package deliveries
- Password resets
- Security alerts
- Employment opportunities
- Invoices
- Refunds
- Technical support
- Website or hosting services
- Account suspension
- Unusual login attempts
- Payment changes
Do not assume a text message is legitimate simply because the sender knows your name, company name, telephone number, job title, employee name, project information, or another piece of information about you.
Information about individuals and businesses can be obtained from websites, social media, business directories, public records, previous data breaches, and other sources.
Phishing Phone Calls
Fraudulent phone calls are often referred to as voice phishing or vishing.
A caller may impersonate:
- A Thought Media™ employee
- An executive or manager
- Technical support
- A billing department
- A financial institution
- A government representative
- A vendor
- A customer
- A recruiter
- Another trusted person or organization
Telephone caller identification can also be manipulated or spoofed.
The number appearing on your phone should not, by itself, be considered proof of the caller’s identity.
If you receive an unexpected call claiming to be from Thought Media™ and the caller requests sensitive information, payment, login credentials, authentication codes, remote computer access, or another unusual action, end the call and independently verify the request.
Use contact information published directly on:
ThoughtMedia.com
rather than a telephone number supplied by the caller.
Impersonation Through Messaging Apps and Social Media
Employee and company impersonation is not limited to email.
Scammers may communicate through:
- SMS
- Telegram
- Signal
- Microsoft Teams
- Other social networks
- Other messaging applications
A scammer may claim that they are traveling, using a personal device, experiencing email problems, have recently changed telephone numbers, or need to communicate through an alternate service.
These explanations should not replace normal verification procedures.
If you receive an unusual communication claiming to come from Thought Media™ or one of our employees, verify it through established company contact information.
Be Careful With Links and Attachments
Phishing messages frequently contain links directing recipients to fraudulent websites.
A link’s visible text may appear to say:
ThoughtMedia.com
while the actual destination leads to an unrelated website.
Before opening an unexpected link, inspect its destination.
On many desktop computers, hovering your pointer over a link will display the destination address before you click it.
You should also be cautious with unexpected attachments, particularly files claiming to contain:
- Invoices
- Contracts
- Purchase orders
- Payment instructions
- Resumes
- Account notices
- Shared documents
- Security updates
- Password-protected documents
- Tax documents
- Employment documents
Unexpected attachments may contain malicious software or lead users to fraudulent login pages.
Never Rely on a Message Alone to Verify Its Authenticity
Company logos, employee names, email signatures, addresses, website screenshots, invoices, photographs, branding, and other information can be copied.
Modern impersonation attempts may closely resemble legitimate company communications.
A communication should therefore not be considered authentic simply because it:
- Uses the Thought Media™ logo
- Mentions a real Thought Media™ employee
- Contains our company address
- References information found on our website
- Uses professional-looking branding
- Includes a convincing email signature
- Knows details about your company
- Knows information about an existing project
- Appears to come from a familiar telephone number
- Includes a professional-looking invoice
- References a real service offered by Thought Media™
- Includes information about an actual employee or executive
If something appears unusual, independently verify the communication through a separate trusted channel.
What Should You Do If You Receive a Suspicious Message?
If you receive an unexpected communication claiming to represent Thought Media™:
- Do not immediately respond.
- Do not click suspicious links.
- Do not download or open unexpected attachments.
- Do not provide passwords or authentication codes.
- Do not provide financial or banking information.
- Do not provide sensitive personal or company information.
- Do not send money based solely on an email, text message, or telephone request.
- Do not change payment or banking instructions without independent verification.
- Check the complete sender email address and domain.
- Verify the website address before entering login or payment information.
- Preserve the suspicious communication if you intend to report it.
- Contact Thought Media™ independently using contact information published on ThoughtMedia.com.
- Report suspected Thought Media™ impersonation to [email protected] or [email protected].
When verifying a suspicious communication, do not rely on the telephone number, email address, website, or other contact information provided exclusively by the suspicious sender.
Report Suspected Thought Media™ Phishing or Impersonation
If someone appears to be impersonating Thought Media™, one of our employees, executives, recruiters, departments, services, or websites, please report it to us.
Email:
[email protected]
or:
[email protected]
Whenever possible, include:
- The complete sender email address
- The name of the Thought Media™ employee being impersonated, if applicable
- The telephone number that contacted you
- The website or domain involved
- Screenshots of the communication
- The date and time you received it
- Links included in the message
- Copies of fraudulent documents or invoices
- A description of what the sender asked you to do
- Whether you clicked a link
- Whether you opened an attachment
- Whether you provided information
- Whether you sent money
If your email application allows you to forward the suspicious email as an attachment, doing so may help preserve sender and message-header information.
Do not open suspicious attachments solely for the purpose of reporting them.
Report a Phishing Website to Google
If a phishing message directs you to a fraudulent or deceptive website, you can report the website to Google Safe Browsing.
Google Safe Browsing – Report a Phishing Page:
https://safebrowsing.google.com/safebrowsing/report_phish/report
Provide the URL of the page you believe is attempting to impersonate another website, steal information, or otherwise conduct phishing activity.
Report Phishing in Gmail
If you use Gmail and receive a phishing email, Gmail provides a built-in reporting option.
On a desktop computer:
- Open the suspicious email.
- Select the More menu next to Reply.
- Select Report phishing.
Google provides additional information here:
Google – Avoid & Report Phishing Emails
Reporting suspicious messages to your email provider may help its systems recognize similar threats.
Report Cybercrime and Fraud in the United States
If you are located in the United States and believe you have been the victim or target of cybercrime, online fraud, phishing, business email compromise, account takeover, impersonation, or another cyber-enabled crime, you can report the incident to the Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3).
FBI Internet Crime Complaint Center:
https://www.ic3.gov/
IC3 is the FBI’s central reporting hub for cyber-enabled crime.
If money has been transferred or stolen, contact your bank, credit card provider, payment service, or other affected financial institution immediately in addition to making an appropriate report.
Report Fraud to the Federal Trade Commission
Fraud, scams, phishing, impersonation schemes, and other deceptive practices in the United States can also be reported to the Federal Trade Commission (FTC).
FTC ReportFraud:
https://reportfraud.ftc.gov/
The FTC uses consumer reports to identify patterns of fraud and support law-enforcement efforts.
Report Cybercrime and Fraud in Canada
If you are located in Canada, cybercrime and fraud can be reported through the Government of Canada’s national reporting service for the Royal Canadian Mounted Police (RCMP) and Canadian Anti-Fraud Centre (CAFC).
Report Cybercrime and Fraud:
https://reportcyberandfraud.canada.ca/
The service accepts reports involving cybercrime and fraud, including online scams and related fraudulent activity.
If you have lost money or provided financial information, contact your financial institution promptly and contact local law enforcement where appropriate.
Report Spam and Electronic Threats in Canada
Canadians may also report spam and other electronic threats through Canada’s Spam Reporting Centre.
Government of Canada – Report Spam:
https://ised-isde.canada.ca/site/canada-anti-spam-legislation/en/form/report-spam-form
The Spam Reporting Centre collects information concerning spam and other electronic threats in support of Canada’s Anti-Spam Legislation.
If You Already Responded to a Phishing Attempt
If you believe you interacted with a fraudulent communication, act quickly.
Depending on what occurred, you may need to:
- Change affected passwords immediately
- Change passwords on other accounts where the same or a similar password was used
- Enable or review multi-factor authentication
- Contact your bank or payment provider
- Notify your organization’s IT or cybersecurity team
- Review account activity for unauthorized access
- Sign out of active account sessions
- Remove unauthorized account recovery methods
- Scan affected computers or devices for malicious software
- Report fraudulent transactions
- Contact credit bureaus if identity theft may be involved
- Preserve suspicious emails, text messages, telephone numbers, URLs, screenshots, and payment records
- Report the incident to the appropriate cybercrime or fraud authority
If you entered a password into a suspicious website, do not return to that website.
Instead, visit the legitimate service directly by manually entering its known website address and change the affected password there.
If the same password or a similar password is used elsewhere, change those passwords as well.
If You Sent Money or Changed Payment Instructions
If you believe money was sent as a result of phishing, impersonation, business email compromise, or fraudulent payment instructions, contact the financial institution or payment provider involved as quickly as possible.
Explain that you believe the transaction resulted from fraud.
Depending on the payment method and circumstances, the institution may be able to take steps concerning the transaction or affected accounts.
You should also preserve:
- Payment confirmations
- Wire-transfer information
- Banking instructions
- Cryptocurrency wallet addresses
- Invoices
- Email communications
- Telephone numbers
- Screenshots
- Relevant dates and times
Report the incident to the appropriate authorities for your jurisdiction.
Preserve Evidence
Before deleting a phishing message, consider preserving information that may assist Thought Media™, your email provider, your financial institution, cybersecurity personnel, or law enforcement.
Useful information may include:
- The complete email message
- Full email headers
- Sender email addresses
- Telephone numbers
- Text message screenshots
- Website URLs
- Domain names
- Screenshots of fraudulent websites
- Payment instructions
- Cryptocurrency wallet addresses
- Banking information supplied by the scammer
- Dates and times
- Copies of invoices or documents received
- Information concerning money or data provided
Do not continue communicating with a suspected scammer simply to obtain additional evidence.
Verify Thought Media™ Communications
If you receive an email, text message, phone call, invoice, employment communication, payment request, technical support notice, account notice, or other communication claiming to be from Thought Media™ and you are uncertain whether it is legitimate, verify it with us independently.
Visit:
ThoughtMedia.com
or contact:
[email protected]
[email protected]
For employment-related scams and recruiter impersonation, please also review:
Thought Media™ Recruitment Fraud Awareness
Do not rely exclusively on contact information provided within a suspicious communication.
Help Protect Yourself From Phishing
Phishing and impersonation attempts can closely imitate legitimate business communications.
Fraudulent communications may incorporate company information, employee names, copied branding, professional-looking documents, spoofed telephone numbers, fraudulent domains, compromised accounts, and information obtained from public sources.
Remember:
A familiar company name, employee name, logo, email display name, telephone number, signature, invoice, or website design is not proof that a communication is legitimate.
For communications involving Thought Media™, verify the actual sender, domain, and request and independently confirm anything unusual through our official company channels.
Stop. Review. Verify. Report.
Official United States website:
ThoughtMedia.com
Report suspected Thought Media™ phishing, staff impersonation, domain impersonation, or other fraudulent communications:
[email protected]
[email protected]
Frequently Asked Questions
Check the complete sender email address and domain, not just the displayed sender name. Official Thought Media™ communications use company-authorized channels and should not originate from personal Gmail, Yahoo, Hotmail, Proton Mail, or other unrelated email accounts. For Canadian communications, you can independently verify information through ThoughtMedia.ca. If you are uncertain, contact [email protected] or [email protected] rather than replying to the suspicious message.
Do not click links, open attachments, provide passwords, send money, disclose financial information, or follow unexpected payment instructions. Preserve the suspicious communication and report it to [email protected] or [email protected]. You should independently visit ThoughtMedia.ca rather than using links or contact information contained in the suspicious message.
Yes. Scammers may use the real names, job titles, photographs, email signatures, or professional information of Thought Media™ employees to make fraudulent communications appear legitimate. A real employee’s name or photograph does not prove that the person actually contacted you. Recruitment-related communications should also be reviewed against our Recruitment Fraud Awareness information.
Yes. Phishing can occur through email, SMS text messages, telephone calls, social media, messaging applications, and fraudulent websites. Text-message phishing is commonly called smishing, while telephone-based phishing is commonly called vishing. Telephone numbers and caller ID information can also be spoofed, so unexpected requests should always be independently verified.
Suspected Thought Media™ phishing, employee impersonation, fraudulent domains, or other misuse of our company identity can be reported to [email protected] or [email protected]. Canadians may also report cybercrime and fraud to the RCMP and Canadian Anti-Fraud Centre, and phishing websites can be reported to Google Safe Browsing. If you have sent money or disclosed financial information, contact your financial institution as quickly as possible.
Let’s Build the Future of Enterprise
At Thought Media™, we collaborate with businesses and government organizations worldwide to create impactful digital strategies and brand experiences. If you’re ready to elevate your enterprise, let’s connect.
