Someone is sending emails that appear to come from DOWO Digital. If you’ve received something claiming to be from us that you weren’t expecting, please read this before you reply.
What’s happening
This isn’t the usual “click this link” phishing, and that’s what makes it more dangerous.
The first email normally looks harmless. No link, no attachment, no threat – just a message that reads like it came from us, opening a conversation. Often it’s a note that your website is “insecure” or that your plugins are out of date; sometimes a question about hosting, a renewal or an invoice.
If you reply, the exchange continues – politely and plausibly, over several messages – until money enters it. An invoice for something you don’t owe, a renewal to settle “before it lapses”, or, most damaging of all, a message saying our bank details have changed.
That’s the purpose of the friendly opening. By the time the payment request arrives, it doesn’t feel like a cold approach. It feels like the continuation of a conversation you’ve been having for a fortnight.
The “insecure website” and “outdated plugins” versions deserve particular attention, because they sound exactly like something a web agency would legitimately raise. If we look after your website, we look after your updates. Patching and plugin maintenance are part of what we already do for you. You won’t get an unprompted email from us telling you to go and sort your own plugins out. If your site needs a decision from you, it comes from the person you deal with here, by name.
The one rule that stops this
We will never change our bank details by email.
If you receive a message saying our payment details have changed, treat it as fraudulent. Don’t pay it, and don’t reply to it to check – call us on the number you already have, from your own records.
Every version of this scam ends in the same place: money sent to an account that isn’t ours. Hold that one line and the rest of it can’t hurt you. The same goes for any invoice you weren’t expecting – if it doesn’t match work we’ve agreed, ring us before paying, even if it looks exactly right.
How to spot a fake
Check the sender address, not the display name. The name in your inbox is trivial to fake; the address behind it is what matters. Genuine email from us ends @dowo.digital. Read it right to the end – a free webmail address, or any other domain that merely resembles ours, isn’t us.
Check where a reply would go. Some of these are set up so the address you see and the address your reply reaches are different. Hit reply and look at the recipient before typing.
Be wary of a thread with no history, of generic greetings like “Dear Customer”, and of small wrong notes – odd phrasing, a signature that isn’t quite ours, American spellings, a tone that doesn’t sound like us.
What to do:
Verify outside the email. If anything claiming to be from us involves money, payment details or account access, don’t reply to it to check. Come to us on a channel you already trust — the number in your own records, the person you normally deal with, or hello@dowo.digital typed in fresh.
Please don’t worry about being over-cautious. Ignoring a genuine email from us costs nothing; we’ll chase you. Replying to a fake one can cost a great deal.
Forward anything suspicious to hello@dowo.digital. The full original message (forwarded “as attachment”, or as a .eml file) is most useful — it preserves the detail needed to get these operations shut down.
If you’re already in one of these conversations, stop replying, pay nothing, and tell us. Keep the emails; they’re useful evidence.
If money has already gone, call your bank immediately and tell them it’s authorised push payment fraud – speed matters, as funds can sometimes be recalled. Change any passwords you’ve shared, turn on two-factor authentication, let us know so we can check your services, and report it to Action Fraud on 0300 123 2040. Suspicious emails can also be forwarded to report@phishing.gov.uk.
There’s nothing embarrassing about being drawn into one of these. They’re patient, professional and built to look like ordinary business correspondence. Telling us quickly is always the right move.
Please pass this on
If someone else in your business pays the invoices — a bookkeeper, office manager or accountant – forward this to them. They’re the real target. The person who receives the friendly opening email often isn’t the person who eventually presses “pay”, and this works precisely in that gap.
A simple standing rule closes it: no supplier’s bank details are ever changed on the basis of an email, without a phone call to a known number first.
Where the addresses came from
We’re looking into how the sender obtained the addresses they’ve targeted. Business email addresses are widely and legitimately available in public – websites, WHOIS records, Companies House, LinkedIn, directories – and attackers scrape these at scale, work out which suppliers a business appears to use, and approach them in bulk. It’s an industry-wide pattern affecting agencies, hosts and accountancy firms across the UK.
If our investigation changes that position, we’ll tell you directly and promptly.
Meanwhile we’re reporting the domains and hosts involved so they can be taken down, and monitoring for further attempts. No supplier can stop someone else sending emails with their name on them – but we can make sure you know what genuine communication from us looks like, and make it easy to check.
If you’re ever unsure whether an email is really from us, just ask. Email hello@dowo.digital or call us. We’d far rather verify a genuine message than have you act on a fake one.
Further reading: the National Cyber Security Centre’s guide to spotting and reporting scam emails.
