Recently, a highly deceptive phishing campaign has been hitting inboxes, attempting to steal credit card details and account credentials by impersonating Squarespace. If you receive an email claiming your "Pro subscription" payment failed and your website will be blocked, take a close look before clicking anything.
Here is exactly how this scam works and what you need to look out for.
As you can see in the screenshot provided (reference the file image_e6ae67.png), scammers are using urgent language and stolen logos to trick website owners. However, a quick inspection reveals several massive red flags:
Mismatched Sender Information: The email claims to be about your website subscription, but the sender name displays as "Christelijke mutualiteit" (which is actually a Belgian health insurance fund). Furthermore, the "Reply-To" address is listed as noreply@lightspeedhq.com, which belongs to a completely different e-commerce platform, not Squarespace.
Fake Urgency: The email aggressively pushes a 48-hour deadline to update your payment method, threatening that your "Service will be suspended" and your "website blocked." Scammers rely on this panic-inducing language to make you act before you think.
Sloppy Footer Details: While the email includes the official Squarespace logo at the very bottom, the scammers completely forgot to fill in the sender details, leaving obvious placeholder text like [Your Company Name] | [Your Address] | [Your Contact Email].
The most dangerous part of this email is the "UPDATE PAYMENT DETAILS" button.
Instead of linking to squarespace.com, the button hides a malicious redirect link routed through a legitimate marketing platform (specifically, hirefrederick.com, which is part of Mindbody's Marketing Suite). Because hirefrederick.com is a trusted service used by small businesses to send newsletters, scammers exploit it to easily bypass standard spam filters.
If you click that button, the tracker instantly redirects you to a fake login page controlled by the scammers. Any passwords or credit card information you type into that page will go straight into their hands.
If you receive this email (or one similar to it), follow these steps:
Do not click any links. Keep your mouse away from that update button. Clicking confirms your email is active and redirects you to a dangerous page.
Verify independently. If you are genuinely worried about your Squarespace account status, open a fresh browser window, type in squarespace.com, and log in to your official dashboard. If there is a real billing issue, Squarespace will alert you directly within your account, not just via email.
Report and delete. Forward the deceptive email to Squarespace's security team at reportphishing@squarespace-security.com so they can track the campaign, and then delete it from your inbox entirely.
Stay vigilant and always double-check the sender's actual email address before handing over your payment details!