By J. Mesa
An email lands in your inbox at 4:45 on a Friday. Your mailbox is full, it says, and you will stop receiving messages unless you sign in now. You click, type your password, and go home. By Monday, a stranger has read three months of your email and sent an invoice to your largest customer. Most break-ins at small businesses begin this way, with one message and one tired person.
What is phishing?
Phishing is a fraudulent message that poses as a trusted sender to trick you into giving up a password, sending money, or opening a malicious file. Email carries most of it. Text messages, phone calls, and social media carry the rest.
How does a phishing attack work?
The attacker wants one of three results.
- Your credentials. The message links to a fake sign-in page for Microsoft 365, Google, your bank, or a shipping company. Whatever you type goes to the attacker.
- Your money. The message poses as a vendor, a boss, or a customer and asks for a payment, a gift card, or a change of bank details.
- Your computer. The message carries an attachment or a link that installs malware, including the kind that leads to ransomware.
What are the warning signs of a phishing email?
- The sender address does not match the name. The display name says “Microsoft Support,” and the address behind it ends in a domain you have never seen. Click or tap the name to reveal the full address.
- The domain is close but wrong. Look for swapped or added characters: “rn” in place of “m,” a zero in place of the letter o, or an extra word such as “-secure” or “-billing.”
- The message creates urgency. Your account closes today. The invoice is overdue. The boss needs it in ten minutes. Pressure exists to stop you from thinking.
- The request is unusual. A vendor changes its bank account by email. The owner asks for gift cards. Payroll gets a request to move a direct deposit.
- The link goes somewhere else. Hover over the link on a computer, or press and hold on a phone, and read the real address. A Microsoft sign-in page does not live on a random website.
- The attachment was not expected. Treat surprise invoices, voicemails, scans, and shipping documents as suspect, above all files that ask you to “enable content” or sign in to view them.
- The greeting is generic. “Dear customer” from a bank that knows your name.
- The tone is off. A colleague who writes in short bursts sends three formal paragraphs. Trust that instinct.
- The message asks for secrets. No legitimate company asks for your password, your verification code, or your full card number by email.
Spelling mistakes used to be a reliable sign. They are less reliable now, because attackers use better tools and copy real company emails word for word. A clean, well-written message can still be a fake.
What are the common types of phishing?
- Bulk phishing. One message to millions of people, posing as a bank, a streaming service, or a delivery company.
- Spear phishing. A message written for one person, using details from LinkedIn, your website, or an earlier breach.
- Whaling. Spear phishing aimed at owners and executives.
- Business email compromise. A message that poses as a boss or a vendor to redirect a payment. It often contains no link and no attachment, which lets it pass through filters.
- Smishing and vishing. The same tricks by text message and by phone.
- Clone phishing. A copy of a real email you received before, with the link or attachment swapped.
Our post on how hackers get in covers the psychology behind these attacks.
How do I check a link safely?
- Hover first, and read the address from right to left. The part just before “.com” or “.org” is the real owner. In “microsoft.com.account-verify.net,” the owner is account-verify.net.
- Do not trust the padlock. Fake sites have them too.
- When in doubt, skip the link. Open your browser and type the company’s address yourself, or use the bookmark you already have.
- Be careful with shortened links and QR codes, which hide the destination.
What should I do when I get a suspicious email?
- Do not click, reply, or open the attachment.
- Report it. Use the “Report phishing” button in Outlook or Gmail, and forward it to whoever handles your IT.
- Verify through another channel. Call the sender at a number you already have. Do not use the phone number in the message.
- Delete it.
If the message poses as a coworker or a vendor you know, tell that person. Their account may have been hacked, and they may not know yet.
What should I do if I clicked a phishing link?
Speed matters more than embarrassment. Tell your IT contact right away.
- You clicked but entered nothing. Close the page. Run a scan with your security software. Watch the account for a few days.
- You entered a password. Change it at once from a different device. Change it on every other account where you used the same one. Turn on multi-factor authentication. Ask IT to sign out all active sessions and check the mailbox for forwarding rules the attacker may have added.
- You opened an attachment or enabled content. Disconnect the computer from the network and call IT. Do not keep working on it.
- You sent money or bank details. Call your bank immediately and ask for a recall, then report the fraud to the FBI at ic3.gov.
How do I protect my business from phishing?
- Turn on multi-factor authentication for email first, then for banking, payroll, and remote access. A stolen password alone then gets the attacker nowhere.
- Use the email filtering you already pay for. Microsoft 365 and Google Workspace include phishing and attachment protections that many businesses never switch on.
- Tag outside email. A banner that marks messages from outside the company exposes a fake “boss” at a glance.
- Set a payment verification rule. No change to bank details and no new payee without a phone call to a known number and a second approver.
- Use a password manager. It fills passwords only on the real site, so a look-alike page gets nothing.
- Limit what staff post. Job titles, vendor names, and travel plans on public pages help an attacker write a convincing message.
- Make reporting easy and safe. One button or one address. Thank the people who report, including the ones who clicked first.
Does phishing training work?
Yes, when you repeat it. A one-hour lecture once a year fades within weeks. Short sessions through the year, paired with simulated phishing emails, build the habit of pausing before a click. Track two numbers: how many people click, and how many people report. The second number matters more, because one fast report lets you warn everyone else.
Treat a failed test as a coaching moment. Staff who fear punishment hide their mistakes, and a hidden click does the most damage. Our cybersecurity training covers phishing for every role, from the front desk to the owner.
Can email filters stop all phishing?
No. Filters catch most bulk phishing. Targeted messages, messages sent from a real hacked account, and messages with no link or attachment still arrive. Your people are the last check, so give them the knowledge and the permission to slow down.
Your next step
Forward this list of nine signs to your staff, and ask each person to find the “Report phishing” button in their mail program today. To build a training program and a payment verification policy that fit your business, see our services or contact Cerberus Cybersecurity.