How to spot a phishing email before it costs your business.
Most break-ins at a small firm do not start with clever code. They start with one convincing email and one busy person who acted before they thought. This guide teaches your whole team to catch the fake before it moves your money or hands your inbox to a stranger.
Why phishing is how small firms actually get breached
When a small business gets breached, the cause is rarely a genius exploiting a flaw in your software. It is a person reading a message that looked normal and doing what it asked. Phishing keeps working because it targets the one part of your setup that no firewall protects: a busy human who is trying to be helpful and fast.
Attackers favor small firms for a plain reason. You move real money, you usually have no security team, and one well-timed email to the person who pays invoices can be worth more than weeks of technical effort. The message does not have to fool everyone. It has to fool one person, once, on a bad day.
What a phishing email actually looks like
Almost every phishing attempt carries one or more of the same tells. None of them require technical skill to spot. They require a habit of slowing down and looking. Here is what to watch for, with the kind of examples you will actually see.
- The display name lies, the real address tells the truth. The name reads "Chase Fraud Department," but the actual sender is billing-alerts@secure-verify123.info. Always read the address itself, not the friendly name in front of it.
- Urgency and fear. "Your account will be closed in 24 hours." "Final notice." "The owner needs this handled now and is about to board a flight." The pressure is the whole point, because a rushed person stops checking.
- A push to move money or change payment details. A supplier suddenly sends "updated banking details" for the next payment, or a boss asks you to buy gift cards and send the codes. Any change to where money goes is a red flag until you prove otherwise.
- Unexpected attachments and links. An invoice you were not expecting, a "shared document" you did not request, a tracking link for a package you never ordered. Surprise plus a click is the classic setup.
- Look-alike domains. alphamomin.com becomes alphamornin.com, where "rn" reads as an "m" at a glance. micros0ft.com hides a zero. your-supplier.co quietly drops the .com. The eye fills in what it expects.
- A request that skips the normal process. The wire that avoids the usual sign-off, the vendor who will only talk over email and never by phone, the login approval that arrives when you were not logging in.
Hover before you click, and read the domain backwards
The words in a link and its real destination are two different things. On a computer, hover your cursor over any link and read the true address that appears at the bottom of the window. On a phone, press and hold the link to preview where it goes before you commit. If the preview does not match the words, do not tap.
When you read a web address, the part that matters is the domain sitting just to the left of the first single slash. "secure-paypal.com.login-verify.ru/account" is not PayPal. It is a site called login-verify.ru with "paypal" pasted in front to fool you. Read the domain out from that pivot point and the disguise falls apart.
Business email compromise: the quiet con aimed at your money
The costliest phishing aimed at small firms often has no malware in it at all. Business email compromise, or BEC, is pure social engineering: someone impersonates a supplier, a boss, or a client and steers a legitimate payment into their own account. Invoice fraud is the common form. The attacker learns that a payment is due, then sends "our new bank details" at exactly the right moment.
The dangerous version is vendor email compromise, where an attacker who has quietly gotten into a real supplier's mailbox replies inside a genuine, ongoing thread and changes only the account number. There is no bad link, no strange attachment, and often no spelling mistake, so spam filters wave it through. Because the email looks perfect, the only reliable defense is process: treat every change to payment details as unverified until you confirm it on a channel you already trusted.
The login prompt you did not start
Multi-factor authentication stops most stolen passwords cold, so attackers built a workaround called MFA fatigue. They already have your password from some unrelated leak, and they trigger the login over and over, hoping the flood of approval prompts on your phone wears you down until you tap "approve" just to make it stop.
The rule is simple and absolute: never approve a login prompt you did not personally start. If prompts you did not trigger keep arriving, that is not a glitch. It is a signal that your password has leaked and someone is standing at the door with it. Deny the prompt, change that password immediately, and tell whoever runs your systems.
When you are not sure, verify on a second channel
This single habit prevents most successful attacks. If a message asks you to move money, change payment details, share a password, or approve a login, confirm it using a contact method you already had, not one supplied by the message itself. Call the phone number you have on file, walk over to the person's desk, or message them in the tool your team already uses.
The trap to avoid: replying to the suspicious email to ask "is this really you?" If it is a fake, the attacker is the one who answers, and they will happily confirm. A second channel means a genuinely separate path to a person you can trust.
If someone already clicked
Speed matters far more than blame. The employee who reports a mistake right away is saving you money, and a team that punishes honesty just teaches people to hide the click until it is too late. If something has gone wrong, move fast and stay calm.
- If a password was entered on a fake page, change it right away from a different, trusted device, and change it anywhere else that same password was reused.
- Keep or turn on multi-factor authentication on the affected account, and sign out all active sessions so a stolen session cannot linger.
- If money moved or a payment was redirected, call your bank immediately. Fast reporting is sometimes the only way funds get recovered.
- If an attachment was opened and a device is acting strangely, disconnect it from the network and get it checked before the problem spreads.
- Report the email using your mail app's "report phishing" button, then warn the rest of the team, because phishing arrives in waves and you are rarely the only target.
Make it a team habit, not a memo
Awareness that lives in a policy no one reopens does nothing. Awareness that lives as a shared reflex stops real attacks. Pick one rule small enough that everyone actually remembers it, and repeat it until it is muscle memory: slow down on anything about money or passwords, and verify on a second channel before acting.
Build a culture where checking is the norm and asking is a win. The person who forwards a suspicious email and asks "is this real?" should get a thumbs up, never a sigh. Phishing awareness is one line item in a short list of cheap protections. The rest are in our guide to small business cybersecurity: the protections that matter first.
- One rule everyone can recite: no money moves and no password changes on the strength of an email alone.
- A known way to report a suspicious message in seconds, so reporting is easier than ignoring.
- Permission to be wrong. A false alarm costs a couple of minutes; a real click can cost a great deal more.
What we do here at Alpha Momin
Cutting off phishing is part of our IT and admin support. We tighten the technical side so fewer fakes reach anyone: email authentication with SPF, DKIM, and a strict DMARC policy so your domain is harder to spoof, plus multi-factor authentication enforced across the team. Then we set up the human side that filters miss: a quick way to report suspicious mail, a short awareness habit your people will actually keep, and a one-page plan for the day someone clicks. We do it once, write it in plain English, and review it after. It will not make anyone unphishable, and we will not pretend it does, but it turns a wide-open door into a narrow, watched one.
This post is general guidance, not a security assessment. Attackers change their tactics constantly, and every business has its own systems and risks; matching these habits to yours is what the discovery call is for.
Frequently asked
How can I tell if an email is really from who it claims to be?
Read the actual sender address rather than the friendly display name, since the name is trivial to fake while the address is harder to hide. Hover over any link to see its true destination, and watch for look-alike domains where a letter or an ending has been swapped. For anything involving money, passwords, or a change to payment details, do not judge by the email alone; confirm it with the person on a phone number or channel you already had.
What is business email compromise, and why do small firms fall for it?
Business email compromise is a scam where an attacker impersonates a boss, supplier, or client to redirect a legitimate payment into their own account. It often carries no link and no attachment, which is exactly why spam filters miss it and people trust it. The most convincing version comes from inside a real, hijacked mailbox, replying in a genuine thread and changing only the bank details. The defense is a firm rule: verify any change to where money goes on a separate, trusted channel before you pay.
What should I do if I clicked a phishing link or entered my password?
Act fast and skip the self-blame, because speed is what limits the damage. Change the exposed password immediately from a different, trusted device, and change it anywhere you reused it. Keep multi-factor authentication on and sign out all active sessions, then tell whoever runs your systems and warn your team. If any money moved or a payment was redirected, call your bank right away, since quick reporting is sometimes the only path to getting funds back.
If we already use multi-factor authentication, do we still need to worry about phishing?
Yes, because multi-factor authentication reduces the risk a great deal but does not remove it. Attackers respond with MFA-fatigue prompts that spam your phone hoping you tap approve, and with fake login pages that relay your code in real time. The habits still matter: never approve a login prompt you did not start, treat repeated prompts as a sign your password has leaked, and verify money-related requests on a second channel. Report the suspicious prompt so the pattern gets caught early.
Want your whole team to catch the fake?
Tell us what your team uses for email and where it feels exposed. We will set up email authentication and a short awareness habit so a convincing fake gets caught before it costs you a thing.