How your team can spot phishing and scam emails
Most attacks on small businesses start with a message that looks normal enough to click. Filters catch a lot, but not everything. A team that knows the warning signs, and knows what to do next, is one of your strongest defenses.
Common warning signs
- Urgency or pressure: "Your account will be closed today" or "Pay this before 3 p.m."
- A sender that doesn't quite match: a familiar name with an unfamiliar email address, or a domain with a small misspelling.
- Unexpected attachments or links, especially invoices, shared documents or voicemail notices you weren't expecting.
- Requests to change payment details, or to buy gift cards.
- A sign-in page asking for your email password after you click a link.
Scams that target small businesses
Payment-change fraud
A message appears to come from a vendor, client or executive asking to update bank details or send an urgent payment. Sometimes the attacker is writing from a real, compromised account. Always confirm payment changes by phone, using a number you already have rather than one in the email.
Fake sign-in pages
An email about a shared file or full mailbox leads to a page that looks like Microsoft 365. Entering your password hands it to the attacker. Multifactor sign-in stops many of these attempts from succeeding.
Fake tax and government notices
The IRS says it does not start contact with taxpayers by email, text message or social media to ask for personal or financial information. Treat messages like that as scams, especially around tax season.
Delivery and disaster scams
Fake shipping notices are common year-round. In South Florida, scams also spike after storms, pretending to come from insurers, disaster agencies or charities.
What to do when something looks wrong
- Don't click, reply or open attachments.
- Verify through another channel, such as a phone number you already trust.
- Report it to whoever handles your IT, so they can block it and warn others.
- If you already clicked or entered a password, say so immediately. Changing the password and checking the account quickly limits the damage. Nobody should be afraid to report a mistake.
Make phishing harder to succeed
- Turn on multifactor sign-in for email and remote access.
- Use email filtering that flags outside senders and known threats.
- Adopt a simple rule: all payment and banking changes are verified by phone.
- Give staff short, practical refreshers during the year, not once-a-year lectures.
Check your basics with our free IT risk self-check.
We combine email protection, secure sign-in and practical guidance for staff.
Cybersecurity services