Phishing is how most small business break ins start. Not a hacker in a hoodie, just a convincing email that gets somebody in the office to type a password into the wrong box. The emails have gotten good, but they still leave the same fingerprints, and once you know what to look for you will see them instantly.
1. Look at the Actual Sender Address #
The display name in your inbox is free text. Anyone can put “Microsoft Support” or your own bank’s name there. What matters is the address behind it.
Click or tap the name to reveal the real address and read the domain, the part after the @. Read it right to left. Scammers register lookalikes: micros0ft-billing.com, yourbank.secure-login.net, or a real company name buried inside a domain that is not theirs. If the domain is not exactly the company’s real domain, delete the message.
2. Hover the Link Before You Click It #
On a computer, hold your mouse over the link without clicking and the true destination appears at the bottom of the window. On a phone, press and hold to preview it.
The visible text and the actual link do not have to match, and in a phishing email they never do. If the button says “Verify your account” and the link goes somewhere unrelated, that is your answer. When in doubt, do not click anything in the email. Open a new tab and type the company’s address yourself.
3. Urgency Is the Tell #
Your account will be closed in 24 hours. Your payment failed. Suspicious login detected. Legal action pending. Every one of these is engineered to get you moving before you think.
Real companies do not usually threaten to delete your account by tomorrow over email. When a message makes your stomach drop, that feeling is the product. Slow down, put the phone down, and check through a channel you already trust.
4. Nobody Legitimate Asks You for Your Password #
Not your bank, not your web host, not Microsoft, not your accountant, not your IT support. Not by email, not by text, not on a phone call you did not initiate. Same goes for the six digit code from your authenticator app. That code is the last thing standing between an attacker and your account, and a shocking number of break ins happen because somebody read it out loud to a caller.
If anyone asks for either one, that is the end of the conversation.
5. Unexpected Attachments #
An invoice you were not expecting. A shipping notice for a package you did not order. A resume when you are not hiring. A voicemail delivered as a file.
Be especially careful with anything that wants you to “enable content” or “enable macros” to view it. That prompt exists to run code on your machine. A document that needs you to disable a security feature to read it is not a document.
6. The Invoice Scam That Targets Businesses #
This one is aimed squarely at you. A supplier you really do work with emails to say their bank details have changed, please send the next payment to this new account. It comes from an address that looks almost right, and often it references a real invoice, because the attacker has been reading someone’s mailbox.
The rule that stops it cold: never change payment details based on an email. Call the supplier on the number you already had on file, not the number in the message, and confirm out loud. Make that a written policy for anyone in your business who can send money.
7. If You Already Clicked #
Do not panic and do not hide it. Speed matters more than embarrassment.
- If you entered a password, change it right now on the real site, and change it anywhere else you used the same one.
- Turn on two factor authentication on that account if it is not on already.
- Sign out all other sessions and review the account’s recent activity and any rules or forwarding addresses that have been added to your email.
- If it was a work machine, disconnect it from the network and tell whoever handles your IT.
- If money moved, call your bank immediately. Fast reporting is sometimes the difference between recovering it and not.
Then tell your team what happened. The email that fooled you is almost certainly sitting in their inbox too.
Wrapping It Up #
Check the sender’s real domain. Hover the link. Distrust urgency. Never hand over a password or a login code. Never change bank details on the strength of an email. Those five habits stop nearly everything that will be aimed at your business.
If you want your email, your website logins, and your team’s accounts locked down properly, Valla Hub can review your setup and close the obvious doors.
Get the next article by email
Plain, practical web advice for small business owners, from the team at Valla Hub. Unsubscribe any time.
