An email lands in your inbox. It's from your bank. There's a problem with your account, and if you don't verify your details in the next 24 hours, it gets frozen. There's a button. You're busy, it looks legit, you click.
That's phishing. And that exact moment, busy person plus plausible email plus one click, is how most small businesses get hacked. Not by a hoodie genius punching through a firewall. By an email that looked right.
What phishing actually is
Phishing is someone pretending to be a person or company you trust, to trick you into handing over something valuable, usually a password, a payment, or access to your computer.
The name is exactly what it sounds like. They throw out bait and wait for a bite. The bait shows up three main ways:
- Email. The classic. Fake messages from "your bank," "Microsoft," "UPS," or, the crowd favorite, "your boss."
- Text messages. "Your package couldn't be delivered, click here." (There's a nerdy name for this one, smishing, which you are free to forget immediately.)
- Phone calls. Someone from your bank's "fraud department," or "Microsoft support" calling because they nobly noticed a problem with your computer. They did not.
Why small businesses are the favorite target
Big companies have security teams, email filters, and training programs. You have you, and possibly a nephew who's "good with computers." Attackers know that. They also know something better: small businesses move money on trust. When the "owner" emails the bookkeeper to pay an invoice, the bookkeeper usually just... pays it.
One version is aimed right at businesses like yours. An email that looks like it's from the owner, that's you, lands with whoever handles the money, asking for an urgent wire or a quick change to a vendor's bank details. It's called business email compromise, and it costs companies billions a year. Not millions. Billions, with a B.
The five red flags
Nearly every phishing attempt trips at least one of these:
-
Urgency. "Within 24 hours." "Immediately." "Your account will be suspended." Real companies almost never demand instant action over email. Panic is the whole tool. A panicked person doesn't stop to check.
-
The sender address is a little off. The name says "Chase Bank." The actual address is chase-security@alerts-verify.net, which is not a place Chase has ever sent anything from. Tap or hover on the sender to see the real address. Not the company's normal domain? Fake.
-
It wants you to log in or "verify" through their link. Real companies don't email you a link to type your password into. When in doubt, don't click. Go to the website yourself, the normal way, and log in there.
-
Money is suddenly moving in a new way. New bank details for a vendor. A surprise wire. Gift cards (yes, still, "grab $500 in gift cards for a client and send me the codes" is somehow undefeated). Any change to how money moves earns a phone call first.
-
Something's just... off. A weird greeting, phrasing that doesn't sound like the person, a tone that's slightly wrong. Modern scams are well-written, so don't count on typos. But do trust your gut when a message feels off. Your gut is a security tool.
What to actually do
For you, starting today:
- Slow down on anything touching money, passwords, or urgency. The 30 seconds it takes to check a sender address is the entire game.
- Never log in through an emailed link. Go to the site directly.
- Turn on multi-factor authentication everywhere, starting with email. Even if you get fooled and your password walks out the door, MFA usually stops the attacker cold at the next step.
For your team, this week:
- Make one rule and make it sacred: any request to move money or change bank details gets verified by phone, using a number you already have, not one from the email.
- Tell your team, out loud, that they will never be in trouble for double-checking a request that looks like it came from you. The scam runs on people being afraid to question the boss.
- Forward this post to whoever handles your invoices. Genuinely. They're the number one target in the building.
If someone already clicked:
Change that password immediately, turn on MFA, and watch the account for anything weird. If money moved, call your bank right now, today, because banks can sometimes claw back a wire if you move within hours. Then breathe. This happens to sharp people every single day.
The bottom line
Phishing isn't a technology problem, it's a trust problem. The fix isn't fancy software. It's a 30-second pause before you click, plus one unbreakable rule: money requests get confirmed by phone.
Want a printable checklist your team can keep at their desk? Grab the free Small Business Security Quick-Check.