A practical guide for Brooklyn small businesses on recognizing phishing emails before someone clicks
Phishing is the most common way small businesses get hacked — not through some sophisticated break-in, but through a single convincing email that tricks a busy person into clicking a link, entering a password, or paying a fake invoice. The emails have gotten good: clean logos, real names, and urgent-sounding requests that look like they came from your bank, a vendor, Microsoft, or even your own boss.
The best defense isn’t expensive software — it’s knowing what to look for. Once you and your team can recognize the warning signs, most phishing attempts fall apart. This guide walks through exactly how to spot a phishing email and what to do when one lands in your inbox.
Why Phishing Works So Well
Phishing succeeds because it targets people, not computers. A scammer doesn’t need to break your security if they can convince an employee to hand over a password or approve a payment. They rely on urgency (“your account will be closed”), authority (“this is the CEO”), and routine (“here’s the invoice”) to get a quick click before anyone stops to think.
That’s why even businesses with good software still get caught — the technology can filter a lot, but the final decision usually comes down to a person reading an email on a busy afternoon.
The Warning Signs of a Phishing Email
Most phishing emails give themselves away if you know where to look. Here are the signs worth training yourself and your team to catch.
| Warning sign | What to look for |
|---|---|
| Urgency or threats | “Act now,” “account will be suspended,” “final notice” — pressure designed to stop you thinking |
| Wrong sender address | A display name that looks right but an email address that’s slightly off (support@micros0ft-billing.com) |
| Login or payment links | Asks you to “verify,” “sign in,” or “update payment” through a link instead of going to the site yourself |
| Mismatched links | The visible link text and the real destination (shown when you hover over it) don’t match |
| Unexpected attachments | Invoices, receipts, or “documents” you weren’t expecting, especially ZIP or unusual file types |
| Odd wording | Awkward grammar, generic greetings (“Dear customer”), or a tone that doesn’t match the real sender |
| Requests for secrecy or speed | “Handle this quietly,” “I’m in a meeting, just do it” — classic in CEO/vendor fraud |
You rarely need all of these — even one or two should make you pause and verify before acting.
The Trickiest One: Business Email Compromise
The most costly phishing for small businesses isn’t the obvious spam — it’s the targeted request that looks completely normal. An email that appears to be from the owner asking an employee to buy gift cards or send a wire. A “vendor” emailing new banking details for their next payment. These have no bad links or attachments at all, which is exactly why they slip through.
The defense is a simple habit: any request to move money or change payment details gets verified through a second channel — a phone call to a known number, or in person — before it’s acted on. No exceptions, even when the email seems to come from the boss.
What to Do If You Get a Phishing Email
If an email looks suspicious and you haven’t clicked:
- Don’t click links, open attachments, or reply
- Don’t unsubscribe — for scam email, that just confirms your address is active
- Report it (most email systems have a “Report phishing” button) and delete it
- If it claims to be from a company you use, contact them through their real website or phone number to check
If someone already clicked or entered a password:
- Change that password immediately from a device you trust, and turn on multi-factor authentication
- Change the same password anywhere else it was used
- Watch for unexpected sign-ins, sent emails, or mailbox forwarding rules
- If money or customer data may be involved, get help right away and pair it with virus and malware removal if a device may be infected
How to Protect Your Business From Phishing
You can’t stop scammers from sending emails, but you can make them far less likely to succeed:
- Turn on multi-factor authentication everywhere — even a stolen password won’t get them in
- Train your team to recognize the signs above and to verify money requests through a second channel
- Use spam and malware filtering so fewer phishing emails reach the inbox at all
- Keep good data backups so a phishing-delivered ransomware attack doesn’t cost you your files
- Run reliable internet security and antivirus software on every business computer
How Secure IT Global Helps
Secure IT Global helps small businesses reduce their exposure to phishing and clean up quickly when something slips through. We can help set up multi-factor authentication and email filtering, secure and recover an account after a suspected compromise, and remove malware from an affected device. Phishing protection fits naturally into ongoing managed IT support or a monthly support plan, and most issues can be handled through remote tech support. It’s one of the common technology problems small businesses face — and one of the most preventable.
Frequently Asked Questions
How can I tell if an email is really from who it says?
Check the actual email address, not just the display name — scammers often use a name you recognize with an address that’s slightly wrong. Hover over any link to see where it really goes before clicking. And if the email asks you to log in, pay, or change details, go to the company’s real website or call a known number instead of using anything in the email.
What should I do if I clicked a phishing link?
Change the password for any account you may have entered, from a device you trust, and turn on multi-factor authentication. Change that password anywhere else you used it. Watch for unexpected sign-ins or emails sent from your account, and check for mailbox forwarding rules an attacker may have added. If money or customer data may be involved, get help right away.
What is business email compromise (BEC)?
It’s a targeted scam where an attacker impersonates an owner, manager, or vendor to trick staff into sending money or changing payment details. These emails often have no bad links or attachments, which is why they slip past filters. The best defense is a rule that any money movement or payment change is verified through a second channel, like a phone call to a known number.
Will antivirus or spam filters stop all phishing?
They stop a lot, but not everything — especially targeted emails with no malicious links or attachments. Filtering is an important layer, but the final defense is a trained person who knows the warning signs and verifies suspicious requests. Combining good filtering, multi-factor authentication, and staff awareness is what actually works.
Should I reply to ask if an email is real?
No. Replying, or clicking “unsubscribe” on a scam email, just confirms your address is active and monitored. Instead, verify through a separate channel — the company’s real website or a phone number you already have — and report the email using your email system’s report-phishing button.
Worried your team might fall for a phishing email?
Call or text us to set up multi-factor authentication, email filtering, and simple protections that stop most phishing attacks.
Call 718-354-8420
Support: 888-902-2303
Secure IT Global · 3603 Ave S, Brooklyn, NY 11234 · secureitglobal.com

