Phishing emails pretend to be from someone you trust — your bank, Microsoft, Canada Post, a supplier, even your own boss — to get you to click a link, open an attachment or send money. They are the most common way small businesses get hacked.
The 30-second check
- Look at the real sender address, not just the display name. "Microsoft Support" sending from a random Gmail address is a red flag.
- Hover over links before clicking. If the address that appears doesn't match the company's real website, don't click.
- Watch for urgency. "Your account will be closed today", "Payment overdue", "Final notice" — pressure is the scammer's main tool.
- Be suspicious of unexpected attachments, especially invoices, shipping notices or "scanned documents" you weren't expecting.
- Never change payment details by email alone. If a supplier says their bank account changed, call them on a number you already have.
What to do if you clicked
Don't panic, and don't ignore it. Change the password for the account involved right away, turn on multi-factor authentication if it isn't already, and contact us. The sooner we look, the less damage is possible.
Protecting your whole team
Good email filtering, multi-factor authentication and short, regular staff training stop most phishing before it becomes a problem. We set all three up for businesses across Huron County.