Phishing Emails: How Small Businesses Can Spot and Stop Scams

A practical phishing guide covering fake login pages, supplier impersonation, payment fraud, suspicious links and staff reporting.

Cyber Security Basics · Lesson 3 of 10

Quick answer: A practical phishing guide covering fake login pages, supplier impersonation, payment fraud, suspicious links and staff reporting.

Phishing is the use of fake emails, messages, websites or calls to trick somebody into revealing information, signing in to a fraudulent page, opening a malicious file or making a payment. It remains one of the most important cyber risks for small businesses because it targets normal business processes.

Why phishing works

Modern phishing messages can copy real branding, signatures, suppliers and services. Attackers also use public information from websites and social media to make messages more convincing. The objective is usually to create enough urgency or familiarity that the recipient acts before checking.

Common phishing scenarios

  • A fake Microsoft 365 password expiry or document-share notification.
  • A supplier asking for bank details to be changed.
  • A director requesting an urgent transfer or gift-card purchase.
  • A courier or invoice attachment containing malware.
  • A fake account security alert leading to a copied login page.

Check the sender, not just the display name

Email applications prominently show a display name, but this can be misleading. Expand the sender details and check the full address. Look for spelling changes, unexpected domains and unusual reply-to addresses.

Be cautious with urgent requests

Phishing often uses pressure: “pay today”, “your account will be closed”, or “I am in a meeting, do this now”. Urgency should increase verification rather than reduce it.

Verify payment changes independently

Never accept a supplier bank-detail change from email alone. Use a trusted phone number already held by the business, or another independently verified communication route. Do not rely on the contact details contained in the message being checked.

Avoid signing in through unexpected links

If a message says there is a problem with Microsoft 365, your bank or another important service, open the service independently using a known bookmark or by typing the address yourself. A realistic-looking sign-in page can still be fraudulent.

Create a no-blame reporting process

Employees must be able to report a suspicious message or accidental click quickly. Delayed reporting gives an attacker more time to abuse a stolen password or mailbox. The business should make it clear who receives reports and what happens next.

What to do after this lesson

Agree one rule for your finance process today: bank-detail changes and unusual payment instructions must be independently verified before money is sent.

Frequently asked questions

What is the biggest warning sign of a phishing email?

There is no single reliable sign. Unexpected urgency, unusual sender addresses, login links, attachments and payment changes should all trigger verification.

What should I do if I clicked a phishing link?

Stop, report it immediately and follow your incident process. If you entered credentials, the account should be treated as potentially compromised and investigated promptly.

Can a phishing email look exactly like a real Microsoft email?

Yes. Branding and layout can be copied, which is why the sender, destination link and context of the request matter.

Useful UK guidance

Put the lesson into practice

39Security helps small businesses turn cyber security guidance into practical controls and owned actions.

Course overview ← Previous lesson Next lesson →