How to spot a phishing email aimed at your business
The phishing that costs small businesses real money is not the badly spelled prince. It is a well-written invoice from a supplier you actually use. Here is what to look for and the one habit that beats every checklist.
Everyone knows the badly spelled email from a stranded prince. That is not the one that costs businesses money. The expensive kind is well written, mentions a supplier you genuinely use, arrives during business hours, and asks for something that sounds completely routine.
The one that takes the most money
Invoice and vendor payment fraud. It usually reads something like this:
Hi, quick note that we have changed banks. Please use the updated account details below for this month’s invoice. Sorry for the hassle.
It works because nothing about it is alarming. Vendors do change banks. The email looks like the vendor’s normal email, sometimes because the attacker has been reading a compromised mailbox for weeks and knows exactly how they write and what they are owed.
The variants all share a shape:
- The owner is travelling and needs gift cards or an urgent transfer, right now, and cannot take a call.
- Payroll asks to update someone’s direct deposit details.
- A shared document needs you to sign in again to view it, on a login page that looks perfect.
The tells
- A change of routine. New account number, new address, new process. Fraud almost always needs something to change.
- Pressure plus payment. Urgency exists to stop you checking. Real vendors survive a phone call.
- A lookalike domain.
shastatech-services.cominstead ofshastatechservices.com, or a capital I standing in for a lowercase l. Read the part after the @ character by character. - Reply-To does not match From. The message shows the real vendor, but your reply goes somewhere else. Most mail apps hide this until you expand the header.
- A link whose text and destination disagree. Hover over it, or long-press on a phone, and read where it actually goes before you tap.
- Attachments you did not expect, especially anything asking you to enable content or macros.
The habit that beats the checklist
Verify out of band.
If an email asks you to move money or change payment details, pick up the phone and call the vendor on the number you already had for them. Not the number in the email. Not by replying to the email. Thirty seconds on a line the attacker does not control defeats essentially all of this, and no legitimate supplier has ever been offended by the call.
Make it a standing rule rather than a judgment call, so nobody has to feel awkward about following it and nobody has to be the person who decided this particular email looked fine.
If someone already clicked
Move fast, and skip the blame. The first hour matters more than anything else.
- Change the password for that account, and anywhere else the same password was used.
- Turn on two-factor authentication if it was not already on.
- Call the bank immediately if money moved. Wire recalls are sometimes possible, but the window is hours, not days.
- Check the mailbox for new forwarding rules. Attackers commonly add a quiet rule that copies incoming mail to themselves, and it survives a password change.
- Tell your team what happened. The same message usually went to several people.
Getting caught by one of these does not mean somebody was careless. They are designed by people who do this full time, against people who are busy running a business.
Want a second opinion on an email that feels off, or help tightening up your accounts? Get in touch.