Red flags that show up again and again
- Urgent language — “your account will be closed in 24 hours” or “unusual sign-in attempt”
- Sender address that almost matches a real company but is slightly wrong
- Links that go somewhere different from the text when you hover (on desktop)
- Attachments you did not expect—especially invoices, shipping notices, or “voice message” files
- Requests for passwords, gift cards, or wire transfers by email
What to do when something looks suspicious
- Do not click links or open attachments—contact the company through their real website or phone number instead.
- Report it to your IT person or mark as phishing in your email program.
- If you already clicked, disconnect from Wi-Fi, call for help, and change passwords from a clean device.
- Turn on multi-factor authentication on email and banking—it blocks most stolen-password attacks.
How I help businesses stay ahead of it
I train staff with real examples, tighten email filtering, and set up backups and access controls so one bad click does not take down the whole operation. You do not need a lecture—just clear habits and systems that match how your team actually works.