Phishing is Rampant, Don’t Take the Bait!

by | Cybersecurity

Phishing is the most common and most successful tactic of bad actors looking to cause mischief with your small business. An astonishing 91% of data breaches start with a phishing attack. Phishing is a sneaky method to lure you into disclosing your login/password credentials or financial data or downloading malware or other malicious software. The best line of defense to protect your business is constant vigilance and regular security awareness training. Check out this practical advice on how to spot, block, and report phishing attempts.

Article shared from The National Cybersecurity Alliance:

Fortunately, it’s easy to avoid a scam email, but only once you know what to look for. With some knowledge, you can outsmart the phishers every day.  

See it so you don’t click it.

The signs can be subtle, but once you recognize a phishing attempt you can avoid falling for it. Before clicking any links or downloading attachments, take a few seconds (like literally 4 seconds) and ensure the email looks legit. Here are some quick tips on how to clearly spot a phishing email:  

  • Does it contain an offer that’s too good to be true?  
  • Does it include language that’s urgent, alarming, or threatening?  
  • Is it poorly crafted writing riddled with misspellings and bad grammar? 
  • Is the greeting ambiguous or very generic?  
  • Does it include requests to send personal information? 
  • Does it stress an urgency to click on an unfamiliar hyperlinks or attachment? 
  • Is it a strange or abrupt business request? 
  • Does the sender’s e-mail address match the company it’s coming from? Look for little misspellings like pavpal.com or anazon.com. 
Uh oh! I see a phishing email. What do I do? 

Don’t worry, you’ve already done the hard part, which is recognizing that an email is fake and part of a criminal’s phishing expedition.  

If you’re at the office and the email came to your work email address, report it to your IT manager or security officer as quickly as possible.  

If the email came to your personal email address, don’t do what it says. Do not click on any links – even the unsubscribe link – or reply back to the email. Just use that delete button. Remember, DON’T CLICK ON LINKS, JUST DELETE.  

You can take your protection a step further and block the sending address from your email program. 

Here’s how to… 

Report phishing. 

Some email platforms let you report phishing attempts. If you suspect an email is phishing for your information, it’s best to report it quickly. If the phishing message came to your work email, let your IT department know about the situation ASAP. 

Here’s how to:

Need help updating your employees with security awareness training? We can help! Learn more about our partnership with Bullphish, a platform that helps you identify vulnerable employee activity with simulations and provides security training on current threat trends.

5 IT Upgrades to Prioritize in 2025

5 IT Upgrades to Prioritize in 2025

Technology moves fast—too fast sometimes! If your business is hanging onto outdated systems or skipping critical upgrades, you could be missing out on efficiency, security, and growth. Worse yet, old tech could put you at risk for costly downtime or cyberattacks. Here...

read more
Protect Your Business During The Holidays

Protect Your Business During The Holidays

The holiday season is full of cheer—but for cybercriminals, it's also a time of opportunity. With businesses closing for extended periods and employees distracted by festivities, it's prime time for hackers to strike. Whether your company is shutting down for the...

read more

Let's chat about how we can help.

Call us at 636.949.8850, grab a spot on our calendar, or fill out this form and we will reach out to you.

  • This field is for validation purposes and should be left unchanged.