Phishing emails remain one of the most common ways cybercriminals get into a business. According to the FBI’s 2025 Internet Crime Report, the Internet Crime Complaint Center received 191,561 phishing and spoofing complaints in 2025. The same report shows 24,768 business email compromise complaints, with reported losses of more than $3 billion.
For a small or mid-sized business, one successful phishing email can mean a stolen password, a fraudulent wire transfer, or malware spreading across your network. The good news is that most phishing emails share warning signs, and your team can learn to spot them. In this post, we’ll cover what a phishing email is, why they’re harder to catch than they used to be, the red flags to look for, and what to do when one lands in your inbox.
Key Takeaways
- Phishing and spoofing were among the most reported cybercrimes in 2025, according to the FBI.
- AI-written phishing emails often have no typos, so focus on what the message asks you to do.
- Red flags include lookalike sender addresses, urgency, payment or banking changes, and unexpected links, attachments, or QR codes.
- If you clicked, tell IT right away and change your password. Speed matters more than blame.
What Is a Phishing Email?
A phishing email is a message designed to trick the recipient into doing something that helps an attacker. That might mean clicking a link to a fake login page, opening an attachment that installs malware, sharing sensitive information, or sending money.
Phishing emails usually pretend to come from someone you trust. Common disguises include banks, software providers like Microsoft, shipping companies, government agencies, vendors you work with, and even your own coworkers or boss. The goal is to make the request feel routine enough that you act before you think.
Phishing is only one type of attack. If you want to understand the full picture, including spear phishing, whaling, and voice scams, see our guide to the types of phishing attacks.
Why Phishing Emails Are Harder to Spot Today
For years, the standard advice was to look for bad spelling and awkward grammar. That still helps with some messages, but it’s no longer enough.
Attackers now use AI tools to write clean, professional emails that read like they came from a real person. They can copy a company’s logo and email layout in minutes. Some phishing emails are sent from real accounts that have already been hacked, so the sender address looks exactly right.
That’s why it helps to look at what a message asks you to do, not just how it looks. Our post on AI cybersecurity threats goes deeper into how attackers are using these tools.
10 Warning Signs of a Phishing Email
No single sign proves an email is a scam, but the more of these you see, the more careful you should be.
- The sender’s address doesn’t quite match. Look past the display name to the actual email address. Attackers use lookalike domains, such as swapping a letter, adding a word, or using a different ending, so the address looks right at a glance.
- The display name is familiar, but the address isn’t. An email may show your CEO’s name while coming from a personal Gmail account or an unfamiliar domain.
- The message creates urgency or fear. Phrases like “act now,” “your account will be suspended,” or “final notice” are designed to rush you past your better judgment.
- It asks for login credentials or personal information. Legitimate companies rarely ask you to confirm a password or share sensitive details by email.
- It requests a payment, a gift card purchase, or a change in banking details. Requests to wire money, buy gift cards, or update a vendor’s bank account are common in business email compromise scams.
- The link doesn’t go where it says. Hover over a link before you click. If the web address that appears doesn’t match the company it claims to be, don’t click.
- There’s an unexpected attachment. Be cautious with attachments you weren’t expecting, especially invoices, shipping notices, or files that ask you to enable macros or “enable content.”
- It includes a QR code asking you to log in or verify something. QR codes can hide a malicious link, and scanning one with your phone moves the attack to a device that may be less protected.
- The greeting or tone feels off. A generic greeting like “Dear Customer,” or a coworker writing in a way that doesn’t sound like them, can be a clue.
- It asks you to keep it quiet or skip normal steps. Messages that say “keep this between us” or “don’t call, I’m in a meeting” are trying to stop you from verifying the request.
Example of a Phishing Email
Here’s an example of what a business-targeted phishing email might look like.
Hello,
Due to a recent change with our bank, please update our payment details before processing this week’s invoice. The new account information is in the attached form. Payments sent to the old account after today may be delayed.
Please confirm once updated. I’m traveling this week, so email is the best way to reach me.
Thank you,
Accounts Receivable Team
Sample phishing email for illustration only. Not a real message.
Several red flags appear in this one message. The sender’s domain isn’t the vendor’s real domain. It asks for a change in banking details, adds a deadline, includes an unexpected attachment, and discourages you from calling to confirm. Any one of those is worth a second look. Together, they point strongly to a scam.
What to Do If You Receive a Phishing Email
If an email looks suspicious, slow down and follow a few simple steps.
- Don’t click links, open attachments, or reply. Replying confirms your address is active.
- Verify through a separate channel. Call the person or company using a phone number you already have, not one listed in the email.
- Report it. Use your email program’s report button or forward it to your IT team, so they can block similar messages for everyone.
- Delete it once it’s reported.
If You Already Clicked
Mistakes happen, and speed matters more than blame. If you clicked a link, entered a password, or opened an attachment:
- Tell your IT team or IT provider right away.
- Change the password for any account you may have exposed, and make sure multi-factor authentication is turned on.
- Disconnect the device from the network if your IT team tells you to.
- If money was sent, contact your bank immediately.
For a broader plan, see our guide on what to do after a cyberattack.
How to Protect Your Business from Phishing Emails
Spotting phishing emails is a skill, but your business shouldn’t depend on every employee getting it right every time. A few layers of protection work together.
- Security awareness training. Regular, practical training helps your team recognize phishing emails and feel comfortable reporting them. Our post on building employee security training covers how to make training stick.
- Email filtering. Good email security catches many phishing emails before they ever reach an inbox.
- Multi-factor authentication. If a password is stolen, multi-factor authentication adds a second step that makes it much harder for an attacker to log in.
- Verification rules for payments. Require a phone call to a known number before changing vendor bank details or sending a wire transfer. This one habit can stop many business email compromise scams.
- Up-to-date devices and software. Updates close security gaps that malicious attachments and links try to exploit.
Phishing doesn’t only arrive by email. Attackers also use text messages, phone calls, and social media. Learn more in our posts on phishing text messages and phishing and social engineering. For a complete plan, start with our guide to small business cybersecurity.
How Courant Helps
At Courant, we help businesses across Greater New Orleans reduce the risk of phishing with layered protection, including email filtering, multi-factor authentication, security awareness training, and responsive help desk support when something looks suspicious. Your team gets a partner to call before they click, and help right away if something goes wrong.
Frequently Asked Questions
What is the most common sign of a phishing email?
There isn’t just one, but urgency is one of the most common. Phishing emails often pressure you to act quickly, such as resetting a password, paying an invoice, or confirming account details, before you have time to think.
Can a phishing email come from someone I know?
Yes. Attackers can spoof a familiar name or send messages from a real account they’ve already compromised. If a request is unusual, verify it with the person directly using a phone number you already have.
Is it dangerous to open a phishing email?
Opening the email is usually low risk. The danger comes from clicking links, opening attachments, scanning QR codes, or replying. If you’re unsure, don’t interact with it and report it to your IT team.
What should I do if I clicked a link in a phishing email?
Contact your IT team or IT provider right away, change any password you may have entered, and make sure multi-factor authentication is turned on. Acting quickly limits the damage.
How can a small business reduce phishing risk?
Combine employee training with technical protections like email filtering, multi-factor authentication, and clear rules for verifying payment requests. Layers of protection mean one mistake is less likely to become a major incident.
Stop Phishing Emails Before They Cost You
Phishing emails are designed to catch busy people off guard. With the right training and protections in place, your team can spot them sooner and report them with confidence.
Schedule a 15-minute consultation to talk about how well your business is protected against phishing emails, or contact us to learn how Courant can help your team stay one step ahead.
Image generated with Gemini Nano Banana.



