Phishing & Business Email Compromise

MODULE 01 / FOUNDATIONAL12 min / Includes knowledge checks and quiz

Phishing & Business Email Compromise

Phishing is the number one way attackers target small organizations. Learn to spot phishing emails, recognize business email compromise, and respond with confidence.

A professional at a desk looking thoughtfully at a suspicious email on their laptop screen

What You Will Learn

Phishing is the number one way attackers target small organizations. This module teaches you how to spot phishing emails, what business email compromise (BEC) looks like, and exactly what to do when a suspicious email lands in your inbox.

  • Phishing basics: what it is and why it works
  • Red flags: how to spot a phishing email in 10 seconds
  • Business Email Compromise (BEC): the costliest threat to small organizations
  • Spear phishing: targeted attacks that feel personal
  • What to do: your step-by-step response when you suspect phishing

Why Phishing Matters for Your Organization

Phishing is not a nuisance. It is the entry point for most cyberattacks. According to industry research, over 90% of data breaches start with a phishing email. For regulated organizations in healthcare, legal, nonprofit, and education sectors, a single clicked link can expose patient records, client files, donor data, or student information.

The good news: phishing is preventable. When your team knows what to look for, they become your strongest security control, not your weakest link.

Quick Check

An email arrives from your bank asking you to verify your password by clicking a link. The email looks official with the bank logo. What should you do?

A) Click the link and verify your password since it has the bank logo
B) Forward it to your IT team or use the Report Phishing button, then delete it
C) Reply asking if the email is legitimate
D) Ignore it but do not report it

How to Spot a Phishing Email in 10 Seconds

Train yourself to scan every email for these five red flags before you click anything:

5 Red Flags of Phishing

  • 1. Urgency or fear: The email pressures you to act immediately. Phrases like your account will be closed or payment overdue are designed to make you panic and click without thinking.
  • 2. Mismatched sender address: The display name says your CEO but the email address is a random Gmail or a look-alike domain like @paypa1.com instead of @paypal.com.
  • 3. Unexpected attachments or links: An attachment or link you were not expecting, even from someone you know. Their account may be compromised.
  • 4. Generic greetings: Dear Customer or Dear User instead of your actual name. Legitimate organizations usually know who you are.
  • 5. Requests for credentials or payments: Any email asking for passwords, MFA codes, wire transfers, or gift cards is almost certainly a scam.

Quick Check

You receive an email from your executive director asking you to urgently buy $500 in gift cards for a client and send the codes. The email says they are in a meeting and cannot talk. What is this?

A) A normal request from your boss
B) A spear phishing / BEC attack trying to steal money
C) A legitimate business expense
D) A phishing test from your IT department

Business Email Compromise (BEC)

BEC is the most financially damaging type of phishing. In a BEC attack, the attacker impersonates someone you trust: your CEO, a vendor, a client, or a colleague. They use that trust to manipulate you into sending money, changing payment details, or sharing sensitive information.

BEC attacks are sophisticated. The attacker may have studied your organization online, learned the names of your executives and vendors, and crafted an email that looks completely legitimate. The email may come from a look-alike domain or even from a compromised real account.

Common BEC Scenarios

  • Vendor invoice fraud: An email that looks like it is from one of your vendors says they changed their bank account. You wire money to the new account, which belongs to the attacker.
  • Executive impersonation: An email from your CEO asks you to urgently process a wire transfer or share sensitive files. The attacker counts on you not questioning the boss.
  • Payroll diversion: An email that appears to be from an employee asks HR to change their direct deposit information. The new account belongs to the attacker.
  • Gift card scam: An email from an executive asks you to buy gift cards for a client emergency and send the codes. The codes are immediately resold online.

Quick Check

Your vendor emails you to say they have changed banks and provides new account details for your next payment. What should you do?

A) Update the bank details as requested
B) Call your vendor at their known phone number to verify the change
C) Reply to the email asking for confirmation
D) Wait and see if they email again

Spear Phishing: When Attacks Feel Personal

Spear phishing is a targeted attack aimed specifically at you or your organization. The attacker has done their homework. They know your name, your role, your colleagues, maybe even your schedule. The email feels personal and legitimate, which makes it dangerous.

Spear phishing emails might reference a real project, a real colleague, or a real vendor. They might come during a time when you are expecting an email from that person. The key defense is the same: verify through a different channel before acting on any request for money, data, or credentials.

How to Protect Yourself

Your Phishing Defense Plan

  • Pause before you click. Urgency is a weapon. Take 10 seconds to scan for red flags.
  • Verify through a different channel. If an email asks for money or data, call the person directly using a known phone number.
  • Report suspicious emails. Use the Report Phishing button or forward to your IT team. Reporting protects everyone.
  • Never enter credentials from an email link. Go to the website directly by typing the URL or using a bookmark.
  • Hover before you click. Hover your mouse over links to see the real destination before clicking.
  • When in doubt, do not click. It is always better to verify than to click and regret.

How This Looks in Your Industry

Healthcare Practices

Phishing emails may appear to come from your EHR vendor, Medicare, or a hospital partner. They may ask you to verify your login or update billing information. A compromised email account can expose patient PHI, triggering HIPAA breach notification requirements.

Legal Firms

Attackers may impersonate clients, opposing counsel, or court clerks. A phishing email may contain a fake court document attachment that installs malware. Compromised email accounts can expose privileged client communications.

Nonprofits

Phishing emails may appear to come from grantors, donors, or board members. BEC attacks may redirect grant payments or donation deposits to attacker accounts. Nonprofits are attractive targets because they often have less IT security.

Daycares and Schools

Phishing emails may appear to come from parents, state licensing boards, or education vendors. A compromised account can expose student records, creating FERPA or COPPA compliance issues.

Key Takeaways

  • Phishing is the number one entry point for cyberattacks. Your awareness is your best defense.
  • Scan every email for the 5 red flags: urgency, mismatched sender, unexpected links, generic greetings, and credential/payment requests.
  • BEC attacks impersonate trusted people to steal money. Always verify payment changes by phone using a known number.
  • Spear phishing feels personal because the attacker did their homework. Verify through a different channel before acting.
  • When in doubt, do not click. Report it. It is always better to verify than to click and regret.

Module Quiz

Complete this quiz to test your understanding of the module. Answers are provided below each question.

1. You get an email from Microsoft 365 saying your account will be suspended in 24 hours unless you click a link to verify. What do you do?

A) Click the link immediately to avoid losing access
B) Check the sender address and hover over the link before deciding
C) Delete it and go to office.com directly to check your account status
D) Forward it to all your colleagues as a warning

2. Which of these is the strongest indicator of a BEC attack?

A) An email from a vendor with an invoice attached
B) An email from your CEO asking you to urgently wire money and keep it confidential
C) A newsletter from a vendor you have never heard of
D) An email with a typo in the subject line

3. You hover over a link in an email and the URL does not match the organization the email claims to be from. What should you do?

A) Click it anyway to see where it goes
B) Report the email as phishing and do not click
C) Forward it to your friends to warn them
D) Reply to the sender asking why the URL is different

4. An email from a colleague has an attachment you were not expecting. What is the safest action?

A) Open it to see what it is
B) Reply asking what it is, then open it if they confirm
C) Call or text your colleague to verify before opening
D) Forward it to IT without opening it, and verify with your colleague

5. Why are nonprofits and small practices especially vulnerable to phishing?

A) They have more money than large companies
B) They often have less IT security and fewer training resources
C) They do not use email
D) They are not vulnerable

Module 01 of 10 – Cybersecurity Essentials Training

Back to ResourcesNext Module