Phishing & Business Email Compromise
Phishing is the number one way attackers target small organizations. Learn to spot phishing emails, recognize business email compromise, and respond with confidence.
What You Will Learn
Phishing is the number one way attackers target small organizations. This module teaches you how to spot phishing emails, what business email compromise (BEC) looks like, and exactly what to do when a suspicious email lands in your inbox.
- Phishing basics: what it is and why it works
- Red flags: how to spot a phishing email in 10 seconds
- Business Email Compromise (BEC): the costliest threat to small organizations
- Spear phishing: targeted attacks that feel personal
- What to do: your step-by-step response when you suspect phishing
Why Phishing Matters for Your Organization
Phishing is not a nuisance. It is the entry point for most cyberattacks. According to industry research, over 90% of data breaches start with a phishing email. For regulated organizations in healthcare, legal, nonprofit, and education sectors, a single clicked link can expose patient records, client files, donor data, or student information.
The good news: phishing is preventable. When your team knows what to look for, they become your strongest security control, not your weakest link.
Quick Check
An email arrives from your bank asking you to verify your password by clicking a link. The email looks official with the bank logo. What should you do?
How to Spot a Phishing Email in 10 Seconds
Train yourself to scan every email for these five red flags before you click anything:
5 Red Flags of Phishing
- 1. Urgency or fear: The email pressures you to act immediately. Phrases like your account will be closed or payment overdue are designed to make you panic and click without thinking.
- 2. Mismatched sender address: The display name says your CEO but the email address is a random Gmail or a look-alike domain like @paypa1.com instead of @paypal.com.
- 3. Unexpected attachments or links: An attachment or link you were not expecting, even from someone you know. Their account may be compromised.
- 4. Generic greetings: Dear Customer or Dear User instead of your actual name. Legitimate organizations usually know who you are.
- 5. Requests for credentials or payments: Any email asking for passwords, MFA codes, wire transfers, or gift cards is almost certainly a scam.
Quick Check
You receive an email from your executive director asking you to urgently buy $500 in gift cards for a client and send the codes. The email says they are in a meeting and cannot talk. What is this?
Business Email Compromise (BEC)
BEC is the most financially damaging type of phishing. In a BEC attack, the attacker impersonates someone you trust: your CEO, a vendor, a client, or a colleague. They use that trust to manipulate you into sending money, changing payment details, or sharing sensitive information.
BEC attacks are sophisticated. The attacker may have studied your organization online, learned the names of your executives and vendors, and crafted an email that looks completely legitimate. The email may come from a look-alike domain or even from a compromised real account.
Common BEC Scenarios
- Vendor invoice fraud: An email that looks like it is from one of your vendors says they changed their bank account. You wire money to the new account, which belongs to the attacker.
- Executive impersonation: An email from your CEO asks you to urgently process a wire transfer or share sensitive files. The attacker counts on you not questioning the boss.
- Payroll diversion: An email that appears to be from an employee asks HR to change their direct deposit information. The new account belongs to the attacker.
- Gift card scam: An email from an executive asks you to buy gift cards for a client emergency and send the codes. The codes are immediately resold online.
Quick Check
Your vendor emails you to say they have changed banks and provides new account details for your next payment. What should you do?
Spear Phishing: When Attacks Feel Personal
Spear phishing is a targeted attack aimed specifically at you or your organization. The attacker has done their homework. They know your name, your role, your colleagues, maybe even your schedule. The email feels personal and legitimate, which makes it dangerous.
Spear phishing emails might reference a real project, a real colleague, or a real vendor. They might come during a time when you are expecting an email from that person. The key defense is the same: verify through a different channel before acting on any request for money, data, or credentials.
How to Protect Yourself
Your Phishing Defense Plan
- Pause before you click. Urgency is a weapon. Take 10 seconds to scan for red flags.
- Verify through a different channel. If an email asks for money or data, call the person directly using a known phone number.
- Report suspicious emails. Use the Report Phishing button or forward to your IT team. Reporting protects everyone.
- Never enter credentials from an email link. Go to the website directly by typing the URL or using a bookmark.
- Hover before you click. Hover your mouse over links to see the real destination before clicking.
- When in doubt, do not click. It is always better to verify than to click and regret.
How This Looks in Your Industry
Healthcare Practices
Phishing emails may appear to come from your EHR vendor, Medicare, or a hospital partner. They may ask you to verify your login or update billing information. A compromised email account can expose patient PHI, triggering HIPAA breach notification requirements.
Legal Firms
Attackers may impersonate clients, opposing counsel, or court clerks. A phishing email may contain a fake court document attachment that installs malware. Compromised email accounts can expose privileged client communications.
Nonprofits
Phishing emails may appear to come from grantors, donors, or board members. BEC attacks may redirect grant payments or donation deposits to attacker accounts. Nonprofits are attractive targets because they often have less IT security.
Daycares and Schools
Phishing emails may appear to come from parents, state licensing boards, or education vendors. A compromised account can expose student records, creating FERPA or COPPA compliance issues.
Key Takeaways
- Phishing is the number one entry point for cyberattacks. Your awareness is your best defense.
- Scan every email for the 5 red flags: urgency, mismatched sender, unexpected links, generic greetings, and credential/payment requests.
- BEC attacks impersonate trusted people to steal money. Always verify payment changes by phone using a known number.
- Spear phishing feels personal because the attacker did their homework. Verify through a different channel before acting.
- When in doubt, do not click. Report it. It is always better to verify than to click and regret.
Module Quiz
Complete this quiz to test your understanding of the module. Answers are provided below each question.
1. You get an email from Microsoft 365 saying your account will be suspended in 24 hours unless you click a link to verify. What do you do?
2. Which of these is the strongest indicator of a BEC attack?
3. You hover over a link in an email and the URL does not match the organization the email claims to be from. What should you do?
4. An email from a colleague has an attachment you were not expecting. What is the safest action?
5. Why are nonprofits and small practices especially vulnerable to phishing?
Module 01 of 10 – Cybersecurity Essentials Training
