
Phishing is still the most common way attackers get into small businesses—not because staff are careless, but because modern lures look professional, urgent, and familiar.
Save this post as a refresher for new hires. Pair it with CISA’s Recognize and Report Phishing and the FTC’s phishing guidance when you train your team.
What phishing looks like in 2026
- Payroll or direct-deposit change requests from a “new employee”
- Vendor invoice PDFs with a malicious link
- Fake Microsoft 365 or Google “sign in now or lose access” notices
- Shipping, tax, or banking alerts timed around busy seasons
- QR codes on posters or emails that open look-alike login pages
How to avoid common phishing scams
1. Slow down on urgency. Attackers manufacture deadlines. Real payroll and banking changes can wait for a second channel check.
2. Hover before you click. On a computer, hover links and read the real URL. On mobile, long-press. Look for misspellings and odd domains.
3. Do not trust the display name. Anyone can set “IT Support” as a From name. Check the full email address.
4. Verify money and credential requests out-of-band. Call a known number—not the number in the email—before changing banking info or sending passwords.
5. Use MFA everywhere that matters. See CISA: Turn on MFA. MFA will not stop every attack, but it stops a large class of password theft.
6. Use layered defenses. Email filtering, web protection, MFA, and endpoint protection reduce the blast radius when someone inevitably clicks.
If you already clicked
- Disconnect from sensitive systems if instructed by IT
- Change passwords from a clean device
- Report the message to IT immediately
- Watch for unusual inbox rules or outbound mail
- Do not pay ransomware or “refund” scams without professional advice
Authoritative outbound resources
- CISA: Recognize and Report Phishing
- CISA: Turn on MFA
- FTC: How to recognize and avoid phishing scams
- Microsoft account security
- Google Account Security
For business email protection and user coaching, see our layered security approach or contact SabatAge at (845) 475-8468.

Comments are closed