Phishing awareness — laptop email with warning shield

Phishing is still the most common way business accounts get taken over. The email looks almost right—logo, urgency, a familiar brand—and the goal is simple: get you to enter a password, approve an MFA prompt, or open a malicious file.

Red flags employees should know

  • Unexpected urgency: “Your account will be closed in 1 hour”
  • Slightly wrong domains (rnicrosoft.com, g00gle.com, extra words in the address)
  • Requests for wire transfers, gift cards, or password “verification”
  • Links that do not match the claimed brand when you hover (on desktop)
  • Attachments you were not expecting (invoices, “shared docs,” zip files)

What to do instead of clicking

  • Open the real site by typing the address or using a bookmark—not the email link
  • Call the person who “sent” an urgent money request using a known phone number
  • Report suspicious mail with your email client’s report-phishing tools
  • If you already clicked or entered a password, change it from a clean device and tell IT immediately

Business controls that reduce phishing damage

  • Multi-factor authentication on email and admin portals
  • Advanced email filtering and safe-link policies where available
  • Least-privilege admin accounts (daily work is not done as Domain Admin)
  • Short security reminders for staff—not a once-a-year slideshow

For a deeper public overview, see the FTC’s guidance on phishing: How to recognize and avoid phishing scams.

Related reading on our site: Two-factor authentication and layered security.


Need help putting this into practice for your business? Contact SabatAge or call (845) 475-8468. We support Hudson Valley and Orange County businesses with practical security and managed IT.

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe

SabatAge blog—IT news, tips, and stories for Hudson Valley businesses