Why phishing works even on careful people
Phishing is no longer the badly-spelled “Nigerian prince” email of a decade ago. The messages that reach business inboxes today are polished, well-branded and often reference real suppliers, real invoices and real colleagues. They succeed not because staff are careless, but because they arrive during a busy day and ask for something that feels routine — approve a payment, reset a password, open an attachment. The whole trick is to make you act before you think.
Understanding that helps you slow down at the right moment. Almost every phishing email is trying to trigger one of two responses: urgency (act now or something bad happens) or authority (the boss, the bank or IT is telling you to). Once you learn to notice those levers being pulled, the red flags become much easier to spot.
The red flags worth checking every time
No single sign proves an email is fake, but the more of these that stack up, the more suspicious you should be:
- The sender address doesn’t match the display name. An email that shows “Accounts Team” but comes from
billing@account-secure-verify.comis a classic. Hover over — or tap and hold on mobile — the sender name to reveal the real address. - The greeting is oddly generic. “Dear Customer” or “Dear User” from a company that normally knows your name is a warning sign.
- There’s pressure to act immediately. “Your account will be suspended in 24 hours” or “final reminder” is designed to stop you checking.
- Links don’t go where they claim. Hover over any link (don’t click) and read the address that appears.
microsoft.comandmicros0ft-login.netare not the same place. - Unexpected attachments, especially
.zip,.html, or a document that asks you to “enable content” or “enable macros”. - The request breaks normal process — a supplier suddenly changing their bank details by email, or a director asking you to buy gift cards.
- Small language errors. Not always present, but odd phrasing, missing articles or the wrong currency symbol can give a foreign scammer away.
Real tactics we see used on local businesses
A few patterns come up again and again in the machines and mailboxes we look at in the Putney workshop:
The invoice swap. A genuine supplier thread is hijacked or spoofed, and a “polite” follow-up email says the bank details have changed for this month’s payment. The email looks like part of a real conversation, so it sails through. Always confirm changed bank details by phone using a number you already hold — never the number in the email.
The CEO or “quick favour” request. Staff receive a short message appearing to come from a director: “Are you at your desk? I need you to sort something quickly.” The reply-to address is subtly wrong, and once you engage, the request becomes a wire transfer or gift-card purchase.
The fake Microsoft 365 login. An email claims your mailbox is “full”, a document is “shared with you”, or your password is “expiring”. The link leads to a near-perfect copy of the Microsoft sign-in page that simply harvests your credentials. A correct Microsoft 365 setup with multi-factor authentication is the single best defence here, because a stolen password alone is no longer enough to get in.
The “verify your account” text-and-email combo. Increasingly, the email is followed by a text message or phone call reinforcing the same story, which makes it feel legitimate. Treat contact across multiple channels as a tactic, not proof.
What to do the moment something looks off
If an email feels wrong but you haven’t clicked anything, don’t reply and don’t forward it to colleagues “to check”. Report it using your mail provider’s built-in Report phishing button (both Outlook and Gmail have one), then delete it. If it references a real supplier or your bank, contact them separately through a number or website you already trust.
If a member of staff has already clicked
This is the part that matters most, and panic is the enemy. If someone has clicked a link, opened an attachment, or entered a password, act quickly and calmly:
- Disconnect that device from the network — unplug the Ethernet cable or turn off Wi-Fi — to limit anything spreading.
- Change the password immediately from a different, clean device, and change it anywhere the same password was reused.
- Turn on multi-factor authentication if it wasn’t already, so a leaked password can’t be used on its own.
- Check for mailbox rules and forwarding. Attackers often add a hidden rule that auto-forwards or deletes incoming mail to cover their tracks. Review your rules and connected apps.
- Warn your team and any affected contacts, because a compromised account is frequently used to phish everyone in the address book.
- Run a full malware scan on the affected machine before trusting it again.
The sooner these steps happen, the smaller the damage. A clicked link is not automatically a disaster — most incidents are contained fine when caught early.
Building habits that outlast any single scam
Technology helps, but people are the real defence. Agree a simple rule that any payment or bank-detail change is verified by phone. Keep software and browsers updated so known-malicious sites are blocked. And make it genuinely safe for staff to say “I think I clicked something” without fear of blame — the businesses that recover fastest are the ones where people report mistakes early.
If you’d like your team’s email hardened properly — spam filtering, multi-factor authentication and sensible mailbox rules — a solid email setup combined with the right cybersecurity measures makes phishing far harder to land. We can also review your Microsoft 365 setup so a stolen password doesn’t open the door. Call us on 020 7610 0500, pop into the Putney workshop, or use the contact form and we’ll take a look.




