A single phishing email is now the most common way a business gets breached, and it works fast: Verizon’s data shows the median time for someone to click a malicious link and hand over their information is under one minute. Spotting a phishing email is not a technical skill reserved for your IT department. It is a habit any employee can learn in an afternoon, and it is one of the highest-return defenses your business has. This guide walks through the exact warning signs to check on every message, in the order a careful person would check them, plus what to do the moment something looks wrong.

Phishing stopped being an IT-only problem the moment attackers realized it is easier to trick a person than to break through a firewall. In 2024, phishing and spoofing were the most-reported type of cybercrime in the United States, generating 193,407 complaints to the FBI’s Internet Crime Complaint Center, more than any other category. Those complaints are part of a record year in which reported losses topped $16 billion, a 33% jump over the year before.
The reason phishing works is not that people are careless. It is that a well-crafted message exploits how quickly we process email. According to Verizon’s Data Breach Investigations Report, the median time for a user to click a malicious link after opening a phishing email is 21 seconds, and only another 28 seconds to enter their data on the fraudulent page. That puts the median time to fall for phishing at under a minute. Verizon’s most recent report also found that around 60% of all confirmed breaches involve a human element, which is exactly the gap phishing is designed to widen.
Most-Reported Cybercrime Types by Complaint Volume (FBI IC3, 2024)
Source: FBI Internet Crime Report 2024 | Verizon Data Breach Investigations Report
The good news: the same speed that makes phishing effective is also its weakness. A phishing email is trying to rush you. The single most powerful defense is to slow down and run through a short mental checklist before you click, reply, or open anything. The next seven steps are that checklist, in the order a careful reader would apply them. If any one of them raises a flag, stop and verify before acting. Understanding the wider threat picture helps too, and our overview of cybersecurity fundamentals for business owners puts phishing in context alongside the other controls every business needs.
What to do: Do not trust the display name. On a phone, tap the sender’s name; on a desktop, hover over or click it to reveal the full email address behind it. Read the domain, the part after the @, character by character.
Why this step matters: The display name is the easiest thing in an email to fake. An attacker can set it to “Microsoft Support” or the name of your CEO while sending from a completely unrelated address. The real domain is much harder to disguise, so it is the first and most reliable tell.
Look specifically for three patterns. First, a public domain pretending to be a company, such as a “bank” emailing from an @gmail.com or @outlook.com address. Second, a misspelled or lookalike domain, like amaz0n.com with a zero, micros0ft-support.com, or paypa1.com with a number one. Third, a legitimate brand name buried in a longer address, such as billing@security-microsoft-update.com, where the real domain is the last part before the slash, not the brand word in the middle.
What success looks like: You can state, out loud, the exact domain the message came from, and you have confirmed it matches the organization the email claims to be from, letter for letter.
What to do: Move your cursor over any link and pause without clicking. On desktop, the true destination appears in the bottom corner of your screen or in a small tooltip. On mobile, press and hold the link to preview the address in the pop-up that appears, then cancel. Compare that real address to the link text and to the sender’s supposed identity.
Why this step matters: The visible text of a link is just words. It can say your bank’s name while pointing anywhere on the internet. The destination address is the truth, and it is available to you before you commit to clicking.
Watch for a destination domain that does not match the sender, a long string of random characters, or a shortened link (bit.ly and similar) that hides where you are actually going. Also be wary of links that lead to a login page, since credential-harvesting pages are the most common phishing payload.
What success looks like: Every link’s real destination matches the organization it claims to be from. If you cannot verify a link, you navigate to the site yourself by typing the known address into your browser instead of clicking.
What to do: Notice how the message makes you feel. Phishing is engineered to trigger panic or excitement so you act before you think. Treat any manufactured time pressure as a warning sign in its own right.
Why this step matters: Urgency is the mechanism, not a side effect. When a message says your account will be closed in one hour, a payment failed, or a package is being returned, it is trying to collapse the gap between reading and clicking, the same gap Verizon measured at under 60 seconds.
Common pressure tactics include threats of account suspension, warnings of unauthorized activity, fake overdue invoices, “your mailbox is full” storage alerts, and too-good-to-be-true rewards. A real organization that needs something from you will still let you log in through the front door on your own schedule.
What success looks like: You recognize the emotional push, name it, and let it slow you down rather than speed you up. Urgency becomes a reason to verify, not a reason to comply.
What to do: Stop at any email that asks you to log in, confirm a password, verify banking or card details, update payment information, or buy gift cards. Ask a simple question: would this organization really ask me for this, by email, this way?
Why this step matters: Legitimate companies do not ask for passwords, full card numbers, or Social Security numbers over email. The entire economic point of most phishing is to collect exactly these details, so a request for them is one of the clearest signals you will ever get.
Gift card requests deserve special mention. A message claiming to be from your boss or a vendor asking you to quietly buy gift cards and send the codes is a scam, every time, without exception. So is a supplier suddenly emailing new bank details for an existing invoice, which should always be confirmed by phone using a number you already have.
What success looks like: You never enter credentials or payment details in response to an inbound email. When an account genuinely needs attention, you reach it by typing the address yourself, not by following the message.
What to do: Weigh the whole message. Does the greeting fit? Does the topic make sense for this sender right now? Is the tone what you would expect from this person or company?
Why this step matters: Context is one of the hardest things for an attacker to get right at scale. A generic “Dear Customer” from a company that knows your name, an invoice from a vendor you have never used, or a wildly out-of-character request from a colleague are all signs the message is not what it claims.
What success looks like: You evaluate whether the message makes sense in context, and you treat a mismatch in tone, topic, or timing as a reason to verify, even when the writing is polished.
What to do: Do not open attachments you were not expecting, especially files that arrive with a vague message like “see attached” or “your invoice is ready.” Be especially cautious of anything that asks you to “enable content,” “enable macros,” or “enable editing” to view it.
Why this step matters: Attachments are a direct delivery method for malware. A booby-trapped document or a fake invoice can install ransomware or a credential stealer the moment you open it and follow its prompts. Legitimate businesses generally point you to a secure portal rather than pushing sensitive files as email attachments.
The highest-risk file types include documents that request macros, compressed .zip or .rar archives from unknown senders, and anything ending in .exe, .scr, or a double extension such as invoice.pdf.exe. When in doubt, do not open it, and confirm with the sender through a channel other than a reply.
What success looks like: You open only attachments you were expecting, from senders you have verified, and you never enable macros or content to view a file you did not ask for.
What to do: When a message asks you to do something consequential, send money, change payment details, share information, or reset access, confirm it first using a contact method you already trust. Call the person on their known number, or log in to the service by typing its address into your browser.
Why this step matters: Verification defeats even a convincing phish, because the attacker controls the email but not your independent line of contact. Critically, never use the phone number, link, or “reply” in the suspicious message itself, since those lead straight back to the attacker.
What success looks like: Any high-stakes request is confirmed out-of-band before you act. A thirty-second phone call to a number you already had is the cheapest security control your business owns, and it neutralizes the majority of business email compromise attempts.
Source: CISA guidance on recognizing and reporting phishing | FBI IC3 2024 Annual Report
See How CNiC’s Cybersecurity Services Stop Phishing Before It Reaches Your Team
Individual awareness catches a lot, but it is a last line, not a first one. If you reach the point where phishing emails are getting through to your team regularly, where an employee has clicked something and you are not sure what it touched, or where you have no email filtering, no multi-factor authentication, and no way to know if an account has been compromised, that is the point to bring in professional help.
A managed IT and security partner adds the layers a single employee cannot: filtering that blocks most phishing before it lands, enforced multi-factor authentication so a stolen password is not enough, and monitoring that flags a compromised account quickly. For businesses across Houston and Texas, that is where our team at CNiC Solutions works alongside your staff, so awareness and technology reinforce each other. You can also read why strong network security is the foundation these email defenses sit on.
Explore Managed IT With Built-In Email Security and Monitoring
If you clicked, replied, or entered information, do not panic and do not stay silent. Speed of response is what limits the damage. Here is what to do for the most common situations.
| What happened | What to do right now |
|---|---|
| I clicked a link but did not enter anything | Close the page, do not enter any data, and run a scan with your security software. Report the email to your IT team so they can block the sender and warn others. |
| I entered my password on the page | Change that password immediately from a different device, and change it anywhere you reused it. Turn on multi-factor authentication and tell your IT team so they can check for unauthorized logins. |
| I opened an attachment | Disconnect the device from the internet, do not enter credentials or enable any content, and contact IT. The machine may need to be isolated and checked for malware before it goes back online. |
| I replied with sensitive or financial information | Contact your bank or the affected provider directly using a known number, place fraud alerts if payment details were shared, and report the incident internally and to the FBI at ic3.gov. |
| I am not sure if the email was real | Do not click anything further. Verify through a separate channel, and forward the message to your IT team or to reportphishing@apwg.org. When unsure, treat it as phishing until proven otherwise. |

The worst outcome is not clicking a phishing link. It is hiding that you did. Businesses that build a blame-free reporting culture contain incidents faster, because employees speak up in the first minutes instead of hoping no one notices. If credentials or data were exposed, tested backups and a clear recovery plan are what get you back to normal, which is why reliable backup and recovery belongs in every phishing conversation.
Protect Your Business With Tested Backup and Recovery
Spotting one phishing email is a skill. Keeping an entire organization safe over time is a system. Once your team knows the seven warning signs, a few ongoing practices turn that knowledge into durable protection.
Brief, frequent training beats a once-a-year lecture. Sending your own harmless simulated phishing emails, then coaching anyone who clicks without blame, keeps recognition sharp and gives you a real measure of your risk. The goal is a team that reports suspicious messages by reflex.
Assume a password will eventually be phished, and make that not enough. Multi-factor authentication on email, financial, and cloud accounts means a stolen password alone cannot open the door. It is the single most effective safety net behind human awareness.
Give employees a one-click way to report phishing and a clear message that reporting is always the right call, even after a mistake. Local threat patterns matter too; our Houston cybersecurity threat data shows how actively regional businesses are targeted, which makes a fast internal reporting habit worth building.
Track how many people report versus click over time. Improvement is the proof your program works, and stagnation tells you where to focus. For the broader trends behind these attacks, see our phishing statistics for 2026.
All statistics in this article come from Tier 1 primary sources only, with no blog-to-blog citations. Complaint volumes and loss figures are from the FBI Internet Crime Complaint Center 2024 Annual Report (859,532 complaints; over $16 billion in reported losses, up 33% year over year; 193,407 phishing and spoofing complaints; 64,882 personal data breach complaints; approximately 86,000 extortion complaints; $2.77 billion in business email compromise losses). Human-element and time-to-click figures are from the Verizon Data Breach Investigations Report (median 21 seconds to click and a further 28 seconds to enter data; approximately 60% of breaches involving a human element). Guidance on recognizing and reporting phishing reflects the Cybersecurity and Infrastructure Security Agency (CISA). Figures reflect the most recently published data available as of August 2026; readers are encouraged to consult the primary sources directly for full methodology.
IT compliance for a small business is the work of meeting the legal, industry, and contractual…
IT support tiers are a layered structure that routes each technical issue to the right level…
A disaster recovery plan is the documented, tested playbook that gets your systems, applications, and data…
A business continuity plan is the written playbook that keeps your company running when something goes…