Skip to main content

CNiC Solutions

IT professional analyzing cybersecurity data on a laptop in a modern office setting.

A single phishing email is now the most common way a business gets breached, and it works fast: Verizon’s data shows the median time for someone to click a malicious link and hand over their information is under one minute. Spotting a phishing email is not a technical skill reserved for your IT department. It is a habit any employee can learn in an afternoon, and it is one of the highest-return defenses your business has. This guide walks through the exact warning signs to check on every message, in the order a careful person would check them, plus what to do the moment something looks wrong.

Key Takeaways

  • Phishing and spoofing were the single most-reported cybercrime in 2024, with 193,407 complaints to the FBI
  • Around 60% of all confirmed data breaches involve a human element such as a mistaken click
  • The median time to fall for a phishing email is under 60 seconds, so a quick check before acting matters
  • Seven warning signs catch the vast majority of phishing: sender address, link destination, urgency, data requests, context, attachments, and unverified requests
  • Modern phishing can have perfect grammar, so never rely on spelling mistakes alone
  • If you clicked, disconnect, change exposed passwords from another device, and report it immediately

What’s in This Guide

 

 

Infographic checklist of seven phishing email warning signs to check before clicking
Run every suspicious message through these seven checks before you click, reply, or open anything.

 

 

Why Spotting Phishing Is a Business Skill Now

Phishing stopped being an IT-only problem the moment attackers realized it is easier to trick a person than to break through a firewall. In 2024, phishing and spoofing were the most-reported type of cybercrime in the United States, generating 193,407 complaints to the FBI’s Internet Crime Complaint Center, more than any other category. Those complaints are part of a record year in which reported losses topped $16 billion, a 33% jump over the year before.

193,407
phishing and spoofing complaints in 2024, the most-reported cybercrime type, FBI IC3 2024

The reason phishing works is not that people are careless. It is that a well-crafted message exploits how quickly we process email. According to Verizon’s Data Breach Investigations Report, the median time for a user to click a malicious link after opening a phishing email is 21 seconds, and only another 28 seconds to enter their data on the fraudulent page. That puts the median time to fall for phishing at under a minute. Verizon’s most recent report also found that around 60% of all confirmed breaches involve a human element, which is exactly the gap phishing is designed to widen.

Most-Reported Cybercrime Types by Complaint Volume (FBI IC3, 2024)

Phishing / Spoofing
193,407

Extortion
86,000

Personal Data Breach
64,882

Source: FBI Internet Crime Report 2024 | Verizon Data Breach Investigations Report

The good news: the same speed that makes phishing effective is also its weakness. A phishing email is trying to rush you. The single most powerful defense is to slow down and run through a short mental checklist before you click, reply, or open anything. The next seven steps are that checklist, in the order a careful reader would apply them. If any one of them raises a flag, stop and verify before acting. Understanding the wider threat picture helps too, and our overview of cybersecurity fundamentals for business owners puts phishing in context alongside the other controls every business needs.

Step 1: Check the Sender’s Actual Email Address

What to do: Do not trust the display name. On a phone, tap the sender’s name; on a desktop, hover over or click it to reveal the full email address behind it. Read the domain, the part after the @, character by character.

Why this step matters: The display name is the easiest thing in an email to fake. An attacker can set it to “Microsoft Support” or the name of your CEO while sending from a completely unrelated address. The real domain is much harder to disguise, so it is the first and most reliable tell.

Look specifically for three patterns. First, a public domain pretending to be a company, such as a “bank” emailing from an @gmail.com or @outlook.com address. Second, a misspelled or lookalike domain, like amaz0n.com with a zero, micros0ft-support.com, or paypa1.com with a number one. Third, a legitimate brand name buried in a longer address, such as billing@security-microsoft-update.com, where the real domain is the last part before the slash, not the brand word in the middle.

What success looks like: You can state, out loud, the exact domain the message came from, and you have confirmed it matches the organization the email claims to be from, letter for letter.

Common mistake: Assuming a familiar name in the “From” field means the email is safe. Business email compromise, where an attacker impersonates a known colleague or vendor, cost U.S. victims $2.77 billion in 2024 according to the FBI. The name looking right is exactly the effect the attacker is paying for.

Step 2: Hover Over Links Before You Click

What to do: Move your cursor over any link and pause without clicking. On desktop, the true destination appears in the bottom corner of your screen or in a small tooltip. On mobile, press and hold the link to preview the address in the pop-up that appears, then cancel. Compare that real address to the link text and to the sender’s supposed identity.

Why this step matters: The visible text of a link is just words. It can say your bank’s name while pointing anywhere on the internet. The destination address is the truth, and it is available to you before you commit to clicking.

Watch for a destination domain that does not match the sender, a long string of random characters, or a shortened link (bit.ly and similar) that hides where you are actually going. Also be wary of links that lead to a login page, since credential-harvesting pages are the most common phishing payload.

What success looks like: Every link’s real destination matches the organization it claims to be from. If you cannot verify a link, you navigate to the site yourself by typing the known address into your browser instead of clicking.

Step 3: Watch for Urgency, Threats, and Pressure

What to do: Notice how the message makes you feel. Phishing is engineered to trigger panic or excitement so you act before you think. Treat any manufactured time pressure as a warning sign in its own right.

Why this step matters: Urgency is the mechanism, not a side effect. When a message says your account will be closed in one hour, a payment failed, or a package is being returned, it is trying to collapse the gap between reading and clicking, the same gap Verizon measured at under 60 seconds.

Common pressure tactics include threats of account suspension, warnings of unauthorized activity, fake overdue invoices, “your mailbox is full” storage alerts, and too-good-to-be-true rewards. A real organization that needs something from you will still let you log in through the front door on your own schedule.

What success looks like: You recognize the emotional push, name it, and let it slow you down rather than speed you up. Urgency becomes a reason to verify, not a reason to comply.

Step 4: Question Any Request for Credentials or Payment

What to do: Stop at any email that asks you to log in, confirm a password, verify banking or card details, update payment information, or buy gift cards. Ask a simple question: would this organization really ask me for this, by email, this way?

Why this step matters: Legitimate companies do not ask for passwords, full card numbers, or Social Security numbers over email. The entire economic point of most phishing is to collect exactly these details, so a request for them is one of the clearest signals you will ever get.

Gift card requests deserve special mention. A message claiming to be from your boss or a vendor asking you to quietly buy gift cards and send the codes is a scam, every time, without exception. So is a supplier suddenly emailing new bank details for an existing invoice, which should always be confirmed by phone using a number you already have.

What success looks like: You never enter credentials or payment details in response to an inbound email. When an account genuinely needs attention, you reach it by typing the address yourself, not by following the message.

 

CNiC Solutions — Cybersecurity

 

Step 5: Read the Greeting, Grammar, and Context

What to do: Weigh the whole message. Does the greeting fit? Does the topic make sense for this sender right now? Is the tone what you would expect from this person or company?

Why this step matters: Context is one of the hardest things for an attacker to get right at scale. A generic “Dear Customer” from a company that knows your name, an invoice from a vendor you have never used, or a wildly out-of-character request from a colleague are all signs the message is not what it claims.

Myth to retire: “Phishing emails always have bad spelling.” That was true a decade ago. Today attackers use AI writing tools to produce flawless, natural-sounding messages, so perfect grammar is no longer proof an email is safe. Judge the sender address, the link destination, and the request, not just the prose.

What success looks like: You evaluate whether the message makes sense in context, and you treat a mismatch in tone, topic, or timing as a reason to verify, even when the writing is polished.

Step 6: Treat Unexpected Attachments as Dangerous

What to do: Do not open attachments you were not expecting, especially files that arrive with a vague message like “see attached” or “your invoice is ready.” Be especially cautious of anything that asks you to “enable content,” “enable macros,” or “enable editing” to view it.

Why this step matters: Attachments are a direct delivery method for malware. A booby-trapped document or a fake invoice can install ransomware or a credential stealer the moment you open it and follow its prompts. Legitimate businesses generally point you to a secure portal rather than pushing sensitive files as email attachments.

The highest-risk file types include documents that request macros, compressed .zip or .rar archives from unknown senders, and anything ending in .exe, .scr, or a double extension such as invoice.pdf.exe. When in doubt, do not open it, and confirm with the sender through a channel other than a reply.

What success looks like: You open only attachments you were expecting, from senders you have verified, and you never enable macros or content to view a file you did not ask for.

Step 7: Verify Through a Separate, Trusted Channel

What to do: When a message asks you to do something consequential, send money, change payment details, share information, or reset access, confirm it first using a contact method you already trust. Call the person on their known number, or log in to the service by typing its address into your browser.

Why this step matters: Verification defeats even a convincing phish, because the attacker controls the email but not your independent line of contact. Critically, never use the phone number, link, or “reply” in the suspicious message itself, since those lead straight back to the attacker.

What success looks like: Any high-stakes request is confirmed out-of-band before you act. A thirty-second phone call to a number you already had is the cheapest security control your business owns, and it neutralizes the majority of business email compromise attempts.

Source: CISA guidance on recognizing and reporting phishing | FBI IC3 2024 Annual Report

See How CNiC’s Cybersecurity Services Stop Phishing Before It Reaches Your Team

When to Call a Professional

Individual awareness catches a lot, but it is a last line, not a first one. If you reach the point where phishing emails are getting through to your team regularly, where an employee has clicked something and you are not sure what it touched, or where you have no email filtering, no multi-factor authentication, and no way to know if an account has been compromised, that is the point to bring in professional help.

A managed IT and security partner adds the layers a single employee cannot: filtering that blocks most phishing before it lands, enforced multi-factor authentication so a stolen password is not enough, and monitoring that flags a compromised account quickly. For businesses across Houston and Texas, that is where our team at CNiC Solutions works alongside your staff, so awareness and technology reinforce each other. You can also read why strong network security is the foundation these email defenses sit on.

Explore Managed IT With Built-In Email Security and Monitoring

Troubleshooting: I Think I Already Fell for One

If you clicked, replied, or entered information, do not panic and do not stay silent. Speed of response is what limits the damage. Here is what to do for the most common situations.

What happened What to do right now
I clicked a link but did not enter anything Close the page, do not enter any data, and run a scan with your security software. Report the email to your IT team so they can block the sender and warn others.
I entered my password on the page Change that password immediately from a different device, and change it anywhere you reused it. Turn on multi-factor authentication and tell your IT team so they can check for unauthorized logins.
I opened an attachment Disconnect the device from the internet, do not enter credentials or enable any content, and contact IT. The machine may need to be isolated and checked for malware before it goes back online.
I replied with sensitive or financial information Contact your bank or the affected provider directly using a known number, place fraud alerts if payment details were shared, and report the incident internally and to the FBI at ic3.gov.
I am not sure if the email was real Do not click anything further. Verify through a separate channel, and forward the message to your IT team or to reportphishing@apwg.org. When unsure, treat it as phishing until proven otherwise.

 

 

Infographic of five response steps to take after clicking a phishing link
If you clicked, speed matters: disconnect, change exposed passwords, and report it right away.

 

 

The worst outcome is not clicking a phishing link. It is hiding that you did. Businesses that build a blame-free reporting culture contain incidents faster, because employees speak up in the first minutes instead of hoping no one notices. If credentials or data were exposed, tested backups and a clear recovery plan are what get you back to normal, which is why reliable backup and recovery belongs in every phishing conversation.

Protect Your Business With Tested Backup and Recovery

Maintain and Monitor: Building a Phishing-Resistant Team

Spotting one phishing email is a skill. Keeping an entire organization safe over time is a system. Once your team knows the seven warning signs, a few ongoing practices turn that knowledge into durable protection.

Run regular phishing simulations and short training

Brief, frequent training beats a once-a-year lecture. Sending your own harmless simulated phishing emails, then coaching anyone who clicks without blame, keeps recognition sharp and gives you a real measure of your risk. The goal is a team that reports suspicious messages by reflex.

Enforce multi-factor authentication everywhere

Assume a password will eventually be phished, and make that not enough. Multi-factor authentication on email, financial, and cloud accounts means a stolen password alone cannot open the door. It is the single most effective safety net behind human awareness.

Make reporting easy and expected

Give employees a one-click way to report phishing and a clear message that reporting is always the right call, even after a mistake. Local threat patterns matter too; our Houston cybersecurity threat data shows how actively regional businesses are targeted, which makes a fast internal reporting habit worth building.

Keep an eye on the numbers

Track how many people report versus click over time. Improvement is the proof your program works, and stagnation tells you where to focus. For the broader trends behind these attacks, see our phishing statistics for 2026.

Frequently Asked Questions

What is the fastest way to tell if an email is phishing?

Check the sender’s real email address and hover over any links before clicking. If the address uses a public or misspelled domain, or a link points somewhere other than the claimed sender’s website, treat the message as phishing. Combine that with a quick gut check: unexpected requests for money, credentials, or urgent action are the most reliable red flags.

Can a phishing email be dangerous if I do not click anything?

Reading an email in a modern, updated mail client is generally low risk on its own. The danger comes from clicking links, opening attachments, enabling content, or replying with information. Do not interact with a suspicious message beyond reporting it. If you are unsure whether it already caused harm, contact your IT provider so they can check your account for unauthorized access.

Do phishing emails always have spelling mistakes?

No. Poor grammar used to be a reliable tell, but attackers now use AI tools to write flawless, convincing messages in perfect English. You cannot rely on spelling alone. Focus instead on the sender address, the true link destination, unexpected requests, and artificial urgency, which are far harder for an attacker to disguise.

What should I do if I clicked a link in a phishing email?

Disconnect the device from the internet, do not enter any information on the page that opened, and change the password for any account you may have exposed, from a different device. Enable multi-factor authentication if it is not already on, and report the incident to your IT team or provider immediately. Fast reporting is what turns a near-miss into a contained event.

Where do I report a phishing email?

Report it to your internal IT or security team first so they can protect other employees. You can also forward the message to the Anti-Phishing Working Group at reportphishing@apwg.org and file a report with the FBI’s Internet Crime Complaint Center at ic3.gov. Reporting helps shut down the campaign and protects other businesses targeted by the same attacker.
Methodology and Sources

All statistics in this article come from Tier 1 primary sources only, with no blog-to-blog citations. Complaint volumes and loss figures are from the FBI Internet Crime Complaint Center 2024 Annual Report (859,532 complaints; over $16 billion in reported losses, up 33% year over year; 193,407 phishing and spoofing complaints; 64,882 personal data breach complaints; approximately 86,000 extortion complaints; $2.77 billion in business email compromise losses). Human-element and time-to-click figures are from the Verizon Data Breach Investigations Report (median 21 seconds to click and a further 28 seconds to enter data; approximately 60% of breaches involving a human element). Guidance on recognizing and reporting phishing reflects the Cybersecurity and Infrastructure Security Agency (CISA). Figures reflect the most recently published data available as of August 2026; readers are encouraged to consult the primary sources directly for full methodology.

 

author avatar
David McFarlane Founder & CEO
As Founder and CEO of CNiC Solutions, David McFarlane has spent more than 15 years guiding Houston-area organizations through complex IT and cybersecurity challenges. His hands-on leadership ensures technology decisions align with business goals, risk management, and operational efficiency.
back to blog