Scam School · A Free Learning Resource

Spot the scam before it costs you.

You didn’t start your business to become a cybersecurity expert — but the emails hitting your inbox don’t care. Fake invoices, “urgent” requests from the boss, messages that look like they came from you. It’s a lot, especially when you’re already wearing every other hat. This page exists to make it simpler: clear explanations, real examples, and practical steps so you and your team can recognize the tricks and get back to running the business.

Where Technology Meets Dedication — serving RI, MA & CT small businesses since 2002.
#1 Phishing was the most-reported cybercrime in the FBI’s 2024 Internet Crime Report (193,407 complaints).
$2.7B+ Reported to the FBI in 2024 from Business Email Compromise alone — a scam that starts with one convincing email.
Most attacks Start in your inbox. Email is still the front door attackers try first.
Start Here

Why scammers love smaller businesses

There’s a myth that criminals only go after big corporations. In reality, small and mid-sized businesses are often the preferred target — here’s why.

You have real money moving

Payroll, vendor payments, and wire transfers make you worth the effort — but you likely don’t have a large security team watching every transaction.

Everyone wears many hats

When one person handles accounting, HR, and the front desk, a well-timed “urgent” email is easier to slip past. Attackers count on you being busy.

You’re a doorway to others

If you serve larger clients or supply chains, criminals may target you to reach them. Your trusted relationships are exactly what they want to hijack.

Know the Threats

The email tricks, in plain English

Attackers rely on a handful of proven tactics. Once you can name them, they’re much easier to catch.

Spam

Spam

Unsolicited bulk email — the digital equivalent of junk mail. Most is just annoying advertising, but spam is also the delivery vehicle for scams, chain schemes, and malware. Cutting down the volume reduces the chances something dangerous slips through.

Think of it like: flyers stuffed under your windshield. Harmless clutter — until one of them is a fake parking ticket designed to get your card number.
Phishing

Phishing

An email that pretends to be from a company or person you trust — your bank, Microsoft, a vendor — to trick you into clicking a link, opening an attachment, or handing over login details. The message and the fake website can look convincingly real.

Real-world example: a staffer gets a “Your mailbox is full—verify to keep receiving mail” email, clicks, and types their Microsoft 365 password into a lookalike login page. The attacker now has the keys.
Spoofing

Spoofing

Faking the “From” address so a message appears to come from someone you know — sometimes even from your own address. Website spoofing does the same for pages: a near-perfect copy of a real login screen built only to capture what you type.

Think of it like: a letter with your company’s return address on the envelope — that you never sent. The envelope is easy to fake; that’s the whole point.
Business Email Compromise

BEC & CEO fraud

A targeted, personalized attack where the sender poses as your CEO, a manager, or a familiar vendor and asks for a wire transfer, gift cards, or a change to banking details. It leans on urgency and authority so you act before you verify.

Real-world example: “I’m in a meeting—can you push through this vendor payment today? New bank info attached.” Signed with the owner’s name. It’s not the owner.
Sextortion & Blackmail

Extortion emails

A threatening message claiming the sender has compromising footage, files, or access — pay up (often in cryptocurrency) or they’ll expose you. To seem credible, they may quote an old password pulled from a past data breach. It’s almost always a bluff.

Reality check: that password proves they bought a leaked list, not that they hacked you. Don’t pay, don’t reply — but do change any password still in use.
Ransomware

Ransomware

Malware — often delivered by a single phishing click or attachment — that encrypts your files and demands payment for the key. For a small business, a day without access to your data can be devastating. Strains like CryptoLocker and Ryuk have hit organizations for years.

Think of it like: someone changing every lock in your building overnight and sliding a ransom note under the door. Good backups are the spare keys that make you immune.
Vishing & Robocalls

Vishing (voice phishing)

Phishing over the phone. Using internet calling, scammers can spoof caller ID to look like your bank, a government agency, or even a coworker, then use pressure and a live human voice to extract information or payment.

Think of it like: a stranger at your door in a convincing uniform. The uniform is rented. Verify before you let them in — hang up and call the number you know is real.
The Common Thread

They’re all social engineering

Every one of these relies on the same thing: getting a human to act quickly without checking. Urgency, authority, fear, curiosity. Slow down, verify, and most of these attacks fall apart.

Red-Flag Checklist

How to spot a scam email

No single sign is proof on its own — but the more of these you see in one message, the more suspicious you should be. When in doubt, don’t click; verify.

  • Urgency or pressure. “Act now,” “within the hour,” “your account will be closed.” Real businesses rarely demand instant action by email.
  • A request for money, gift cards, or banking changes. Especially wire transfers or a “new” vendor account — even if it looks like it’s from your boss.
  • A mismatched or look-alike sender address. Check the actual address, not just the display name. [email protected] vs. john.kelley@compаny.com can be nearly identical.
  • Links that don’t match. Hover over a link (don’t click) and confirm the real destination matches the company it claims to be from.
  • Unexpected attachments. Invoices, “shipping documents,” or files you weren’t expecting are a classic malware delivery method.
  • A request for login credentials or personal information. Legitimate companies won’t ask you to “confirm” your password by email.
  • A generic or slightly-off greeting. “Dear Customer” or odd phrasing can be a tell — though note that AI now lets scammers write clean, error-free messages, so good grammar is no longer reassurance.
  • It just feels off. A familiar contact making an unusual request, an odd tone, a strange time of day. Trust that instinct and verify through a channel you already know.
Your Defense Playbook

Practical steps you can actually put in place

You don’t need an enterprise budget to be a hard target. These are the moves that stop the majority of email attacks — most cost little more than a habit change.

Turn on multi-factor authentication (MFA) everywhere

Especially on email and Microsoft 365. Even if a password is stolen, MFA stops the attacker at the door. This is the single highest-impact step you can take.

Verify money and data requests out-of-band

Any request to move funds, change bank details, or send sensitive info gets confirmed through a second, known channel — call the person on a number you already have. Never use the contact info in the suspicious message itself.

Slow down before you click

Build a culture where “let me double-check that” is normal, not rude. Opening an email to read it is safe; clicking links and attachments is where the risk lives.

Keep tested backups of your data

Follow the 3-2-1 rule: three copies, on two types of media, with one kept off-site or offline. Reliable backups turn a ransomware crisis into an inconvenience — and test that they actually restore.

Keep software and devices updated

Enable automatic updates so security patches install themselves. Outdated systems are the open windows attackers look for.

Train your team — and keep training them

Your people are your best firewall. Short, regular refreshers beat a once-a-year lecture, because the threats change constantly. Make sure everyone knows how and to whom to report a suspicious message.

Filter email and lock down your inbox

Spam filtering, anti-malware, and modern email security dramatically reduce what ever reaches your staff. The best-defended click is the one your team never has to make.

Don’t Panic

What to do if something slips through

Everyone gets caught off guard eventually. What matters is acting fast and calmly. If you clicked a bad link, entered a password, or paid a fake invoice, here’s the order of operations.

  1. Disconnect if you suspect malware. If a downloaded file or attachment may have infected a machine, take it off the network (unplug/turn off Wi-Fi) to limit the spread — don’t keep working on it.
  2. Change the exposed password immediately — and anywhere else you reused it. Then turn on MFA if it wasn’t already on.
  3. Call your bank right away if money moved. With Business Email Compromise, speed matters most; a fast call can sometimes stop or recall a transfer before it’s gone.
  4. Tell someone. Loop in your manager, owner, and your IT provider. There’s no shame in reporting — quiet mistakes are the ones that turn into disasters.
  5. Report the phish. Use your email tool’s “report” button, then delete the message. Report fraud and BEC to the FBI’s IC3 at ic3.gov.
  6. Watch for round two. Once you’ve been hit, attackers often try again. Stay alert and let your team know what to look for.
Deep-Dive Guides from IT Support RI

Go deeper on any threat

Our team writes these guides for real business owners — no jargon, just what you need to know. Grouped by topic so you can start wherever you have questions.

Trusted Outside Resources

Straight from the experts

These free, authoritative guides come from the U.S. government agencies that track and fight these threats every day — the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI. They’re excellent to bookmark and share with your team.

Frequently Asked Questions

Your questions, answered

The things business owners ask us most about email scams — in short, straight answers.

What’s the difference between phishing and spoofing?

They work together but aren’t the same thing. Phishing is the goal — tricking you into giving up information, money, or access. Spoofing is one of the techniques used to pull it off — faking the sender’s email address or a website so the phishing attempt looks legitimate. Put simply: spoofing is the disguise; phishing is the con.

How can I verify an email that looks like it’s from my boss?

Use a second, known channel. Call or text the person on a number you already have, or walk over and ask — don’t reply to the email or use any phone number listed in it. Be especially careful with any request to move money, change bank details, or buy gift cards, and with messages that stress urgency or secrecy. A real manager won’t mind you double-checking; an attacker is counting on you not to.

I clicked a suspicious link — what should I do now?

Don’t panic, and act quickly. If you entered a password, change it immediately (and anywhere you reused it) and turn on multi-factor authentication. If you downloaded or opened a file, disconnect that device from the network to limit any spread. Then tell your manager and your IT provider — reporting fast is what keeps a small slip from becoming a real incident. Simply opening an email to read it is generally safe; the risk comes from clicking links and attachments.

Why am I getting emails that look like they’re from my own address?

This is “from” spoofing. The “From” line on an email is easy to forge, so a scammer can make a message appear to come from your own address without ever accessing your account. It’s unsettling but usually not a sign you’ve been hacked. That said, change your password and enable MFA to be safe, and email security tools like SPF, DKIM, and DMARC help block spoofed mail from reaching your inbox in the first place.

Is bad spelling still a reliable way to spot a scam?

Not anymore. Poor grammar used to be a giveaway, but with AI writing tools, scammers can now produce clean, professional-sounding emails. So don’t treat good writing as proof a message is safe. Focus on the other red flags instead: unexpected requests, urgency, mismatched sender addresses, links that don’t match, and anything asking for money or credentials.

A scammer emailed me one of my real passwords. Am I in danger?

Almost always, this is a bluff. Extortion emails quote an old password to seem credible, but that password typically came from a past data breach that’s been sold online — not from hacking you directly. Don’t pay and don’t reply. Do change that password anywhere you still use it, turn on MFA, and consider a password manager so every account has a unique, strong password.

What is Business Email Compromise (BEC), and why is it so costly?

BEC is a targeted scam where an attacker poses as your CEO, a manager, or a trusted vendor to trick an employee into wiring money or changing payment details. It’s expensive because it bypasses technology and targets people directly — there’s often no malware to catch, just a convincing request. The FBI reported over $2.7 billion in BEC losses in 2024 alone. The best defense is a firm rule: always verify payment or banking changes through a second, known channel.

What’s the single most important thing I can do to protect my business?

Turn on multi-factor authentication (MFA) everywhere you can, starting with email. Even if a password gets stolen, MFA stops most attackers cold. Pair it with a simple habit of verifying any money or data request through a second channel, and you’ve blocked the two most common ways businesses get burned.

How does ransomware get in, and how do I protect against it?

Ransomware most often arrives through a phishing email — a click or an attachment that quietly installs malware, which then encrypts your files and demands payment. Your strongest protection is reliable, tested backups following the 3-2-1 rule (three copies, two types of media, one kept off-site or offline). With good backups you can restore your data instead of paying. Keeping software updated, using MFA, and training staff all reduce the odds of an infection in the first place.

Should I train my whole team, or just the people who handle money?

Your whole team. Attackers target whoever they can reach, and a compromised account anywhere in your business can be used to launch attacks on everyone else — and on your clients. Short, regular refreshers work far better than a single annual session, because the tactics keep changing. Make sure every employee knows how, and to whom, to report a suspicious message.

Where do I report a scam or fraud if my business is hit?

Report internet crime, phishing, and Business Email Compromise to the FBI’s Internet Crime Complaint Center at ic3.gov. If money was transferred, contact your bank immediately — fast action can sometimes stop or recover a transfer. You can also report suspicious activity to CISA, and it’s wise to notify your IT provider so they can check for any wider compromise.

Scam School is a free educational resource from IT Support RI — locally owned and operated in North Smithfield, Rhode Island, serving small businesses across RI, MA & CT since 2002.