Spot the scam before it costs you.
You didn’t start your business to become a cybersecurity expert — but the emails hitting your inbox don’t care. Fake invoices, “urgent” requests from the boss, messages that look like they came from you. It’s a lot, especially when you’re already wearing every other hat. This page exists to make it simpler: clear explanations, real examples, and practical steps so you and your team can recognize the tricks and get back to running the business.
Where Technology Meets Dedication — serving RI, MA & CT small businesses since 2002.Why scammers love smaller businesses
There’s a myth that criminals only go after big corporations. In reality, small and mid-sized businesses are often the preferred target — here’s why.
You have real money moving
Payroll, vendor payments, and wire transfers make you worth the effort — but you likely don’t have a large security team watching every transaction.
Everyone wears many hats
When one person handles accounting, HR, and the front desk, a well-timed “urgent” email is easier to slip past. Attackers count on you being busy.
You’re a doorway to others
If you serve larger clients or supply chains, criminals may target you to reach them. Your trusted relationships are exactly what they want to hijack.
The email tricks, in plain English
Attackers rely on a handful of proven tactics. Once you can name them, they’re much easier to catch.
Spam
Unsolicited bulk email — the digital equivalent of junk mail. Most is just annoying advertising, but spam is also the delivery vehicle for scams, chain schemes, and malware. Cutting down the volume reduces the chances something dangerous slips through.
Phishing
An email that pretends to be from a company or person you trust — your bank, Microsoft, a vendor — to trick you into clicking a link, opening an attachment, or handing over login details. The message and the fake website can look convincingly real.
Spoofing
Faking the “From” address so a message appears to come from someone you know — sometimes even from your own address. Website spoofing does the same for pages: a near-perfect copy of a real login screen built only to capture what you type.
BEC & CEO fraud
A targeted, personalized attack where the sender poses as your CEO, a manager, or a familiar vendor and asks for a wire transfer, gift cards, or a change to banking details. It leans on urgency and authority so you act before you verify.
Extortion emails
A threatening message claiming the sender has compromising footage, files, or access — pay up (often in cryptocurrency) or they’ll expose you. To seem credible, they may quote an old password pulled from a past data breach. It’s almost always a bluff.
Ransomware
Malware — often delivered by a single phishing click or attachment — that encrypts your files and demands payment for the key. For a small business, a day without access to your data can be devastating. Strains like CryptoLocker and Ryuk have hit organizations for years.
Vishing (voice phishing)
Phishing over the phone. Using internet calling, scammers can spoof caller ID to look like your bank, a government agency, or even a coworker, then use pressure and a live human voice to extract information or payment.
They’re all social engineering
Every one of these relies on the same thing: getting a human to act quickly without checking. Urgency, authority, fear, curiosity. Slow down, verify, and most of these attacks fall apart.
How to spot a scam email
No single sign is proof on its own — but the more of these you see in one message, the more suspicious you should be. When in doubt, don’t click; verify.
- Urgency or pressure. “Act now,” “within the hour,” “your account will be closed.” Real businesses rarely demand instant action by email.
- A request for money, gift cards, or banking changes. Especially wire transfers or a “new” vendor account — even if it looks like it’s from your boss.
- A mismatched or look-alike sender address. Check the actual address, not just the display name. [email protected] vs. john.kelley@compаny.com can be nearly identical.
- Links that don’t match. Hover over a link (don’t click) and confirm the real destination matches the company it claims to be from.
- Unexpected attachments. Invoices, “shipping documents,” or files you weren’t expecting are a classic malware delivery method.
- A request for login credentials or personal information. Legitimate companies won’t ask you to “confirm” your password by email.
- A generic or slightly-off greeting. “Dear Customer” or odd phrasing can be a tell — though note that AI now lets scammers write clean, error-free messages, so good grammar is no longer reassurance.
- It just feels off. A familiar contact making an unusual request, an odd tone, a strange time of day. Trust that instinct and verify through a channel you already know.
Practical steps you can actually put in place
You don’t need an enterprise budget to be a hard target. These are the moves that stop the majority of email attacks — most cost little more than a habit change.
Turn on multi-factor authentication (MFA) everywhere
Especially on email and Microsoft 365. Even if a password is stolen, MFA stops the attacker at the door. This is the single highest-impact step you can take.
Verify money and data requests out-of-band
Any request to move funds, change bank details, or send sensitive info gets confirmed through a second, known channel — call the person on a number you already have. Never use the contact info in the suspicious message itself.
Slow down before you click
Build a culture where “let me double-check that” is normal, not rude. Opening an email to read it is safe; clicking links and attachments is where the risk lives.
Keep tested backups of your data
Follow the 3-2-1 rule: three copies, on two types of media, with one kept off-site or offline. Reliable backups turn a ransomware crisis into an inconvenience — and test that they actually restore.
Keep software and devices updated
Enable automatic updates so security patches install themselves. Outdated systems are the open windows attackers look for.
Train your team — and keep training them
Your people are your best firewall. Short, regular refreshers beat a once-a-year lecture, because the threats change constantly. Make sure everyone knows how and to whom to report a suspicious message.
Filter email and lock down your inbox
Spam filtering, anti-malware, and modern email security dramatically reduce what ever reaches your staff. The best-defended click is the one your team never has to make.
What to do if something slips through
Everyone gets caught off guard eventually. What matters is acting fast and calmly. If you clicked a bad link, entered a password, or paid a fake invoice, here’s the order of operations.
- Disconnect if you suspect malware. If a downloaded file or attachment may have infected a machine, take it off the network (unplug/turn off Wi-Fi) to limit the spread — don’t keep working on it.
- Change the exposed password immediately — and anywhere else you reused it. Then turn on MFA if it wasn’t already on.
- Call your bank right away if money moved. With Business Email Compromise, speed matters most; a fast call can sometimes stop or recall a transfer before it’s gone.
- Tell someone. Loop in your manager, owner, and your IT provider. There’s no shame in reporting — quiet mistakes are the ones that turn into disasters.
- Report the phish. Use your email tool’s “report” button, then delete the message. Report fraud and BEC to the FBI’s IC3 at ic3.gov.
- Watch for round two. Once you’ve been hit, attackers often try again. Stay alert and let your team know what to look for.
Go deeper on any threat
Our team writes these guides for real business owners — no jargon, just what you need to know. Grouped by topic so you can start wherever you have questions.
Resist Getting Hooked: How to Avoid Phishing Scams
Phishing is getting harder to spot. A plain-language look at how the scam works and how to keep from taking the bait.
Read the guide →How to Become a Pro at Spotting a Phishing Email
A step-by-step breakdown of a real phishing email our own staff received — and the warning signs that gave it away.
Read the guide →Don’t Get Reeled In by Common Phishing Subject Lines
The subject lines attackers use most in Business Email Compromise — and how they weaponize urgency and authority.
Read the guide →Spoof Emails: 10 Tips to Identify These Threats
Ten practical checks for telling a legitimate message from a spoofed one before you act on it.
Read the guide →“From” Spoofing: Why Am I Getting Emails From Myself?
That unsettling email that looks like you sent it — what’s really happening and why it’s usually not a hack.
Read the guide →Phishing, Blackmail & Sextortion: A Triple Threat
Why extortion emails now quote your real (old) passwords — and why it’s almost always an empty threat.
Read the guide →The CryptoLocker Virus: Locking Files Since 2013
How a single infection can encrypt every file on your computer — and what it means for an unprepared business.
Read the guide →Ryuk Ransomware Attacks on the Rise
A look at one of the ransomware strains behind a surge in attacks — and why criminals find it so profitable.
Read the guide →Vishing & the Ever-Increasing Robocall
Phishing by phone: how scammers spoof numbers and use a live voice to pressure you into giving up information.
Read the guide →Cyber Security Training for Employees
How to build a “human firewall” — the what, why, and how of training your team to stop attacks.
Read the guide →Top 5 Office 365 Security Benefits to Enable
MFA, password complexity, and ransomware protection — security features you may already own but haven’t switched on.
Read the guide →Straight from the experts
These free, authoritative guides come from the U.S. government agencies that track and fight these threats every day — the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI. They’re excellent to bookmark and share with your team.
Teach Employees to Avoid Phishing
A small-business-focused playbook for training staff to recognize and report phishing — including the red flags to watch for and why once-a-year training isn’t enough.
Visit CISA → CISA · Secure Our WorldRecognize and Report Phishing
Clear, everyday guidance on catching a phish and the right way to report and delete it — plus a downloadable tip sheet you can pass around the office.
Visit CISA → CISA · Security TipAvoiding Social Engineering & Phishing Attacks
The foundational explainer on how social engineering works — phishing, vishing, and the psychology behind them — and the habits that keep you from being manipulated.
Visit CISA → CISA · For Small BusinessSecure Your Business
CISA’s hub built specifically for small and mid-sized businesses, covering the biggest threats, incident-response basics, and why no business is “too small” to be a target.
Visit CISA → CISA / NSA / FBI / MS-ISACJoint Guidance on Preventing Phishing Intrusions
A one-stop, multi-agency guide that goes beyond “don’t click” — the controls organizations can put in place so a single mistaken click doesn’t become a full breach.
Visit CISA → FBIBusiness Email Compromise Explained
The FBI’s overview of how BEC schemes trick businesses into wiring money or sharing data — and exactly how to report it (and try to recover funds) through ic3.gov.
Visit the FBI →Your questions, answered
The things business owners ask us most about email scams — in short, straight answers.
What’s the difference between phishing and spoofing?
They work together but aren’t the same thing. Phishing is the goal — tricking you into giving up information, money, or access. Spoofing is one of the techniques used to pull it off — faking the sender’s email address or a website so the phishing attempt looks legitimate. Put simply: spoofing is the disguise; phishing is the con.
How can I verify an email that looks like it’s from my boss?
Use a second, known channel. Call or text the person on a number you already have, or walk over and ask — don’t reply to the email or use any phone number listed in it. Be especially careful with any request to move money, change bank details, or buy gift cards, and with messages that stress urgency or secrecy. A real manager won’t mind you double-checking; an attacker is counting on you not to.
I clicked a suspicious link — what should I do now?
Don’t panic, and act quickly. If you entered a password, change it immediately (and anywhere you reused it) and turn on multi-factor authentication. If you downloaded or opened a file, disconnect that device from the network to limit any spread. Then tell your manager and your IT provider — reporting fast is what keeps a small slip from becoming a real incident. Simply opening an email to read it is generally safe; the risk comes from clicking links and attachments.
Why am I getting emails that look like they’re from my own address?
This is “from” spoofing. The “From” line on an email is easy to forge, so a scammer can make a message appear to come from your own address without ever accessing your account. It’s unsettling but usually not a sign you’ve been hacked. That said, change your password and enable MFA to be safe, and email security tools like SPF, DKIM, and DMARC help block spoofed mail from reaching your inbox in the first place.
Is bad spelling still a reliable way to spot a scam?
Not anymore. Poor grammar used to be a giveaway, but with AI writing tools, scammers can now produce clean, professional-sounding emails. So don’t treat good writing as proof a message is safe. Focus on the other red flags instead: unexpected requests, urgency, mismatched sender addresses, links that don’t match, and anything asking for money or credentials.
A scammer emailed me one of my real passwords. Am I in danger?
Almost always, this is a bluff. Extortion emails quote an old password to seem credible, but that password typically came from a past data breach that’s been sold online — not from hacking you directly. Don’t pay and don’t reply. Do change that password anywhere you still use it, turn on MFA, and consider a password manager so every account has a unique, strong password.
What is Business Email Compromise (BEC), and why is it so costly?
BEC is a targeted scam where an attacker poses as your CEO, a manager, or a trusted vendor to trick an employee into wiring money or changing payment details. It’s expensive because it bypasses technology and targets people directly — there’s often no malware to catch, just a convincing request. The FBI reported over $2.7 billion in BEC losses in 2024 alone. The best defense is a firm rule: always verify payment or banking changes through a second, known channel.
What’s the single most important thing I can do to protect my business?
Turn on multi-factor authentication (MFA) everywhere you can, starting with email. Even if a password gets stolen, MFA stops most attackers cold. Pair it with a simple habit of verifying any money or data request through a second channel, and you’ve blocked the two most common ways businesses get burned.
How does ransomware get in, and how do I protect against it?
Ransomware most often arrives through a phishing email — a click or an attachment that quietly installs malware, which then encrypts your files and demands payment. Your strongest protection is reliable, tested backups following the 3-2-1 rule (three copies, two types of media, one kept off-site or offline). With good backups you can restore your data instead of paying. Keeping software updated, using MFA, and training staff all reduce the odds of an infection in the first place.
Should I train my whole team, or just the people who handle money?
Your whole team. Attackers target whoever they can reach, and a compromised account anywhere in your business can be used to launch attacks on everyone else — and on your clients. Short, regular refreshers work far better than a single annual session, because the tactics keep changing. Make sure every employee knows how, and to whom, to report a suspicious message.
Where do I report a scam or fraud if my business is hit?
Report internet crime, phishing, and Business Email Compromise to the FBI’s Internet Crime Complaint Center at ic3.gov. If money was transferred, contact your bank immediately — fast action can sometimes stop or recover a transfer. You can also report suspicious activity to CISA, and it’s wise to notify your IT provider so they can check for any wider compromise.
Scam School is a free educational resource from IT Support RI — locally owned and operated in North Smithfield, Rhode Island, serving small businesses across RI, MA & CT since 2002.