The people-risk patterns attackers use every day.
Read the patterns, then test yourself honestly: would each one get caught in your office on a busy Tuesday - by the newest hire, not the most careful one?
The five patterns that do the damage
Phishing is not one thing. Small offices mostly get hit by five specific plays - each with a different ask and a different fix.
- ✓The payment change - a supplier, landlord or closing email announces “updated banking details” right before real money moves
- ✓The boss voice - a short message that sounds like the owner: “Are you at your desk? I need this handled quietly, now”
- ✓The login page - “your mailbox is full” or “a document is shared with you”, leading to a perfect copy of the real sign-in screen
- ✓MFA fatigue - your phone buzzes with approval prompts until someone taps yes just to make it stop
- ✓The attachment or QR code - an invoice, voicemail or parking notice that carries the payload past the email filter
The tells that survive good writing
AI has fixed the spelling mistakes. What still gives an attack away is structure, not grammar.
- ✓Pressure plus payment plus a new channel - urgency, money and “reply here instead” in one message is the signature combination
- ✓The reply-to address does not match the display name - the name is borrowed, the mailbox is not
- ✓A link that does not go where it claims - hover first, or better, go to the site directly instead of clicking
- ✓A first-time sender appearing mid-thread on a money conversation - especially near a deadline
- ✓Any request to skip the normal process “just this once” - the process is exactly what the attacker needs you to skip
What a ready office does
You cannot filter your way out of this. The offices that do well have three habits, written down and rehearsed.
- ✓Verify out of band - any banking change or unusual payment request gets a call to a number you already had, never one from the message
- ✓Report fast, no shame - a suspicious email goes to one known place, and reporting a click is treated as the win it is
- ✓After a click: change the password, revoke sessions, tell whoever owns IT - and if money moved, call your bank and your insurer’s breach line immediately
- ✓Rehearse it - a team that has faced a safe version of the real thing hesitates less and reports faster when it counts
Related tools and next steps
Spot the phish
A quick challenge that trains the eye for the tells in real phishing emails.
Take the challengeLive team training
A 90-minute fire drill on the five scams that hit small offices. From $1,800+.
See training optionsSecurity checklist
Review the email-security and reporting basics behind the guide.
Open the checklistReady to see where you stand?
Start with a baseline security checkup. We review your environment, score the highest-risk gaps, and hand you a plain-English 30-day plan.