Phishing is still, by a wide margin, the #1 way small businesses get compromised. Not sophisticated zero-day exploits. Not nation-state hackers. Just employees clicking a link and typing their password into a page that looks like their normal login.
The uncomfortable truth: modern phishing emails are really convincing. AI has made them grammatically perfect and personalized. Here's how to train yourself and your team to spot them anyway.
The 6 Red Flags to Watch For in Every Email
- Sender address doesn't match the display name. The email says it's from “Microsoft Support” but the actual address is
ms-support@security-alerts-svc.com. Always check the actual email address, not just the name. - Urgency and pressure. “Your account will be closed in 24 hours.” “Immediate action required.” “Failure to respond within 4 hours will result in…” Real vendors don't threaten you.
- Generic greeting. “Dear Customer” or “Dear User” when your bank knows your name. Real vendors personalize.
- Suspicious links. Hover over any link (don't click), the actual URL is shown in your browser or email client's status bar. If it doesn't match the sender's real domain, don't click.
- Unexpected attachments. A PDF you didn't request. A Word doc from someone you don't know. An HTML file (extremely suspicious, almost always phishing).
- Requests for credentials, MFA codes, or gift cards. No legitimate business ever asks you to email your password, share your MFA code, or buy gift cards for them. Not ever.
5 Real Phishing Emails From 2026 (What Made Them Phishing)
Example 1: The Microsoft 365 “Password Expiration”
Subject: Your Microsoft 365 password expires today, action required
Body: Perfectly formatted, official Microsoft logo, urgent-sounding but professional. “Your password will expire in 4 hours. Click here to keep your current password.”
The tell: Sender was microsoft-online-security@365-verification.co. Real Microsoft never sends password notifications from that domain. Also: Microsoft 365 passwords don't expire by default, if you got a “password expiration” notice you weren't expecting, it's almost certainly fake.
Example 2: The DocuSign “New Document Waiting”
Subject: Alex Morgan sent you a document via DocuSign
Body: Real-looking DocuSign email with a “Review Document” button.
The tell: The recipient didn't recognize “Alex Morgan.” Real DocuSign emails come from dse@docusign.net; this one came from notification@doc-sign-secure.com. The “Review Document” button went to a fake Microsoft login page designed to steal credentials.
Example 3: The HR/W-2 Request (Business Email Compromise)
Subject: Quick request, can you send me a copy of everyone's W-2?
Body: Short, personal, from the “CEO”'s email address. “Hi Sarah, I need last year's W-2 forms for all employees for the accountant. Please send today.”
The tell: The CEO would never ask for this via email, and they'd know they already have this data in payroll. The sender's address was one letter off from the real CEO's address (rob@etocit.co instead of rob@etocit.com). This attack has hit hundreds of small businesses in Kentucky in the past 2 years.
Example 4: The Fake Vendor Invoice
Subject: Invoice #INV-2026-4471, Payment Due
Body: Professional-looking invoice PDF attached. Amount: $2,847.00. “Please remit payment by end of week.”
The tell: The recipient didn't recognize the vendor. Opening the PDF triggered a “security warning” asking to enable macros, which would have installed malware. Rule: never open unexpected attachments, and never enable macros in Office documents you didn't create yourself.
Example 5: The Fake IT “MFA Code Request”
Subject: Security alert, verify your identity
Body: “Hi, this is IT. We're seeing unusual activity on your account. Please read us your current MFA code so we can verify your identity and lock down the account.” Sometimes this arrives as a phone call.
The tell: No legitimate IT team will EVER ask you to read them your MFA code. The whole point of MFA is that you don't share the code. If someone asks, anyone, ever, for any reason, the answer is no.
What To Do When You Spot One
- Don't click. Don't reply. Don't open attachments.
- Report it. Forward to your IT provider (that's us for Etoc IT clients). In Outlook, there's usually a “Report Phishing” button.
- Delete it.
What To Do If You Already Clicked
- Change your password immediately for the affected account.
- Sign out of all sessions in your account settings.
- Enable MFA if you don't already have it.
- Tell your IT provider. Speed matters, the faster you act, the less damage.
- Watch your bank and email for suspicious activity over the next 30 days.
The Bottom Line
You can't rely on your spam filter to catch every phishing email, especially not now that AI writes them. The single best defense is a team that knows what to look for. If you have employees, take 30 minutes to walk through these red flags with them. It might save your business.
Want us to train your team on phishing?
We run practical phishing awareness training for small business teams, 30 minutes, real examples, no fluff. Ask us how.
Request Phishing Training