Skip to main content
Guide

Phishing: What It Is and How to Protect Your Business

Phishing is a fake message - email, text, or phone call - that impersonates a trusted party to steal a password, data, or money. It is the most common first step in attacks on small businesses. Defense works in three layers: a secured domain (SPF, DKIM, DMARC), MFA on accounts, and the habit of verifying outside the message.

This guide is written for the owner of a small practice - dental office, CPA firm, med spa - not for an IT department. It shows what phishing actually looks like in a business inbox, what the numbers say, and which three defenses buy the most protection for the least work. Phishing is one of the threats mapped in our guide to cyber threats for business - here we take it apart.

1. What phishing is and why it works

Phishing impersonates a trusted sender - a bank, a vendor, a shipping carrier, the IRS - to push the recipient into clicking a link, opening an attachment, or entering a password. The message can arrive by email, text, or phone. The goal never changes: take over an account, data, or money without breaking into anything. Instead of defeating your security, the attacker asks the victim to open the door - which makes phishing the cheapest and most common way into a business.

Its effectiveness rests on three psychological levers: urgency (“your account will be locked in 24 hours”), authority (a bank’s logo, a government letterhead, an address one letter off from the real one), and fear of consequences (an overdue invoice, a missed delivery, an audit). Under pressure, people stop analyzing and start executing. The attacker doesn’t need technical skill - just a well-written message.

In a small practice, this lands on the weakest point: one person handles the email, the invoices, and the client correspondence, usually between other tasks. One clicked link at the front desk is enough to put an attacker inside the business inbox - and from there, into patient records, client files, and payments.

2. The kinds of phishing that hit small businesses

Phishing comes in several variants, and each looks different in a business inbox. Classic email phishing is a mass send “from your bank” or “from a carrier.” Spear phishing is targeted: the attacker researches who you are first, then writes a message tailored to your practice - for example, “from” your software vendor. Smishing moves the same mechanism to text messages, vishing to phone calls, and quishing to QR codes stuck on invoices and parking meters.

VariantChannelTypical exampleFirst defense
Email phishingemail”Overdue invoice for your domain - pay within 24 hours”Check the sender’s address; open the site outside the link
Spear phishingemail”Updated price list” from a known vendor, with an attachmentConfirm any unusual request on a second channel
Smishingtext”$1.20 customs fee due on your package” with a payment linkCheck the shipment in the carrier’s app, not from the link
Vishingphone”This is your bank - we’re blocking a suspicious transfer”Hang up and call the number on the back of your card
QuishingQR codeA sticker with a code on a parking meter or an invoiceType the address manually instead of scanning
BECemail (hijacked inbox)A real-looking invoice with a changed account numberVerify account changes by phone; MFA on email

The lures follow the business calendar. In the US that means tax season above all: fake IRS notices, “W-2 requests” from a spoofed boss, bogus QuickBooks and Microsoft 365 alerts, and “updated payment instructions” from vendors right before a due date. The closer the deadline, the better the pressure works - which is why campaign peaks track filing deadlines.

A special place belongs to BEC (business email compromise) - phishing that ends in a wire transfer. The attacker takes over an inbox, reads the correspondence for weeks, and sends a real-looking invoice with changed bank details just before a payment is due. The full mechanism is covered in our guide to cyber threats. A phishing attachment is also a common first step of a ransomware attack.

3. Phishing in the numbers: 2025-2026

The scale shows in the FBI’s newest data. According to the FBI IC3 2025 Annual Report, Americans filed 1,008,597 complaints with $20.9 billion in reported losses - up 26% year over year. Phishing was the single most reported crime type, with 191,561 complaints, and phishing losses roughly tripled against the prior year. BEC alone accounted for over $3 billion in losses - the second-costliest category in the report - from fewer than 25,000 complaints. Few attack types concentrate that much damage in that few incidents.

The pattern is global, not just American. The Verizon Data Breach Investigations Report has placed phishing and social engineering among the top paths into a breach year after year, with small businesses making up a large share of victims - not because they are chosen, but because the campaigns are mass and automated.

One thing has shifted against defenders: the language. A few years ago, typos and awkward phrasing gave phishing away. Today attackers generate their copy with AI - the 2025 IC3 report tracks AI-enabled fraud as its own category for the first time - and a fake message is often written more carefully than a real vendor email. “Look for bad grammar” has stopped working as advice. That is why the rest of this guide focuses on signals AI cannot mask: what the message asks you to do, and where the link really leads.

4. Can your domain be spoofed? What we see in our scans

Separate two situations, because they need different defenses. First: someone sends phishing to you - that is stopped by habits and account protections, covered below. Second: someone impersonates your domain and sends fake emails “from you” to your patients, clients, and vendors. That second scenario can largely be shut down technically, in your domain’s configuration - and our scans show most small practices haven’t done it.

In the external scans we run on small dental, aesthetic, and accounting practices, 72% of domains had at least one weakness in SPF, DKIM, or DMARC - the three DNS records that decide whether a foreign server can successfully send mail “on your behalf.” 56% had no DKIM record, 50% had no DMARC or had it set to monitor-only (p=none), and 39% had a missing or overly soft SPF record. Our scan base is small European practices, but the misconfigurations are identical on US domains - DNS records don’t care about geography, and neither do the attackers’ scanners.

Then there are lookalike domains. For 33% of the practices we scanned, someone had already registered a typo variant of their domain, and for 17% that variant had a working mail server behind it - ready-made infrastructure for sending email “from a similar address.” A registered lookalike doesn’t have to mean bad intent; domain speculators park them too. But an owner should know such an address exists before it shows up on an invoice sent to their own client.

The last piece is leaks. At 22% of the practices we scanned, a staff email address appeared in a publicly known data breach, and at 17% it came with a plaintext password. At that point the attacker doesn’t need phishing at all - they just log in. Checking these three areas - email configuration, lookalike domains, and leaked credentials - is a standard part of our external vulnerability assessment.

5. How to spot phishing: red flags and the 60-second habit

Red flags still work, as long as you watch the right ones. The strongest signal today is not the language but the demand: the message tells you to do something fast with money, a password, or data. Pressure plus a call to action is the core of nearly every phish, whatever the wrapper.

Before you click, check five things:

  1. The demand and the pressure - “pay today,” “verify your account within 24 hours,” “the boss needs this wire now.”
  2. The full sender address - not the display name; a one-letter typo in the domain is the classic spoof.
  3. Where the link actually goes - hover over it (on a phone: press and hold) and compare the domain with the real one.
  4. An attachment you weren’t expecting - especially .zip archives, .html files, and documents that ask you to enable macros.
  5. An unusual channel or request - a bank doesn’t text you for a $1 fee, and the IRS doesn’t write from a free email address.

The habit that stops most attacks takes 60 seconds and requires no technology: never act from inside the message. Got an email about an overdue invoice from your domain registrar? Type their address into the browser yourself and check the balance there. A call “from the bank”? Hang up and call the number on the back of your card. A vendor asking to change their bank account? Call the number you had before that message arrived. One rule replaces dozens of tips: the message can lie - a channel you open yourself cannot.

6. Technical defense: your domain and your accounts

Habits are one layer, but a good defense cannot depend on every employee being alert every Monday. So we stack it in three layers: domain, account, human. Each catches what the previous one let through.

LayerWhat it blocksWhat to implement
DomainImpersonation of your address in emails to clients and vendorsSPF, DKIM, and DMARC with an enforcing policy (quarantine or reject)
AccountInbox takeover after a phished or leaked passwordMFA on email and key systems; a password manager
HumanClicking and acting under pressureThe 60-second verification habit; short, regular reminders

The three DNS records work together like a seal and a signature card. SPF tells the world which servers may send mail from your domain. DKIM cryptographically signs each message, so the recipient knows nothing changed in transit. DMARC decides what the receiving server does with mail that fails those checks - and only a quarantine or reject policy actually blocks anything. DMARC set to p=none merely reports: the spoof still lands in the recipient’s inbox. We walk through the setup step by step in SPF, DKIM and DMARC for accounting firms - the instructions work for any business, not just accountants.

MFA (multi-factor authentication) is the single most effective account protection: even a phished password is not enough to log in. Turn it on for email first, because the inbox resets passwords for everything else. If you can choose the method, pick a hardware key or a passkey - these are phishing-resistant, because they only work on the genuine site, never on a fake. A password manager closes the account layer: it generates unique passwords and will not autofill a saved password on a spoofed domain, which makes it a built-in authenticity test for every login page.

The human layer doesn’t need long training sessions. A short, repeated rhythm works better: five minutes in a monthly meeting, one current example from your industry, a reminder of the 60-second rule. Add one cultural rule: reporting a suspicious message - or your own slip - never ends in a reprimand. A practice where staff are afraid to admit a click finds out about the attack from the bank or from clients, which is too late.

7. “I clicked. Now what?”

Clicking a link or entering a password is not the end of the world - if the response is fast. Speed matters, blame doesn’t: the employee who reports a slip immediately is worth more to the business than the one who hides it.

  1. Change the password for the account you exposed and sign out all active sessions.
  2. Check the mailbox rules - attackers routinely set up forwarding and filters that hide correspondence from you.
  3. Turn on MFA if it isn’t already active - it blocks a repeat login with the stolen password.
  4. If payment data or a wire is involved, call your bank immediately - a fast recall request is the best chance of stopping a fraudulent transfer.
  5. File a complaint with the FBI at ic3.gov - it feeds the recovery process and helps block the campaign for others.
  6. Assess whether patient or client data was exposed. For health data, HIPAA gives you up to 60 days to notify individuals and HHS; for client financial data at a CPA firm, the FTC Safeguards Rule requires notifying the FTC within 30 days for incidents affecting 500 or more consumers, and state breach laws add their own clocks. We map these duties in the guide to data security compliance.

Keep the original message and don’t delete logs - you will need them for analysis, for the report, and for your cyber-insurance carrier.

8. Phishing in a dental practice, a CPA firm, and a med spa

In a dental practice, phishing impersonates insurers, suppliers, and software vendors, and the stakes are the patient records: health data whose exposure means HIPAA notification duties and conversations with patients no practice wants to have. The specifics are in our dental practice cybersecurity guide and on the dental practices service page.

In a CPA or accounting firm, phishing almost always aims at a payment: a swapped invoice, an “urgent” client instruction, a fake IRS notice at the peak of filing season. Deadline pressure does half of the attacker’s work. More in the accounting firm cybersecurity guide and on the accounting firms service page.

In a med spa, fake messages impersonate patients and booking platforms, and the target is often the Instagram account and the before-and-after photo library - material whose leak destroys trust faster than any fine. Details in the aesthetic medicine cybersecurity guide and on the aesthetic medicine service page.

Not sure which layer to start with? Book a free PreScan - within 24 hours we’ll check, among other things, whether your domain can be spoofed, whether registered lookalikes of it exist, and whether staff email addresses are circulating in breaches. No access and no installs required on your side.

FAQ

What is phishing and how does it work?

Phishing is a fake message - an email, text, or phone call - that impersonates a trusted party: a bank, a vendor, a shipping carrier, or the IRS. It pushes you to click a link, open an attachment, or enter a password, using urgency, authority, and fear. Instead of breaking in, the attacker gets the victim to open the door.

How do I recognize a phishing email?

Look at the demand, not the language: phishing tells you to do something fast with money, a password, or data. Check the full sender address and the domain a link points to before you click. Grammar mistakes are no longer a reliable signal, because AI writes clean copy. When in doubt, type the address yourself or call a number you already know.

Change the password for the account you exposed, sign out all active sessions, and check your mailbox rules for hidden forwarding. Turn on MFA, and call your bank immediately if payment data or a wire transfer is involved. File a complaint at ic3.gov. If patient or client data may have been exposed, breach-notification clocks start running.

Can a business block phishing completely?

No - the messages will keep coming, because sending them costs almost nothing. You can make them stop working: SPF, DKIM, and DMARC block spoofing of your domain, MFA makes a stolen password insufficient, and the habit of verifying on a second channel stops the rest. Together the three layers reduce phishing to incidents without damage.

How do I check if my company’s domain can be spoofed?

Check your domain’s SPF, DKIM, and DMARC records - without them, or with DMARC set to monitor-only (p=none), another server can send email that looks like yours. In the scans we’ve run on small practices, 72% had that gap. An external scan such as the free PreScan shows this within 24 hours, along with lookalike domains and leaked passwords.

Neighboring pillars: