By the RaxxWare engineering team ·
How to Recognize Phishing and Business Email Scams
Business email fraud costs companies more than ransomware. Here is how to spot phishing, invoice fraud, and CEO impersonation before money leaves the building.
Business email compromise costs companies more money every year than ransomware does, and it involves no hacking at all. There is no malware and no breached firewall. Someone sends a convincing email, a person believes it, and money moves voluntarily to an account controlled by a criminal.
Because the attack targets judgment rather than technology, no software product fully prevents it. What prevents it is recognizing the patterns and having a verification process that does not depend on anyone's judgment in a rushed moment. This guide covers both.
The Scams That Actually Target Small Businesses
Generic spam is easy to ignore. The attacks that succeed against businesses are specific, researched, and plausible. These are the forms worth recognizing on sight:
Invoice fraud is the most costly. An attacker monitors or guesses your supplier relationships and sends an invoice that looks like it came from a vendor you genuinely use, often with a note that banking details have changed. The amount is reasonable, the branding is right, and the payment goes to the criminal. Sometimes the attacker has actually compromised the supplier's email and is replying inside a real thread, which defeats nearly every visual check.
CEO fraud, sometimes called whaling, impersonates the owner or a senior person and asks a staff member to make an urgent payment or buy gift cards. It exploits hierarchy and urgency together, and it specifically targets people who are unlikely to question the boss. The message usually explains why the sender cannot be reached by phone right now, which is the tell.
Credential phishing sends a convincing login page for a service you use, harvesting the password when you enter it. The link often arrives as a document sharing notification, a password expiry warning, or a failed delivery notice, because those are things people click without thinking.
Payroll diversion targets HR with a request from a supposed employee to update direct deposit details. It is small, routine, and rarely questioned, which is exactly why it works.
The Red Flags Worth Memorizing
Most fraudulent messages carry several of these signals at once. Any one of them justifies slowing down, and two or more should stop the transaction entirely until verified:
- Urgency combined with secrecy, such as needing this done immediately and asking you not to discuss it with others.
- Any change to banking details, payment instructions, or direct deposit information, which is the single highest-risk request in business email.
- A sender address that is subtly wrong, using a lookalike domain with a swapped letter, an added word, or a different extension.
- A reply-to address that differs from the visible sender, which is easy to miss and often the giveaway.
- Requests for gift cards, cryptocurrency, or wire transfers, none of which legitimate vendors ask for and all of which are irreversible.
- A pretext for why you cannot verify by phone, such as being in meetings all day or traveling somewhere unreachable.
- Slightly wrong tone or vocabulary from someone whose writing you know well.
- Links whose visible text does not match their actual destination when you hover over them.
- Attachments you did not expect, particularly documents that ask you to enable content or macros.
Why Checking the Sender Is Not Enough
The standard advice is to check the sender address, and it is worth doing, but it fails against the attacks that cost the most money. Understanding why matters, because people who rely on this check alone feel protected while remaining exposed.
Display names are trivially forged. Email lets the sender set any display name they want, so a message reading from your supplier's name may come from an unrelated address that most mail apps hide by default on mobile.
Lookalike domains defeat casual inspection. A domain with a swapped letter, a doubled character, or a different extension reads as correct when you are moving quickly, and it becomes invisible on a phone screen.
Most seriously, a genuinely compromised account passes every technical check. When an attacker controls your supplier's real mailbox, their message comes from the correct address, arrives in the existing thread, matches previous formatting, and references real prior conversations. Nothing about the email is fake. This is why verification must happen outside of email entirely, using a channel the attacker does not control.
The Verification Rule That Prevents the Loss
One policy stops nearly every version of this fraud, and it needs to be a rule rather than a judgment call, because judgment fails under pressure and pressure is exactly what these attacks manufacture.
The rule: any request to send money or to change payment details is verified by voice, on a phone number you already have on file, before anything moves. Never a number supplied in the message. Never a reply to the email. A known number from your own records, dialed by you.
Make it explicit that this applies to the owner too, and say so out loud to the team. CEO fraud works because employees are reluctant to question authority. If everyone knows in advance that verifying a payment request from the boss is expected and welcomed rather than insubordinate, the attack loses its leverage. Tell staff directly that they will never be criticized for making that call.
Add a second signature above a threshold amount that reflects your business. Two people independently approving a payment defeats an attack that has only fooled one of them. And build in a pause: fraud depends on speed, so a rule that all new payment details wait until the next business day costs almost nothing legitimate and eliminates the urgency the attacker needs.
What to Do If Someone Falls for One
Speed matters enormously, and shame is the main thing that slows people down. Make it clear in advance that reporting a mistake immediately is the expected behavior and will never be punished, because an hour of delay is often the difference between recovering funds and losing them.
If money was sent, call the bank immediately and use the words fraudulent transfer, asking specifically about a recall or a SWIFT recall for international wires. Wire transfers can sometimes be reversed within a short window, and that window is measured in hours.
If credentials were entered, change that password immediately and everywhere it was reused, then enable multi-factor authentication, then check for forwarding rules and filters the attacker may have created. Criminals commonly set a rule that auto-forwards or auto-deletes mail so they can monitor the account quietly after the password changes.
Then look wider. Check whether other accounts share that password, review recent sent mail for messages you did not write, notify anyone who may have received fraudulent mail from your account, and report the incident to the relevant national fraud reporting body, which in the United States is the FBI's Internet Crime Complaint Center.
Reducing Your Exposure
Beyond individual vigilance, a handful of technical and procedural measures make your business a harder target and limit the damage when something slips through:
- Enable multi-factor authentication on email first, since a compromised mailbox is what makes the most convincing attacks possible.
- Configure the standard email authentication records for your domain, which make it substantially harder for anyone to send mail that appears to come from you.
- Turn on external sender warnings so mail from outside your organization is visibly tagged.
- Keep a written list of supplier bank details, and treat any change to it as a verification event rather than a data update.
- Limit who can initiate payments, and require dual approval above a threshold.
- Audit mailbox forwarding rules periodically, since attackers use them to monitor accounts long after the initial compromise.
- Run occasional short refreshers with staff using real examples, which works far better than a policy document nobody reads.
- Reduce public detail about who holds which financial role, since attackers research org structure to target the right person.
Frequently Asked Questions
How can I tell if an email is really from my supplier?
You cannot tell reliably from the email itself, which is the central problem. A compromised supplier mailbox sends messages from the correct address inside real threads. The only dependable verification is a phone call to a number you already have on file from your own records, never a number contained in the message, and this should be mandatory for any request involving payment details.
What should I do immediately if we sent money to a scammer?
Call your bank within minutes, not hours, and use the words fraudulent transfer while asking specifically about a recall. Wire transfers can sometimes be reversed if you act inside a short window. Then report it to your national fraud body, which in the United States is the FBI's Internet Crime Complaint Center, and preserve the original emails with their full headers as evidence.
Does antivirus software protect against phishing?
Only partially. Antivirus and mail filtering catch known malicious links and attachments, which handles a lot of bulk phishing, but business email compromise typically contains no malware at all. It is a plain text message asking a person to do something, sent sometimes from a genuinely legitimate compromised account, so no security product can flag it reliably. Process and verification habits are the actual defense.
See what this would cost to fix
RaxxWare builds custom software and automation for problems exactly like this. Get a free business audit or estimate your savings with our ROI calculator — no commitment.