A bookkeeper at a six-person accounting firm gets an email at 4:47 PM on a Thursday. It’s from QuickBooks. There’s a payment that didn’t process, and the client is asking why. She clicks the link, logs in to fix it, and goes home for the weekend. By Monday, her firm’s QuickBooks Online account has been drained of credentials, the attacker has rerouted a client’s ACH payment to an account in another state, and the firm is on the phone with their bank trying to claw back $43,000 that left their client’s account on Friday afternoon.
She wasn’t careless. She wasn’t untrained in some general sense. She just hadn’t seen that specific email pattern before in a context that gave her permission to slow down. That’s the gap this piece is trying to close — not “what is phishing” but “what does a phishing email actually look like sitting in your inbox at 4:47 on a Thursday, and what makes it work.”
Why small businesses are the specific target
Attackers don’t pick small businesses despite their size. They pick small businesses because of it. A 12-person dental practice or a 25-person law firm has the same kinds of valuable accounts as a Fortune 500 — payroll, banking, client data, vendor payment systems — but rarely has a dedicated security team running quarterly phishing simulations, a SIEM correlating identity events, or a security operations center watching unusual login behavior. The employees are bright and busy. They’ve heard of phishing. They haven’t had the institutional training that makes recognition automatic.
The numbers reflect this. Verizon’s 2024 Data Breach Investigations Report found that the human element was involved in 68% of breaches, with phishing and pretexting among the leading initial-access vectors. The FBI’s IC3 2023 report documented $2.9 billion in losses from business email compromise alone — a category that almost always begins with a phishing email.
The four psychological levers attackers pull are worth naming up front, because once you see them you’ll recognize the pattern in emails you’ve never seen before:
- Urgency. “Act now or this thing you care about goes away.” Short deadlines compress the time the target has to think.
- Authority. “This is from someone you don’t say no to.” The CEO, the IRS, your bank, Microsoft.
- Fear. “Something is wrong and it’s your responsibility to fix it.” A failed payment, a suspended account, a security breach.
- Curiosity. “There’s something here you want to see.” A shared document, an unexpected invoice, a voicemail transcript.
Every example below pulls at least one of these. Often two or three. The examples are ordered roughly from most common to most sophisticated.
1. The fake Microsoft 365 password expiration
Subject line: Your Microsoft 365 password expires today — action required. The email looks like it came from Microsoft. There’s a logo. The sender shows as “Microsoft 365 Team” though the actual sender address — visible if you hover over the name — is something like m365-security@notifications-msft.net. A button reads “Keep my password.” The link goes to a login page that is a pixel-perfect copy of the real Microsoft sign-in screen, hosted on a domain like login-microsoftonline.support.
Why it works: Authority plus urgency. Microsoft is real. Password expirations are real. Most users have clicked an identical-looking real notification before. The lever is “you do this routinely, do it now.”
The tells: Microsoft does not email you to renew a password on a deadline that day. The sender domain is not microsoft.com. Hovering over the button reveals a domain that includes “microsoft” as a subdomain or hyphenated string rather than the actual root domain.
2. The vendor invoice that’s not quite from your vendor
Subject line: Invoice #4471 — Past Due. The email appears to come from a vendor you actually use — a supplier, a software company, a contractor. There’s a PDF attached or a link to “view the invoice.” The amount is plausible. The vendor’s logo is on the PDF. Sometimes the attacker has even compromised the real vendor’s email and is sending this from a legitimate address.
Why it works: The pretext is already true. You do owe vendors money. You do pay invoices. The cognitive load of “wait, is this one real?” gets dropped in favor of “let me get this off my plate.”
The tells: The reply-to address differs from the from address. The PDF contains a link rather than an actual invoice. The bank routing info on the invoice has changed from the last one you paid. Any change in vendor payment instructions — new account, new wire information, new contact — is the single highest-risk signal in a small business inbox and should be confirmed by phone using a number you already had, not a number from the email.
3. The payroll redirect from “the new hire”
An email arrives at HR or whoever handles payroll: Hi, I need to update my direct deposit information before Friday’s payroll runs. Can you change my account to the routing/account number below? The sender name is an employee — sometimes a real one whose email has been spoofed, sometimes a name plausibly belonging to someone the recipient hasn’t met in person yet.
Why it works: Helpfulness. Whoever runs payroll wants to help employees. The request is small and procedural. Nobody expects a payroll fraud attempt to look this mundane.
The tells: The email isn’t from the employee’s normal address — it’s a Gmail or Outlook personal address, or a lookalike domain. The request comes shortly before a payroll cutoff. There’s no prior conversation in the thread.
4. The CEO wire transfer
The owner or managing partner sends a short email from her phone — at least that’s what the signature says. Are you at your desk? I need you to process a wire transfer today for a deal I’m finalizing. Send me the form and I’ll give you the details. Don’t loop anyone else in yet — this is confidential until it closes.
Why it works: Authority plus secrecy plus urgency, stacked. The employee doesn’t want to bother the boss with a phone call. The “confidential” framing prevents the verification conversation that would expose it.
The tells: The sender address is not the owner’s real address — it’s erik.grewe@gmail.com instead of erik@actualcompany.com, or a lookalike domain swapping an “rn” for an “m.” The “Sent from my iPhone” signature is the only signature. The urgency and secrecy are the giveaway: real owners do not run wire transfers this way, and any internal policy worth having requires a phone confirmation for wire requests over a threshold.
5. The QuickBooks (or Xero, or FreshBooks) notification
Subject line: You have a new invoice from [Client Name], or Your payment could not be processed. The email mimics the formatting of real QuickBooks notifications down to the font and button styling. The link goes to a fake login page that captures the user’s QuickBooks credentials. From there, the attacker has access to the firm’s books, can change client payment routing, and can send legitimate-looking invoices to the firm’s actual clients with the attacker’s bank info on them.
Why it works: Bookkeepers and owners process these emails constantly. The pattern is so familiar that clicking is muscle memory.
The tells: The sender domain isn’t intuit.com or quickbooks.com. The link, on hover, doesn’t go to a QuickBooks URL. The notification is for a client you don’t recognize or an invoice you didn’t generate.
6. The IT support ticket you didn’t open
Subject line: [Ticket #88421] Issue resolved — please confirm. The email appears to be from your IT provider or your internal help desk. There’s a link to “verify the fix” or “rate your experience.” Sometimes the attacker has done open-source research and used the actual name of your real IT provider.
Why it works: Curiosity and habit. Employees click IT emails reflexively. If they did open a ticket recently, this is plausibly it. If they didn’t, the impulse is to find out what’s going on.
The tells: The sender domain doesn’t match your IT provider’s actual domain. The link goes somewhere unexpected. When in doubt, call your IT provider — the real one will confirm in seconds whether the ticket exists.
7. The shared document you weren’t expecting
Subject line: [Coworker’s Name] shared a document with you: Q4 Forecast.xlsx. The email mimics a SharePoint, OneDrive, Google Drive, or Dropbox share notification. There’s a thumbnail of a blurred spreadsheet and a button to “Open.” Clicking lands on a fake Microsoft or Google login page.
Why it works: Curiosity, plus the social pressure of a coworker waiting on you. The pretext is now part of normal workflow — people share documents constantly.
The tells: The sender isn’t your coworker — it’s a notifications address from a domain that isn’t Microsoft, Google, or Dropbox. You weren’t expecting a document from this person. The hover-over URL doesn’t go to a real cloud storage domain.
8. The “your account has been compromised” alert
Subject line: Unusual sign-in activity detected on your account. The email warns that someone signed in from a city you don’t live in and asks you to “secure your account” by clicking a link. The link, of course, captures the credentials the attacker wants to “secure.”
Why it works: Fear, weaponized. The reader’s instinct is to act fast to protect themselves. The irony is that the protective action delivers exactly what the attacker wanted.
The tells: Real account-security alerts from Microsoft, Google, or your bank generally tell you to sign in by typing the URL yourself, not by clicking a button. The sender domain is wrong. The “unusual location” is suspiciously specific or suspiciously vague.
9. The IRS or state tax authority notice
Subject line: IRS Notice CP504: Final Notice of Intent to Levy. The email claims to be from the IRS, references a real notice type, and threatens immediate action — wage garnishment, asset seizure, a tax lien — if the recipient doesn’t click through to “resolve” the issue.
Why it works: Authority and fear at maximum amplitude. The IRS is the one organization most small business owners would rather not ignore.
The tells: The IRS does not initiate contact by email. The IRS publishes this explicitly and asks recipients to forward suspected phishing to phishing@irs.gov. Any email claiming to be from the IRS demanding immediate action via a link is phishing.
10. The shipping notification with the unexpected attachment
Subject line: UPS Delivery Notification — Package #1Z999AA10123456784. The email says a package couldn’t be delivered and provides an attachment — often a .zip, .htm, or .iso file — with the “shipping label” or “delivery details.” Opening the attachment runs a script or drops malware.
Why it works: Curiosity, plus the holiday-season volume of legitimate shipping notifications most offices receive.
The tells: Real shipping carriers don’t send executable attachments. Any .zip, .iso, .htm, or password-protected file from a shipping notification is presumptively malicious. The tracking number, if you check it on the real carrier’s site, doesn’t exist.
11. The bank “verify your information” request
The email looks like it came from your business bank. The branding matches. The language is formal. It asks you to verify recent account information or sign a new disclosure due to “regulatory changes.” A link takes you to a login page that looks identical to your bank’s real one.
Why it works: Authority and the genuine background hum of real regulatory updates banks do send.
The tells: Banks ask you to sign in through their main site, not via an emailed link. The sender domain isn’t your bank’s actual domain. When in doubt, call the number on the back of your debit card — not the number in the email.
12. The compromised contact reply-chain
This is the most sophisticated and the hardest to catch. An attacker has compromised a real contact at a real company you really do business with. The email arrives as a reply inside an existing email thread you actually had with that person. The subject line is the same one you’ve been replying to. The greeting picks up where the conversation left off. There’s a new attachment or link with some plausible context — updated proposal, signed contract, final invoice.
Why it works: Every contextual signal that you’d normally use to verify legitimacy is real. The sender is real. The thread is real. The relationship is real. The only thing that’s fake is the attachment.
The tells: The language pattern of your contact may be slightly off — different greeting style, different sign-off, awkward phrasing. The attachment is unexpected within the thread. The link goes somewhere that doesn’t match the contact’s company. If anything feels off about a reply-chain email — even one — pick up the phone before clicking. This is the category where a 30-second phone call has saved companies six- and seven-figure losses.
What to do when something feels off
Recognition is half the skill. The other half is having a low-friction response so that “I’m not sure” doesn’t default to “I’ll just click and see.” Three rules, in order:
- Don’t click. Don’t reply. Don’t open the attachment. Whatever the email wants you to do, the first move is to not do it. Phishing attacks are designed to convert hesitation into action. Stopping is the win.
- Verify out of band. If the email claims to be from your CEO, call her — on a number you already have, not one in the email. If it’s from a vendor changing payment info, call the vendor’s accounts receivable line you’ve used before. If it’s from your bank or the IRS, log in directly by typing the URL or call the number on the back of your card.
- Report it. Forward the suspected phishing email to your IT provider or internal security contact. Most email platforms have a “Report phishing” button built into the toolbar — use it. Reporting matters because if one employee got the email, others probably did too, and a fast report lets the provider pull the message from every inbox before someone else clicks.
The thing not to do is feel embarrassed about reporting something that turns out to be legitimate. A false alarm costs nothing. A real one caught early costs nothing. A real one that isn’t caught can cost a year of recovery work.
Why one article isn’t enough
An employee who reads through 12 examples will be better at spotting phishing this afternoon than they were this morning. That improvement decays. Attackers change tactics. New employees join who never read the article. Memory of specific examples fades faster than memory of general categories.
This is why security awareness training exists as an ongoing program rather than a one-time event. The model that works is short, monthly modules — 5 to 10 minutes — combined with simulated phishing tests that send harmless fake phishing emails to employees and report who clicks. The simulations aren’t punitive. They identify who needs more practice and they keep recognition skills fresh through repeated exposure. The CISA guidance on phishing reinforces this point: training is most effective when it’s continuous and reinforced through simulation, not delivered as a single annual compliance video.
It also matters who’s on the other side of the alert when an employee does report a suspicious email. If the report goes into a void, employees stop reporting. If the report gets a fast response — “thanks, that’s phishing, we’ve pulled it from every inbox” — reporting becomes a habit. The response loop is part of the training. Pairing this habit with dedicated email security gives your team a meaningful technical backstop alongside the human layer.
Where to take this next
If you’ve read this far, you’re already doing more than most small business owners do. The harder question is whether your team — the bookkeeper, the receptionist, the office manager, the new hire who joined last month — would spot these same patterns at 4:47 PM on a Thursday when they’re trying to clear their inbox before the weekend.
A few diagnostic questions worth asking yourself:
- Has anyone on your team received structured phishing training in the last 12 months — not a single video, but an ongoing program?
- If a phishing email landed in 10 inboxes this morning, would you know how many people clicked it? Understanding email security best practices for small business is a good place to start building that visibility.
- Does your team have a clear, written process for handling a suspected phishing email, and does the person who reports one get a fast response?
- If a wire transfer request came in from your name, would your finance person know to call you before sending it?
- Do you have cybersecurity services that catch the obvious phishing attempts before they reach your team, so employees only have to recognize the sophisticated ones?
ForeverOn Technology Solutions provides ongoing security awareness training, simulated phishing campaigns, and the layered email security and 24/7 monitoring that catches what slips past human judgment. We work with small businesses across Washington County, Frederick County, and surrounding Maryland — law firms, dental practices, CPA firms, manufacturers, non-profits — and we’ve helped clients build the kind of training program that turns employees from a liability into a working line of defense.
Our free security assessment is a two-visit consultation: the first visit gathers data on where your current setup actually stands, and the second presents what we found in plain English with color-coded charts showing where the real gaps are. No obligation, no sales pressure. If you’d rather start with a conversation, call (301) 739-7311 — a real person answers, no phone tree — or reach us through our free consultation page. Whatever you do next, do something. The bookkeeper at 4:47 PM on Thursday is counting on the work you do this week.