All Resources
Cybersecurity

How to Recognize a Phishing Email Before It's Too Late

Phishing is the entry point for the vast majority of successful cyber attacks against small and mid-sized businesses. Modern phishing emails are polished, personalized, and often reference real people and real projects. This article walks through the warning signs, common tactics, and a step-by-step response procedure your team can actually use.

July 12, 2026 8 min read Greater Sudbury & Ontario

The warning signs that still work

No single signal is proof — but a combination should trigger caution. Train your team to slow down when they see two or more of these.

  • Sender address slightly wrong (m1crosoft.com, support@microsott.com)
  • Display name matches a real person, but the underlying email address doesn't
  • Urgency and pressure — 'you have 24 hours', 'account will be suspended'
  • A link to review, approve, or sign in — hover to see the real URL before clicking
  • Unusual request outside normal process — CEO asking for gift cards, vendor changing bank details
  • Attachment you weren't expecting, especially .html, .htm, .zip, .iso, or Office files with macros
  • Generic greeting when the sender should know your name
  • Grammar, spelling, or formatting inconsistent with the real sender

Common phishing tactics we see against Sudbury businesses

Microsoft 365 login harvesting

An email pretending to be from Microsoft, IT, or a shared document notification asks you to sign in to view or approve something. The link goes to a fake Microsoft login page that captures your password and MFA code in real time.

Fake invoice / DocuSign / e-transfer

A document notification from a service you recognize — DocuSign, Adobe, QuickBooks — asking you to review an invoice. The link leads to a login harvest or malware.

CEO / owner impersonation

An email that looks like it's from the owner or a senior manager, sent to finance or an assistant, asking for a quick wire transfer, gift card purchase, or vendor payment. Usually 'urgent' and 'I'm in a meeting, can't call.'

Vendor banking change request

An email from a vendor (or compromised vendor mailbox) informing you they've changed banking details for future payments. Always verify by phone using a known number.

What to do when you spot a suspicious email

  • Don't click the link, don't open the attachment, don't reply
  • Report it to IT or use the 'Report Phishing' button if configured in Outlook
  • If you already clicked and entered a password — reset the password immediately and tell IT
  • If you already sent money — contact your bank first, then IT, then your cyber insurer

Prevention beats detection

Individual vigilance matters, but layered controls stop far more attacks than training alone. Email filtering with impersonation detection, MFA on every account, and EDR on every endpoint together stop the vast majority of phishing consequences even when a click happens.

Frequently asked questions

How often should staff receive phishing training?

Short, ongoing training with periodic simulated phishing tests is far more effective than annual one-off sessions. Aim for monthly touchpoints, not annual.

Should we punish staff who fall for phishing tests?

No. Punitive programs cause underreporting, which is the opposite of what you want. Reward reporting, coach the individual privately, and treat repeated issues as a training conversation.

What if I already clicked?

Reset your password immediately (from a clean device), tell IT, and if you entered credentials, revoke Microsoft 365 sessions and enable MFA if it wasn't already. Speed matters.

Can AI stop phishing entirely?

AI-based email filtering catches much more than legacy filters, but no filter is perfect. Layered controls plus trained staff plus MFA is what actually works.

Roll out phishing training and testing

Security awareness training and phishing simulations are part of every managed cybersecurity engagement.

Keep exploring

Related services, locations, and resources

Related services

Related resources