Phishing is still the number one way businesses get hacked, because it targets people rather than technology. A convincing email tricks someone into clicking a link, entering a password or paying a fake invoice, and the damage is done. The good news is that most phishing emails give themselves away if you know what to look for. Here is how to spot them, with examples.
How to spot a phishing email
Learning how to spot a phishing email is one of the best defences a business has, because most scams give themselves away once you know the warning signs. The NCSC offers official guidance too.

What is phishing?
Phishing is a scam where criminals pose as a trusted person or company, usually by email, to trick you into handing over information, clicking a malicious link or making a payment. More targeted versions include spear phishing (aimed at a specific person) and CEO fraud (pretending to be your boss to authorise a payment).
The warning signs to look for
- A sense of urgency: “Your account will be suspended in 24 hours” is designed to make you act before you think.
- Unexpected requests: a sudden ask to pay an invoice, change bank details or buy gift cards.
- A mismatched sender address: the display name looks right but the actual email address is odd or misspelt.
- Dodgy links: hover over a link and the real destination does not match the text or the company.
- Generic greetings: “Dear Customer” instead of your name.
- Spelling and grammar errors: genuine companies rarely send sloppy emails.
- Unexpected attachments: especially invoices, receipts or files you were not expecting.
Real-world examples
- The fake invoice: an email that looks like it is from a supplier, asking you to pay to a “new” bank account. Always verify changes by phone using a known number.
- The CEO request: a message that appears to be from your manager asking you to urgently buy gift cards or make a transfer. Real bosses do not do this by surprise email.
- The password reset: a warning that your Microsoft 365 account is locked, with a link to a login page that steals your details.
- The delivery scam: a “missed parcel” text or email with a link to pay a small fee, harvesting card details.
What to do if you spot a phishing email
- Do not click any links or open attachments.
- Do not reply or forward it to colleagues.
- Report it to your IT provider and, in the UK, forward it to report@phishing.gov.uk.
- Delete it, and if you did click, change your password and tell IT immediately.
How to protect your business
Technology and training work best together. Good email filtering stops most phishing before it lands, multi-factor authentication means a stolen password alone is not enough, and regular staff awareness turns your team into a strong last line of defence. A free cyber security audit will show where your gaps are, and Cyber Essentials puts the core controls in place.
How ATS Connection can help
We protect West Sussex businesses with layered email security, multi-factor authentication and staff awareness, all backed by proactive managed IT support. Get a quote or call 01903 255 159.
Frequently asked questions
What is a phishing email?
It is a scam email where criminals pose as a trusted person or company to trick you into clicking a malicious link, sharing information or making a payment.
How can I tell if an email is phishing?
Look for urgency, unexpected payment or login requests, a mismatched sender address, links that do not match their text, generic greetings, poor spelling, and unexpected attachments.
What should I do if I receive a phishing email?
Do not click links or open attachments. Report it to your IT provider and forward it to report@phishing.gov.uk, then delete it. If you clicked, change your password and tell IT at once.
What is the difference between phishing and spear phishing?
Phishing is sent widely to many people. Spear phishing is targeted at a specific person or business, often using real details to look more convincing.
How do I protect my business from phishing?
Combine email filtering, multi-factor authentication and regular staff awareness training, and put core security controls in place through a cyber audit or Cyber Essentials.