Most cyberattacks on small businesses don’t start with a hacker breaking through a firewall. They start with an email that looks completely normal — and one employee who clicks it.
Phishing emails are the number one way criminals get into small business networks, and Frederick County businesses are no exception. The scams have gotten slick: the logos look right, the grammar is clean, and the sender name might even be your boss’s. But nearly every phishing email still gives itself away if you know what to look for.
Here are seven red flags to teach your whole team.
1. It creates fake urgency
“Your account will be locked in 24 hours.” “Immediate action required.” “Payment overdue — click now.” Urgency is the oldest trick in the book because it works: panicked people don’t think before they click. Legitimate companies rarely demand instant action by email.
2. The sender’s address looks “off”
The display name might say “First National Bank,” but hover over it and the actual address is something odd and unfamiliar. Always check the real email address, not just the friendly name. Scammers also spoof familiar vendor and coworker names, so don’t trust the name alone.
3. Unexpected links or attachments
An invoice you weren’t expecting, a “package delivery” notice, or a shared document you never asked for — these are classic carriers. Never open an attachment or click a link you didn’t expect, even if it looks like it came from someone you know. When in doubt, call the sender at a number you already have.
4. Generic greetings
“Dear Customer,” “Hello Valued Member,” “Dear User.” Real companies you do business with usually know your name. Generic greetings are a sign the same email went out to thousands of inboxes.
5. It asks for money, gift cards, or login details
A real bank will never email you asking for your password. A real vendor will not ask for payment in gift cards or wire transfers. And no, your boss does not need you to buy $500 in Apple gift cards for “client gifts” over email. These requests are always scams.
6. The story doesn’t match how they normally contact you
If your payroll provider has always used a customer portal but suddenly emails asking you to confirm your login, that’s a red flag. Scammers count on you not noticing the change in routine. Ask yourself: is this how this company normally reaches me?
7. Something just feels wrong
Tiny details give scams away: a slightly misspelled company name in the link, a reply-to address that differs from the sender, a logo that’s just a bit blurry. Trust your gut — and verify before you click. You can always call the company directly using a number from their website, not the email.
What to do when you spot one
Don’t click, don’t reply, and don’t forward it to coworkers (that just spreads the risk). Delete it, and if your company has an IT person or provider, let them know — they can warn the rest of the team and block the sender. A thirty-second heads-up can stop the same scam from reaching everyone else in your office.
Make phishing training part of your routine
The best defense against phishing isn’t a tool — it’s a trained team. Short, regular reminders beat a one-time lecture every time. Many small businesses find that a quick monthly example shared with staff does more than any filter.
If you’d like help tightening up your email security or training your team to spot scams, West Main Tech works with small businesses across Frederick County on exactly that. Call us at (240) 490-9703 — we’d be glad to talk through what makes sense for your business.