The phishing email that actually compromises an Anchorage small business in 2026 does not look like a scam. It looks like a Microsoft 365 password-expiry notice. It looks like a shared document from a coworker. It looks like an invoice from a vendor you really do use. The crude, typo-ridden scams are easy; the dangerous ones are the ones that look completely ordinary.
You cannot rely on a spam filter to catch all of them, because the best ones are crafted to slip through. The durable defense is a team that knows what to look for. Here is what to teach them. It takes about ten minutes and it is the highest-return security training a small business can do.
Why phishing is still the number-one way businesses get breached
Almost every account takeover and business email compromise we see traces back to one person clicking one link and typing their password into a fake login page. Not malware downloaded from a sketchy site, not a hacker breaking through a firewall. A real employee, having a busy day, helpfully entering their credentials where they were asked to. Attackers go after people because people are reachable, and one good click gets them in.
That is also the good news: because it comes down to a human decision, training a human changes the outcome.
The signals that catch modern phishing
Teach your team to pause and check these, especially when an email creates urgency or asks them to log in or pay something.
- The real sender address, not the display name. “Microsoft Account Team” is a display name anyone can set. Hover over it, or tap it on a phone, and look at the actual address.
security@microsoft.comis plausible;security@microsoft-account-verify.comis not. The mismatch between a trusted name and a strange address is the single most reliable tell. - Where the link really goes. Hover over any link (on a phone, press and hold) and read the URL that pops up before tapping. A “Microsoft 365 login” link that points to anything other than a microsoft.com or office.com address is a fake login page designed to harvest the password.
- Manufactured urgency. “Your account will be suspended in 24 hours.” “Wire this today or we lose the deal.” “Unusual sign-in, verify immediately.” Urgency is the phisher’s main tool because it stops people from thinking. A real institution rarely demands you act within hours through an email link.
- An unexpected request to log in or pay. Did you ask for a password reset? Were you expecting this invoice? An out-of-the-blue request to authenticate or move money deserves a pause every single time.
- Slightly-off details. A logo that is a little blurry, formatting that is not quite right, a greeting that says “Dear Customer” instead of your name, a tone that is a touch wrong for who it claims to be from. Modern phishing is polished, but small imperfections still leak through.
- The reply-to does not match. An email “from” your CEO asking for gift cards, where the reply address is a random Gmail account. This is the classic business email compromise setup.
The two rules that prevent most of it
You can boil the training down to two habits that, on their own, stop the large majority of successful phishing:
- Never enter your password from an email link. Ever. If an email says your Microsoft 365 or bank login needs attention, do not click the email’s link. Open a new browser tab and go to the site the way you normally do, by typing the address or using a bookmark. Fake login pages only work if you arrive at them through the attacker’s link. Refuse to, and the whole attack fails.
- Verify money and credential requests through a second channel. Any email asking to change payment details, wire funds, buy gift cards, or hand over a password gets verified by phone or in person, using a number you already have, not one from the email. Two minutes of friction prevents the five-figure mistake.
When someone clicks anyway
People are human and someone eventually clicks. What matters then is speed and the absence of blame.
- If they entered a password, change it immediately and check that MFA is on. With MFA enforced, a phished password is far less useful to the attacker, which is why we treat MFA as the non-negotiable backstop to all of this.
- Tell IT right away. The employee who reports their own mistake in five minutes is doing exactly the right thing. The one who hides it out of embarrassment for a week is how a contained slip becomes a breach. Make it safe to report; a culture of “tell us fast, no blame” is itself a security control.
Make it routine, not a one-time lecture
A single training session fades. What sticks is making this normal: occasional simulated phishing tests so people stay sharp, MFA enforced so a single click is not catastrophic, and an easy, blame-free way to report anything suspicious. For managed clients we run phishing simulations and track click rates over time, so training is targeted where it is actually needed rather than a yearly box-tick.
If you want to know how your team would do against a realistic phishing test, or whether your MFA would actually save you when someone clicks, the free IT Health Check is a good place to start. Ten honest minutes on this topic is some of the best security spending a small business can do.