Ransomware, stolen credentials, manipulated invoices: behind most security incidents in SMEs there is no highly complex technology, but an e-mail that someone clicked on. Phishing works because it does not attack systems but habits – time pressure, helpfulness, respect for the boss. The following seven signs help to recognise suspicious messages before it is too late.

1. The sender does not match the address

The display name can be chosen freely. “John Smith – Managing Director” can come from any address. Check the actual e-mail address, not the name. Look for swapped letters (rn instead of m), extra words (company-invoice.com instead of company.com) and foreign domains behind familiar names.

2. Time pressure and threats

“Your account will be locked in 24 hours.” “The payment has to go out today.” Urgency is the attacker's most important tool because it switches off thinking. Legitimate senders rarely set deadlines of a few hours – and if they do, not by e-mail alone.

3. Unusual requests from familiar people

The managing director asks by e-mail to buy gift cards. Accounting is supposed to change a bank account number at short notice. A colleague urgently needs login details. Such requests are typical of CEO fraud and business e-mail compromise. The rule: always confirm unusual requests through a second channel – phone call, in person, chat.

Hover over a link without clicking: the destination appears at the bottom of the browser or e-mail client. If it differs from the displayed text or leads to short URLs and unknown domains, be careful. On a smartphone, long-pressing the link helps.

5. Attachments nobody expects

Invoices, job applications, delivery notes – attackers use exactly the documents that are normal in everyday work. Particularly risky are Office files with macros, ZIP archives and executables disguised as PDFs. An unexpected attachment is a reason to ask, not to open.

6. Login pages outside the usual environment

An e-mail leads to a login page that looks like Microsoft 365, the bank or the customer portal. Check the address bar: does the domain match exactly? Is the connection encrypted? When in doubt, type the service's address into the browser yourself instead of following the link.

7. Small errors in the overall picture

Language errors have become rarer since attackers use AI tools. What remains: an inappropriate salutation, a missing signature, a foreign logo in poor resolution, sending times in the middle of the night, a message in German from a company that otherwise communicates in English. Trust the feeling that something is wrong.

What to do when in doubt

Do not click, do not reply, do not forward – report it.

Define a simple reporting channel, such as an address like phishing@your-company.com or the report button in the e-mail client, and make clear that reports are welcome – even false alarms. Anyone who has already clicked or entered data should inform IT immediately and change the password. Every minute counts, and nobody should fear consequences: a reported mistake is a manageable incident, a concealed one becomes a crisis.

Technology that relieves people

Awareness does not replace technical measures. Multi-factor authentication makes stolen passwords largely worthless. External e-mails can be marked with a warning banner. SPF, DKIM and DMARC prevent attackers from spoofing your own domain. And regular, fair phishing simulations show where the team stands – without exposure, but with measurable progress.