Skip to main content
Shield blocking a phishing email, illustrating Portolan Networks' guide to protecting small businesses from phishing attacks

The Business Owner’s Complete Guide to Phishing

| Pat Midzio |

Updated July 30, 2026

Last year, one of our newer clients had a problem they didn’t yet know they had. An email arrived from a vendor they’d worked with for years — a real vendor, a real contact name, nothing about it looked wrong. It had an attachment. An employee opened it, got redirected to a site, and without realizing it, downloaded remote monitoring and management software (RMM — the same kind IT companies use to manage their clients’ PCs) onto her computer. That software gave an attacker hands-on access to her machine.

Nobody noticed. Not that day, and not that night, when the attacker quietly remoted in, opened her email contacts, and used her account to send the same malicious email to everyone in it. The whole thing only came to light because one of the people who received it happened to notice the timestamp — sent at 3 a.m. — and wrote back asking if it was really from her.

It was a wake-up call, and not just for the client. When we looked at what had let the attack get that far, the answer was the security stack their previous IT provider had put in place — email protection that let the message through, and no monitoring in place to catch the RMM software being installed or the after-hours activity that followed. We migrated them to Proofpoint for email security and rolled out DNS Filter, Huntress MDR, and Huntress ITDR. That upgraded stack is exactly what caught the other two incidents in this guide before they could do any real damage — as you’ll see.

Why This Keeps Working

What happened to that client isn’t rare, and it isn’t going away. Phishing attacks climbed 13.8% in the first quarter of 2026 alone, according to the Anti-Phishing Working Group — over 971,000 attacks detected in three months. And the attackers don’t need you to make a dramatic mistake. They need one employee, on one ordinary day, to open one attachment or click one link.

That’s because phishing isn’t really a technology problem — it’s a people problem that technology either catches or doesn’t. The 2025 Verizon Data Breach Investigations Report found that 60% of confirmed breaches involved a human action: a click, a reply, a form filled out. And once an attacker is in, the stakes escalate fast — ransomware showed up in 44% of all confirmed breaches last year, very often arriving through exactly the kind of foothold a phishing email creates.

The old advice — watch for typos, bad grammar, a sender name that looks slightly off — is also getting less reliable by the year. The Verizon report found that AI-generated phishing messages have roughly doubled over the past two years, and the pattern is obvious why: a well-written, grammatically clean email is easier to fake than ever, so the “does this look sloppy?” test that used to catch a lot of scams is quietly becoming less useful. The vendor email that got our client’s employee didn’t look sloppy at all. It looked completely normal, because that’s the whole point.

It’s Not Always an Email, and It’s Not Always Obvious

Not every phishing attack looks like the vendor scam that opened this guide. A separate client of ours ran into a more classic version: a fake Microsoft sign-in page, delivered by email, that got past their email protection. The message looked like a normal login alert. The page it linked to looked exactly like a real Microsoft sign-in screen — same layout, same branding, same “enter your password to continue.” The employee typed her credentials in without a second thought, because there was nothing to make her think twice. The moment the attacker tried to use them, Huntress ITDR flagged the login as suspicious, disabled the account automatically, and alerted us — we confirmed with the employee, verified the attacker hadn’t gotten further, reset her password, and had her back up and running within a couple of hours.

That’s the most common shape phishing takes — a fake login page harvesting credentials — but it’s far from the only one. A few variants worth knowing by name, because they show up constantly:

  • Spear phishing — a targeted email aimed at one specific person, built using real details about them or their company to seem more credible than a generic blast.
  • Whaling — spear phishing aimed specifically at executives and owners, who tend to have the broadest access and the least oversight of their own inbox.
  • Business email compromise (BEC) — an attacker takes over a real account (yours, a vendor’s, a partner’s) and uses it to send convincing requests from an address people already trust. This is exactly what happened to the vendor in our first story, and it’s one of the hardest variants to catch, because the email genuinely comes from a legitimate, previously-trustworthy source.
  • Smishing and vishing — the same tactics, delivered by text message or phone call instead of email. A caller claiming to be your bank or IT provider, asking you to “verify” account details or grant remote access, is running the same playbook with a different delivery method.
  • Quishing — phishing via QR code, a newer variant that’s grown alongside QR codes showing up on menus, parking meters, and posters; scanning a malicious code sends you to a fake login page the same way a bad link would.

How We Actually Protect Clients

No single tool stops every version of this — that’s the real lesson from these three incidents. Email filtering alone would’ve caught some of it and missed the rest; monitoring alone would have the same problem in reverse. What actually works is layering several tools that each catch what the others miss.

  • Proofpoint filters and scans email before it lands, and rewrites links so they’re checked again at the moment someone actually clicks — not just when the message first arrives. It also verifies SPF, DKIM, and DMARC records, which confirm a message really came from the domain it claims to. That’s useful, but it has a real limit worth knowing: when an attacker is sending from a genuinely compromised account — like the vendor in our first story — those checks pass, because the email really is coming from that account. Authentication checks confirm who sent a message, not whether the sender’s account has been taken over.
  • DNS Filter blocks connections to known-malicious domains at the network level, before a click even finishes loading a page.
  • Huntress MDR watches for malicious activity on the device itself, regardless of how it got there. That matters because not every threat starts with a phishing email — one of our clients had an employee searching Google for a template, who clicked through to a foreign website and downloaded a file containing malicious code. That’s not phishing in the strict sense — nobody impersonated anyone or asked for credentials — but it’s exactly the kind of threat a phishing-focused defense alone wouldn’t catch. Huntress MDR detected the malicious code as it started executing, stopped it, and isolated the machine automatically. We had alerts within minutes and were able to confirm no further spread.
  • Huntress ITDR monitors for exactly the kind of credential misuse in our second story — it’s what disabled that compromised account the moment the stolen login was used.
  • Huntress SAT (security awareness training) is the layer aimed at the human element directly: ongoing training so employees are more likely to pause, question, and report something that looks off, rather than click on reflex.

What You and Your Team Can Actually Do

None of the tools in the last section are things your employees control day to day — but a few habits make every one of those tools more effective, and catch things technology alone might miss.

  • Do hover before you click. Hovering over a sender’s name or a link (without clicking) shows you the actual address behind it. A link that says “microsoft.com” but resolves to something else entirely is one of the fastest tells there is.
  • Don’t log into anything by following a link in an email. Go to the site directly, the way you normally would, and log in there. This alone would have stopped the fake Microsoft sign-in page from working.
  • Do verify unusual requests through a second channel. If an email asks you to change a payment detail, wire funds, or grant remote access — especially if it’s urgent — call the person back using a number you already have on file, not one from the email. This is exactly what would have caught the vendor email compromise that opened this guide: the email itself looked completely legitimate, but a two-minute phone call would have exposed it immediately.
  • Don’t reuse passwords across accounts. If one account gets compromised, reused passwords hand the attacker a key to everything else.
  • Do use a password manager. We deploy Keeper Security for clients — it generates and stores long, random, unique passwords for every account, so there’s nothing simple to guess and nothing reused to exploit.
  • Do turn on multi-factor authentication everywhere it’s available, and lean toward phishing-resistant options like passkeys where you can. We cover this in detail in our guide to MFA — it’s the single biggest thing standing between a stolen password and an attacker actually getting in.
  • If you handle invoices or financial transactions over email regularly, consider a dedicated email address just for that purpose, and a firm internal policy that payment or account changes always get a phone confirmation before anyone acts on them — no exceptions, no matter how routine the email looks.

The Bottom Line

Phishing succeeds for a simple reason: it doesn’t need to break through your defenses, it just needs one person to trust one message. That’s what almost happened when a compromised vendor account nearly cost our client a real breach — and it’s exactly what didn’t happen in the other two stories in this guide, because the right tools were watching when it counted. Filtering, monitoring, and a team that knows what to look for aren’t separate strategies — they’re layers of the same defense, and you need all of them, because no single one catches everything on its own.

Book a Free Consultation

Not sure where your business stands — whether your current email security would catch a compromised-vendor scenario like the one that opened this guide, or whether your team knows what to do if they think they’ve clicked something they shouldn’t have? Let’s talk. Book a time on my calendar and we’ll walk through where the gaps are, as part of a broader cybersecurity program built for your business.

Frequently Asked Questions

Spam is unwanted bulk email — ads, offers, noise — that’s annoying but not necessarily malicious. Phishing is deliberately deceptive: it’s built to trick a specific action out of you, like clicking a link, entering credentials, or opening an attachment. Spam filters catch a lot of phishing, but not all of it, because well-crafted phishing is specifically designed not to look like spam.

Don’t wait to see if anything bad happens. Change the password for that account immediately, ideally from a different device, check whether MFA is enabled on it, and tell your IT provider right away so they can check for further compromise. Speed matters — in our second story, the account was disabled within moments of the stolen credentials being used, which is exactly why the damage stayed contained.

Good filtering stops a lot — but not everything, and that gap is growing as AI-generated phishing emails get harder to distinguish from real ones. Filtering also can’t catch an attack coming from a genuinely compromised, previously-trustworthy account, which is exactly what happened in our first story. That’s why filtering is one layer among several, not a complete solution on its own.

Increasingly, yes. Every cyber insurance application we’ve seen in the past couple of years asks about email filtering and security awareness training specifically, alongside MFA. We don’t have visibility into exactly how their presence or absence affects your premium — that’s a conversation for your broker — but in our experience, it’s often the difference between qualifying for coverage at all.